The authentication process is determined by the certificate profiles that are associated with the
enrollment forms used. This can be done automatically by the server applying preset criteria or by
manual approval from an agent. Once the request is approved, it is available through the CA's end-
entities page for the entity to retrieve.
NOTE
For more information on authentication for enrollment, see
Enrolling Certificates
Section 10.2.1, "Requesting Certificates"
•
Section 10.2.2, "Submitting Certificate Requests"
•
Section 10.2.3, "Retrieving Certificates from the End-Entities Page"
•
10.2.1. Requesting Certificates
The different methods of requesting certificates allow different types of certificates which can be
requested. End users can request client certificates, either agent or user certificates for the Certificate
System or for use with other applications. Administrators can request certificates for servers and
Certificate System instances.
• End-Entities Page: User and Agent Certificates
The end-entities pages can be accessed by any user. Those enrollment forms can be used to
request user and agent certificates. See
through the End-Entities
• Certificate Wizard: Server and Subsystem Certificates
The administrative console can only be accessed by administrators. The Console can be used
to create requests for CA, OCSP, and CRL signing certificates; SSL server certificates; client
certificates; and DRM transport certificates. See
Server, or Signing Certificate through the
• certutil: All Certificates
The certutil utility can be used by administrators or users to generate any certificate.
10.2.1.1. Requesting a User or Agent Certificate through the End-Entities
Page
End entities can use the HTML enrollment forms on the Certificate Management end-entities page
to create user certificates for email and SSL authentication. Other enrollment forms are available for
adding certificates to tokens and signing files. For more information about the end-entities enrollment
forms, see the Certificate System Agent's Guide.
The following forms are used to create user certificates:
• Manual User Dual-Use Certificate Enrollment
• Manual User Signing and Encryption Certificates Enrollment
Chapter 12, Certificate
and
Section 10.2.1.1, "Requesting a User or Agent Certificate
Page".
Console".
Chapter 15, Authentication for
Profiles.
Section 10.2.1.2, "Requesting a Subsystem,
Requesting Certificates
197
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?