The default instructions on the PivKey documentation site: https://pivkey.zendesk.com/hc/en-us do not provide any examples for configuring a self-signed certificate in any of the 25 slots. These instructions were tested with the PivKey C910
version, but likely most Taglio variants will work the same way.
There is support in powershell 5.1+ on currently supported Windows OS (Server 2012+/Windows 10+) configurations for generating self-signed certificates with a wide variety of configuration parameters, including support for the Microsoft Smart Card Key Storage Provider
to generate keys on a smartcard.
- Reference: https://learn.microsoft.com/en-us/powershell/module/pki/new-selfsignedcertificate
- Setup mapping of generate certificate to certificate slots (see Powershell script snippet below) to automatically assign a slot by using the correct
Application Policies
OID configuration in in the initi