The certificate type created in Creating a certificate type for the administrator profile has a Dual Usage certificate definition. You must create a new certificate definition policy for this certificate definition that disables private key backup and enforces generating the key at the client application. 

To create a new certificate definition policy for the new certificate type

  1. Log in to Security Manager Administration for the Security Manager CA.
  2. In the tree view, expand  Security Policy  >  User Policies.

  3. Select  Dual Usage Policy.

  4. Select  Policies  >  User Policies  >  Selected User Policy  >  Copy.
    The  Copy User Policy  dialog box appears.

  5. In the  Label  field, enter  Dual Usage CAGW Admin Policy.
  6. In the  Common name  field, enter  Dual Usage CAGW Admin Policy.
  7. In the  Add to  drop-down list, select the searchbase where you want to store the user policy.
  8. Under  Policy Attributes:
    • Deselect  Backup private key.
    • Select  Generate key at client.
  9. Click  OK.
  10. If prompted, authorize the operation. The operation may require more than one authorization. See the Security Manager Administration documentation for details.