Chapter 10. Managing Certificates
• Request and install new certificates for the subsystem certificates installed in a Certificate System
instance; issuing or requesting a new certificate means getting a certificate based on a new public
and private key pair.
• Install CA certificates in the certificate or trust database of a Certificate System instance.
• Install CA certificate chains in the certificate database of a Certificate System instance.
The wizard performs different tasks depending whether it is launched from the CA Certificates tab or
the Local Certificates tab.
Open the wizard by clicking Add or Add/Renew in the System Keys and Certificates Console menu
item.
The Local Certificates-based wizard has the option to request or install a certificate. The CA
Certificate-based wizard has the option to install a trusted or untrusted certificate chain.
To install certificates, except for self-signed CA certificates, the wizard must be run twice: once to
request the certificate and once to install the certificate. If the certificate request is being submitted
to an outside CA, even another Certificate System CA, the certificate must be issued and retrieved
before it can be installed through the wizard.
10.2. Requesting and Receiving Certificates
The process of receiving a certificate is simple:
1. An end entity requests a certificate.
2. The certificate request is submitted to the CA.
3. The request is verified by authenticating the entity which requested it and by confirming that it
meets the certificate profile rules which was used to submit it.
4. The request is approved.
5. The end entity retrieves the new certificate.
The Certificate System provides three ways to request a certificate:
• Through the enrollment forms of the Certificate Manager end entity pages
• Through the subsystems' administrative console
• By using the certutil command-line tool
There are also three ways that the request is submitted the CA to generate a certificate and to add it to
the certificate database:
• Through the enrollment forms of the Certificate Manager end entity pages. Requests are submitted
immediately when the request is created through the enrollment form; requests can also be
submitted that were created by the administrative console or the certutil tool.
• Through the subsystems' administrative console. The Console has an option to submit the request
to a specified CA.
• By using the certutil command-line tool.
196
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?
Questions and answers