EFS certificate type and enrollment

Enabled: You can restrict the EFS certificate type. You can also enable the enrollment of external EFS certificates by specifying the Certification Authority's web address.
1.EFS certificate type: Specify whether you want to allow all certificate types (domain, external and self-signed certificates) or only certain certificate types. This restriction will apply when users are going to enroll or select certificates.
2.Certificate request URL: Enter a CA's certificate request web address to be used for EFS certificate enrollment, e.g. https://www.companyname.com/foldername.
This target path will be used when an EFS certificate is requested from an external Certification Authority (CA).
The certificate request URL is optional. If you do not specifiy a path here, users will not be able to request external EFS certificates. If you want to enable external EFS certificates, then enter a valid path which will be accessible to all Security Platform PC's. Otherwise the EFS certificate enrollment will fail.

Disabled: The EFS certificate type is not restricted. The web adress to be used to retrieve EFS certificates is not set, i.e. users cannot request external EFS certificates.

Notes:
Note that EFS certificates are not only used for EFS, but also for PSD.
While this setting is valid only for EFS certificates (to be used for EFS or PSD), there is also a user policy which is independent of the certificate usage (URL to start from wizard for certificate enrollment).

Default value: Disabled

Supported on:
Registry HiveHKEY_CURRENT_USER
Registry PathSoftware\Policies\Infineon\TPM Software
Value NameEFSCertificateEnrollmentPol
Value TypeREG_DWORD
Enabled Value1
Disabled Value0

EFS certificate type:


  1. Allow all types
    Registry HiveHKEY_CURRENT_USER
    Registry PathSoftware\Policies\Infineon\TPM Software
    Value NameEFSCertificateTypes
    Value TypeREG_DWORD
    Value1
  2. Allow only domain certificates
    Registry HiveHKEY_CURRENT_USER
    Registry PathSoftware\Policies\Infineon\TPM Software
    Value NameEFSCertificateTypes
    Value TypeREG_DWORD
    Value2
  3. Allow only domain and external certificates
    Registry HiveHKEY_CURRENT_USER
    Registry PathSoftware\Policies\Infineon\TPM Software
    Value NameEFSCertificateTypes
    Value TypeREG_DWORD
    Value3

Certificate Request URL (only relevant for external certificates)

Registry HiveHKEY_CURRENT_USER
Registry PathSoftware\Policies\Infineon\TPM Software
Value NameEFSCertificateEnrollmentURL
Value TypeREG_SZ
Default Value

ifxsppol.admx