This whitepaper is for historical reference only. Some content might be outdated and some links might not be available.
Domain controller certificate
Each domain controller that is going to authenticate smartcard users must have a domain controller certificate. Request and install a domain controller certificate on each domain controller.
If you install a Microsoft Enterprise CA in an AD forest, all domain controllers automatically enroll for a domain controller certificate.