You manage the loaded certificates in that snap-in,
not make them.
To make a cert/key pair to define a DRA one uses
cipher /r option. One then loads the cert info into
the group policy and one logs in as the DRA account
and loads the key into its private certificates store
if one wants to use the DRA to decrypt.
Want to reply to this thread or ask your own question?
You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.