View the Certificate Store
Use the following command to view the CA certificate store. The LDAP URI depends on the Active Directory domain for your organization (such asfx.futurex.com) and the CA name (such as fx-FXCA).
Powershell
Powershell
Sign a certificate
The following steps demonstrate one way to test by using the KMES Series 3 to sign a certificate for the CA server.1
Open the Certificate Manager on the CA server.
2
Right-click Personal and select All Tasks > Request New Certificate.
3
In the Certificate Enrollment window, select [ Next ].
4
In the Certificate Enrollment Policy window, choose a certificate enrollment service associated with the CA server, such as Active Directory Enrollment Policy for an Enterprise CA. Select [ Next ].
5
In the Request Certificates window, choose a certificate template and select [ Enroll ].
If the connection to the KMES succeeds, you receive a success message. If the KMES is offline you receive an error.
6
To locate the certificate that you issued, perform the following steps:
- Open the Active Directory Certificate Authority tool from the Server Manager.
- Expand the node associated with your CA common name.
- Select [ Issued Certificates ].
A certificate matching your request displays on this page.

