When renewing a certificate, users are presented three choices for installing the new certificate:
Personal store
Local machine store
Smart Card
The option 'Personal store' is selected by default.
Use a text editor to open the file <KCA-install-dir>/WebServer/enroll-server/get-cert-msie.xuda, and look for the following lines:
<P> Where is this certificate being installed?
<SELECT NAME="USERPROTECT">
<OPTION VALUE="0" SELECTED>Personal store</OPTION>
<OPTION VALUE="1">Local machine store</OPTION>
<OPTION VALUE="2">Smart Card</OPTION>
</SELECT>
</P>
To change the default selection to 'Smart Card', change the above lines so they look like the following:
<P> Where is this certificate being installed?
<SELECT NAME="USERPROTECT">
<OPTION VALUE="0">Personal store</OPTION>
<OPTION VALUE="1">Local machine store</OPTION>
<OPTION VALUE="2" SELECTED>Smart Card</OPTION>
</SELECT>
</P>
Save the changes. All users will get 'Smart Card' as the default option to install the renewed certificate to.
Related Articles
Issue with RRM after renewing ssl server certificates 17Number of Views Xudad crashes soon after renewing System CA certificate 29Number of Views Unable to renew certificate from web enrollment server 38Number of Views Unable to renew system SSL certificates on Registration Manager 6.6.1 20Number of Views Unable to generate a CRL or revoke a certificate 9Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide