By default, verification key pairs can only be generated by client applications of the CA. To enable PKCS #12 enrollment with client applications, verification keys must be server-generated – that is, keys generated by the CA.
See the Entrust Certificate Authority documentation for instructions on how to export the entmgr.ini file.
To enable server-generated verification keys
- Export the
entmgr.inifile using the Entrust Certificate Authority Control Command Shell. - Configure the following setting in the
entmgr.inifile.[policy]allowServerGenVerCert=true - Save and close the file.
- Import the updated entmgr.ini file into the CA using the Entrust Certificate Authority Control Command Shell,