The certificate type created in Creating a certificate type for the administrator profile has a Dual Usage certificate definition. You must create a new certificate definition policy for this certificate definition that disables private key backup and enforces generating the key at the client application. 

To create a new certificate definition policy for the new certificate type

  1. Log in to the Entrust Certificate Authority administration console.
  2. In the tree view, expand  Security Policy  >  User Policies.

  3. Select  Dual Usage Policy.

  4. Select  Policies  >  User Policies  >  Selected User Policy  >  Copy.
    The  Copy User Policy  dialog box appears.

  5. In the  Label  field, enter  Dual Usage CAGW Admin Policy.
  6. In the  Common name  field, enter  Dual Usage CAGW Admin Policy.
  7. In the  Add to  drop-down list, select the searchbase where you want to store the user policy.
  8. Under  Policy Attributes:
    • Deselect  Backup private key.
    • Select  Generate key at client.
  9. Click  OK.
  10. If prompted, authorize the operation. The operation may require more than one authorization. See the Entrust Certificate Authority documentation for details.