Chapter 11. Managing Certificates
Open the wizard by clicking Add or Add/Renew in the System Keys and Certificates Console menu
item.
The Local Certificates-based wizard has the option to request or install a certificate. The CA
Certificate-based wizard has the option to install a trusted or untrusted certificate chain.
To install certificates, except for self-signed CA certificates, the wizard must be run twice: once to
request the certificate and once to install the certificate. If the certificate request is being submitted
to an outside CA, even another Certificate System CA, the certificate must be issued and retrieved
before it can be installed through the wizard.
11.2. Requesting and Receiving Certificates
The process of receiving a certificate is simple:
1. An end entity requests a certificate.
2. The certificate request is submitted to the CA.
3. The request is verified by authenticating the entity which requested it and by confirming that it
meets the certificate profile rules which was used to submit it.
4. The request is approved.
5. The end entity retrieves the new certificate.
The Certificate System provides three ways to request a certificate:
• Through the enrollment forms of the Certificate Manager end entity pages
• Through the subsystems' administrative console
• By using the certutil command-line tool
There are also three ways that the request is submitted the CA to generate a certificate and to add it to
the certificate database:
• Through the enrollment forms of the Certificate Manager end entity pages. Requests are submitted
immediately when the request is created through the enrollment form; requests can also be
submitted that were created by the administrative console or the certutil tool.
• Through the subsystems' administrative console. The Console has an option to submit the request
to a specified CA.
• By using the certutil command-line tool.
The authentication process is determined by the certificate profiles that are associated with the
enrollment forms used. This can be done automatically by the server applying preset criteria or by
manual approval from an agent. Once the request is approved, it is available through the CA's end-
entities page for the entity to retrieve.
NOTE
For more information on authentication for enrollment, see
Enrolling Certificates
230
Chapter 13, Certificate
and
Chapter 16, Authentication for
Profiles.
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?
Questions and answers