Chapter 11. Managing Certificates
230
Open the wizard by clicking
Add
or
Add/Renew
in the
System Keys and Certificates
Console menu
item.
The
Local Certificates
-based wizard has the option to request or install a certificate. The
CA
Certificate
-based wizard has the option to install a trusted or untrusted certificate chain.
To install certificates, except for self-signed CA certificates, the wizard must be run twice: once to
request the certificate and once to install the certificate. If the certificate request is being submitted
to an outside CA, even another Certificate System CA, the certificate must be issued and retrieved
before it can be installed through the wizard.
11.2. Requesting and Receiving Certificates
The process of receiving a certificate is simple:
1. An end entity requests a certificate.
2. The certificate request is submitted to the CA.
3. The request is verified by authenticating the entity which requested it and by confirming that it
meets the certificate profile rules which was used to submit it.
4. The request is approved.
5. The end entity retrieves the new certificate.
The Certificate System provides three ways to request a certificate:
• Through the enrollment forms of the Certificate Manager end entity pages
• Through the subsystems' administrative console
• By using the
certutil
command-line tool
There are also three ways that the request is submitted the CA to generate a certificate and to add it to
the certificate database:
• Through the enrollment forms of the Certificate Manager end entity pages. Requests are submitted
immediately when the request is created through the enrollment form; requests can also be
submitted that were created by the administrative console or the
certutil
tool.
• Through the subsystems' administrative console. The Console has an option to submit the request
to a specified CA.
• By using the
certutil
command-line tool.
The authentication process is determined by the certificate profiles that are associated with the
enrollment forms used. This can be done automatically by the server applying preset criteria or by
manual approval from an agent. Once the request is approved, it is available through the CA's end-
entities page for the entity to retrieve.
NOTE
For more information on authentication for enrollment, see
Chapter 16, Authentication for
Enrolling Certificates
and
Chapter 13, Certificate Profiles
.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...