# emCA Certificate Manager

The Streamlined and Secure PKI Solution

## Current Version: emCA v5.0.0

**Release Date: 15th Nov'25**

## Introduction&#x20;

emCA, an integrated certificate management solution with a web interface that automates requesting, approving, issuing, and renewing certificates. By reducing manual tasks, it helps organizations enforce consistent certificate policies and decreases the administrative effort required for lifecycle management.

## Summary

Public Key Infrastructure (PKI) is a framework for secure digital communication and data exchange. Within this ecosystem, an essential component is the issuance of digital certificates which validate the identity of entities involved in online transactions. emCA (eMudhra Certificate Authority), an enterprise-grade PKI solution, is a centralized certificate management system. It handles certificate issuance, distribution, renewal, and revocation centrally.

emCA issues certificates containing public keys and identity information. Relying parties use these certificates to verify identities in online transactions. It uses cryptographic algorithms to protect data integrity and confidentiality.

emCA records certificate operations and maintains compliance with industry standards and regulations. It supports audit requirements and external reviews. It can be deployed in finance, healthcare, and government sectors.

emCA includes a web interface and automation features for certificate workflows. It provides tools for monitoring certificate status and performing lifecycle operations.

## Technical Highlights

**Designed for Scalability**

emCA connects to existing IT environments via standard protocols and supports both on-premises and cloud deployments.

**Management Tools**

emCA management tools enable administrators to monitor certificate status and carry out lifecycle operations, such as issuance, renewal, revocation and expiration. Audit logs and reporting functions record each action for compliance and review.

**CA Supporting Modules**\
emCA includes modules for Online Certificate Status Protocol (OCSP), timestamping, and Registration Authority (RA) operations. Each module integrates with the core certificate-issuance engine under a unified platform.

**PKI Framework Integration**\
emCA integrates with public key infrastructures via standard protocols and includes:

* **EAL 4+ Common Criteria Certification**\
  emCA has been evaluated at Evaluation Assurance Level 4+ under the Common Criteria standard (ISO/IEC 15408), confirming conformity to defined assurance requirements.
* **Post-Quantum Cryptography Support**\
  emCA can issue certificates using NIST-approved post-quantum algorithms (for example, Dilithium, Falcon, Sphincs+), enabling deployment of quantum-resistant key pairs.

**RA Integration, Migration & Compliance**

emCA simplifies RA integration, migration of existing certificate infrastructures, and maintains compliance with WebTrust standards.

* **RA Integration**

  Integrates with Registration Authority systems via REST APIs and LDAP to automate certificate request submission and approval.
* **Migration Tools**

  Supports migration of existing certificate inventories, CA hierarchies, and policy configurations using import utilities and guided wizards with minimal service interruption.
* **Compliance**

  Aligns with WebTrust and CA/B Forum compliance for Certification Authorities by generating audit logs and operational controls for external audits and regulatory reviews.

**IoT and Remote Signing Support**

* **IoT Certificate Issuance**\
  Issues certificates for Internet of Things devices via standard enrolment protocols (for example, SCEP and EST), enabling secure device authentication and communications.
* **ETSI-Compliant Remote Signing**\
  Supports ETSI-compliant remote signing for both short-lived and long-lived key pairs, in line with digital-signature workflows and mobile-authentication requirements.

## Key Features

**Hierarchy and Policy Management**

* Manages root, subordinate, and issuing CAs in one system, each with independent policy sets.
* Defines certificate/CRL formats, validity rules, revocation methods (OCSP, CRL, delta-CRL), distribution points, and key usages per profile.

**Certificate Types**

* Device certificates for machines and IoT devices.
* SSL/TLS certificates for web‐server encryption.
* Code‐signing certificates for software integrity.
* S/MIME email certificates for message encryption and signing.
* Client certificates for application and service authentication.
* Document‐signing certificates for electronic documents.
* Extended‐Validation (EV) certificates under CAB Forum requirements.
* EMV certificates for payment‐card security.
* CVC certificates for card verification codes.

**Certificate Transparency**

* Publishes certificate entries to trusted logs per RFC 6962.
* Embeds Signed Certificate Timestamps (SCTs) in issued certificates.

**Algorithm Support**

* **Traditional:** DSA, RSA, ECC (secp-192/256/384/521; brainpool curves; prime224v1; Ed25519), SHA-2 family.
* **Post-Quantum:** NIST-approved schemes (CRYSTALS-Dilithium2/3/5; Falcon-512/1024; SPHINCS+).

**Protocol Support**

* SCEP, CMP, ACME, EST for automated enrolment and renewal.
* SOAP and REST APIs for certificate requests, renewals, revocations, and status checks.

**Integration and Interfaces**

* **LDAP:** Active Directory and OpenLDAP integration; automated distribution of certificates and CRLs; LDIF export; LDAP v3 compliance (RFC 4519, RFC 4524).
* **SAML:** Single Sign-On support via existing SAML-based IAM systems.
* **OID Management:** Predefined and custom OIDs for subject attributes (e.g., Country, Organization, Common Name, Serial Number).

**Stand-Alone Utilities**

* **Root CA Offline:** Desktop utility compatible with TEMPEST-rated machines.
* **API Gateway:** Secure, signed, and encrypted SOAP/REST interfaces for third-party integration (for example, sign servers and eMudhra portals).

**Localization**

* Supports multi-language certificate values and mixed-language subject fields.

**Authentication Controls**

* Enforces digital-signature certificates on FIPS-certified tokens for administrator access.
* Integrates with external MFA systems (for example, Active Directory, IDAM).

## How emCA works?

emCA is implemented in Java and runs on any JVM-compatible environment. It is hardware-agnostic and no dependencies on a specific server or appliance.

**Core Components**

* **Application Engine**\
  Deployed as a standalone WAR/EAR in any Java EE container.
* **Persistence Layer**\
  Stores certificates, policies, and audit records in a relational database (for example, PostgreSQL or MySQL).
* **Cryptographic Module**\
  Integrates with any FIPS-compliant HSM via PKCS#11 or uses a software keystore for key storage.
* **APIs**\
  REST endpoints for automated certificate requests, renewals, revocations, and status checks.

**Integrations**

* **Directory Services**\
  Connects to LDAP systems (for example, Active Directory, OpenLDAP) for user and RA data.
* **External CAs**\
  Supports chaining to external root CAs and cross-certification workflows.
* **Logging & Audit**\
  Writes compliance logs to both database and filesystem for external review.

**Deployment Modes**

* **Standalone**\
  Single-node installation for small-scale or test environments.
* **Clustered**\
  Multi-node setup, load-balanced, and fail-over capable for high availability.

## Licensing

emCA is available under different license models tailored to deployment and usage requirements:

* **Perpetual License**\
  One-time purchase for on-premises installation. Includes an initial 12-month maintenance and support terms, annual renewals available thereafter.
* **Instance-Based License**

  Priced by the total number of emCA application instances deployed, regardless of issuance volume.
* **Subscription License**\
  Term-based (annual or multi-year) license covering software use, updates, and support. Scales by number of CAs or certificate-issuance volume.
* **Capacity-Based License**\
  Tiered by certificate-issuance throughput (for example, Certificate per year). Allows alignment of licensing costs with operational demands.
* **Managed-Service License**\
  Hosted deployment under a service-level agreement. Covers software, infrastructure, and managed support.

Licenses are issued with defined expiration dates and must be renewed prior to expiry to maintain uninterrupted operation and access to updates. License entitlements, such as feature bundles and support levels vary by model and tier.

## Use Cases

emCA supports a wide range of use cases for diverse applications and industries. Here are a few typical emCA use cases.

**National PKI**

* **CA Hierarchy Deployment**
  * Configure root, subordinate, and issuing CAs with emCA’s CA setup tools
  * Define and publish Certificate Policy and Practice Statement (CP/CPS)
* **RA Management**
  * Verify entity identities via the RA module
  * Automate certificate request approvals
* **Key Management & Distribution**
  * Generate, store, and distribute cryptographic keys
  * Issue certificates over secure channels or hardware tokens
* **Regulatory Compliance**
  * Enforce legal and regulatory frameworks via policy controls
  * Support audit and incident-response planning

**EMV Payment-Card PKI**

* **Certificate Lifecycle**
  * Issue, renew, and revoke EMV certificates for cards and terminals
  * Maintain audit logs and reporting for PCI DSS compliance
* **Transaction Security**
  * Enable card and terminal authentication
  * Support offline transactions with signed data

**ePassport PKI**

* **Basic Access Control (BAC)**
  * Manage Country Signing Certificate Authority (CSCA) and Document Signers
  * Issue certificates for chip data signing
* **Extended Access Control (EAC)**
  * Configure Card Verifiable Certificate Authority (CVCA) and DVCAs
  * Issue terminal and verifier certificates

**Smart-Device PKI (Energy Sector)**

* **Enrolment & Issuance**
  * Enroll smart meters and IoT devices via REST/SCEP requests
  * Bind device identifiers to public keys in issued certificates
* **Trust & Data Security**
  * Establish trust between devices and central systems
  * Sign and encrypt meter data for transmission

**Industrial IoT Security**

* **Large-Scale Certificate Management**
  * Automate issuance, renewal, suspension, and revocation at scale
  * Support REST, SOAP\[R1] , SCEP, and SAML for device workflows
* **Security Controls**
  * Apply PKI-based encryption and digital signatures
  * Align device-identity policies with organizational standards

## EAL 4+ Certification

**EAL 4+ Functionalities in emCA**

* **Access Control**\
  Enforces role-based policies for administrative and operator functions.
* **Auditability**\
  Records security-relevant events for review and compliance.
* **Data Protection**\
  Applies approved cryptographic measures to data at rest and in transit.
* **System Integrity**\
  Validates tamper resistance of code and configurations.
* **Secure Communications**\
  Uses encrypted channels for all management interfaces.
* **Authentication**\
  Requires multi-factor methods for administrator access.
* **Security Function Reliability**\
  Verifies feature execution under defined test conditions.
* **Lifecycle Management**\
  Follows defined processes for updates, patches, and re-evaluation.

**References**

* Scheme: Singapore Common Criteria Scheme (SCCS; EAL4+ ALC\_FLR.2) [Cyber Security Agency of Singapore](https://www.csa.gov.sg/our-programmes/certification-and-labelling-schemes/singapore-common-criteria-scheme/product-list/emudhra-certification-authority--emca--v4-0-3?utm_source=chatgpt.com).
* Validity: 11 Feb 2022 – 11 Feb 2027 [Cyber Security Agency of Singapore](https://www.csa.gov.sg/our-programmes/certification-and-labelling-schemes/singapore-common-criteria-scheme/product-list/emudhra-certification-authority--emca--v4-0-3?utm_source=chatgpt.com).


# Key Components

emCA suite has following Solution components

### Certificate Manager – emCA

Handles the full certificate lifecycle (issuance, renewal, revocation, archival).

* &#x20;Manages certificate lifecycle: issuance, renewal, revocation.
* Role-based access control and M-of-N separation of duties.
* Multi-factor authentication using token-based certificates.
* Protocol support: SCEP, CMP, EST for automated issuance.
* Certificate Transparency support.
* CSR signing and cross-certification workflows.
* Multi-HSM support (PKCS#11 compliant).
* OCSP certificate generation and management.
* Mobile PKI support.

### User Enrolment – emRA

Manages KYC data and certificate requests across RAs.

* Decentralized portals for RA-wise KYC and certificate requests.
* Configurable vetting profiles and verification checklists.
* Role-based dashboards with RA-level data segregation.
* Strong authentication: password policies and 2FA.
* Subscriber self-service for certificate management.
* Integration with email/SMS notifications, video and document-upload verification.
* eSign-enabled, paperless enrolment workflows.

### Online Certificate Status Protocol (OCSP)

Provides real-time certificate status checking.

* Response generation per RFC 6960/5019 and CA/B Forum rules.
* HSM-based signing key storage.
* Real-time record display and archival.

### Time Stamping Module

Issues RFC 3161/5816-compliant timestamps.

* Time-source integration (GPS - Global Positioning System, NTP – Network Time Protocol, NPL - National Physical Laboratory).
* TST generation and signature by internal TSA.
* Audit logging of timestamp events.
* Policy-based issuance exclusively for internal use.

### Key Management Module

Oversees cryptographic key generation, rotation, and retirement.

* Secure key creation.
* Rotation and expiry policies.
* Integration with FIPS-compliant HSMs.

### Hardware Security Module Integration

Supports hardware-backed key storage and operations.

* Private-key protection in hardware.
* Hardware-based cryptographic functions.
* Resistance to physical and logical tampering.


# Architecture

emCA is deployed in high-availability mode against a database cluster. Components are isolated into five zones, with all inter-zone communication authenticated.

<figure><img src="/files/o5AffpiMSMa2dI3U4BFx" alt=""><figcaption></figcaption></figure>

The diagram shows a Deployment architecture, containing five main zones:

* **Security Zone:** Firewall and load balancer enforce access controls for incoming and outgoing traffic.
* **Application Zone:** Hosts the certificate enrolment service, OCSP/LDAP endpoint, and TSA for timestamping. The certificate enrolment server is responsible for issuing certificates to clients. The OCSP/LDAP server provides information about the status of certificates, such as whether they are revoked. The TSA provides timestamps for certificates, which can be used to verify their validity.
* **Directory and Validation Services Zone:** This zone contains the LDAP, OCSP, and CRL servers. The LDAP server stores information about users and certificates. The OCSP server provides information about the status of certificates. The CRL server provides a list of revoked certificates.
* **Certificate Management zone:** This is responsible for managing the certificates that are issued to clients. It includes the certificate authority (CA), policy authority (PA), and database cluster. The CA is responsible for issuing certificates. The PA defines the policies that govern how certificates are issued and managed. The database cluster stores information about certificates, users, and other PKI entities.
* **HSM (Hardware Security Module):** This a secure device that stores the CA's private keys. It is used to sign certificates and other PKI entities.


# Algorithm Support

emCA supports the following cryptographic algorithms for certificate and signature operations:

**Traditional Cryptography Algorithms**

* **DSA (Digital Signature Algorithm)**\
  Compliant with FIPS 186-4 for digital signatures.
* **RSA**\
  Implements PKCS #1 v2.2 with key sizes from 2048 to 4096 bits.

**ECC Algorithms**

emCA supports a variety of Elliptic Curve Cryptography (ECC) algorithms, including:

* secp192r1 (NIST P-192)
* secp256r1 (NIST P-256)
* secp384r1 (NIST P-384)
* secp521r1 (NIST P-521)
* brainpoolP256r1, brainpoolP384r1, brainpoolP512r1
* prime224v1, prime256v1
* Ed25519 (RFC 8422)


# Types of Certificates Supported

emCA supports various certificate types that address diverse requirements across sectors. Each certificate type is issued and managed in accordance with established standards and protocols.

## X509

Based on the [ITU‑T X.509 standard](https://en.wikipedia.org/wiki/X.509?utm_source) for public key certificate formats.

* Widely used in SSL/TLS for securing web servers and encrypted communications.
* Support digital signature certificates (DSC) for electronic document signing and eAuthentication.
* Enable client/server authentication for applications, email encryption (S/MIME), and identity verification.
* Applicable in enterprise IT, government services, and regulated sectors.

## EVM Certificates

Support authentication of EMV chip cards and terminals as required under [PCI DSS](https://www.pcisecuritystandards.org/).

* Used in payment ecosystems to secure transactions between cards, terminals, and issuers.
* Commonly deployed by banks, payment processors, and card manufacturers.

## CVC Certificates

Commonly used in ePassports and national ID documents under the [Extended Access Control (EAC) framework](https://www.cryptovision.com/wp-content/uploads/2023/05/IDnomic_ePassPKI_042023.pdf?utm_source=chatgpt.com). These support secure verification of biometric data and identity.

**ePassport PKI (ICAO Standards)**\
Conforms to [ICAO Doc 9303](https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03110/tr-03110.html) standards for ePassport PKI infrastructure.

## C-ITS / ECA Certificates

Cooperative Intelligent Transport Systems used for authentication and message signing in connected vehicle environments, governed by the [EU C‑ITS Certificate Policy](https://cpoc.jrc.ec.europa.eu/data/documents/E01941_C-ITS_Certificate_Policy_Release_3_0_FINAL.pdf?utm_source=chatgpt.com) (release 3.0, 2024)

* Facilitate secure communication in connected vehicles and roadside infrastructure.
* Support message signing and authentication for safety applications in **V2X** (Vehicle-to-Everything) ecosystems.
* Applied in intelligent transport systems, automotive OEMs, and regulatory frameworks for traffic safety.

## SSH Certificates

* Provide secure authentication for server access, replacing static SSH keys.
* Support Privileged Access Management (PAM) systems to control administrator and operator logins.
* Applied in enterprise IT operations, DevOps environments, and cloud infrastructure management.

## Qualified Certificates under eIDAS / ZertES

Issued by accredited providers under EU eIDAS or Swiss ZertES frameworks.

These certificates and advanced electronic signatures (PAdES, XAdES, CAdES) carry legal recognition equivalent to handwritten signatures across Europe.

## Certificate Support - Summary Table

| **Certificate Type**                  | **Use Cases & Sectors**                            |
| ------------------------------------- | -------------------------------------------------- |
| X.509                                 | SSL/TLS, DSC, secure authentication, enterprise IT |
| EMV                                   | Card payments, banking, transaction security       |
| CVC (EAC)                             | ePassport, national eID, biometric systems         |
| ICAO ePassport PKI                    | International travel documents validation          |
| C-ITS / ECA                           | V2X communications, intelligent transport          |
| SSH Certificates                      | PAM, server access control, IT infrastructure      |
| Qualified Certificates (eIDAS/ZertES) | Legally recognized e-signatures in EU/Switzerland  |


# Post-Quantum Cryptography (PQC)

In addition to traditional cryptography algorithms, emCA supports NIST -PQC algorithms, to ensure cryptographic security against potential quantum computing threats:

* **CRYSTALS-Dilithium** (NIST Round 3 signature scheme)
  * Level 2, Level 3, Level 5 parameter sets
* **Falcon** (NIST Round 3 signature scheme)
  * Falcon-512, Falcon-1024
* **SPHINCS+** (Hash-based signature scheme per NIST)
  * Variants based on different hashing schemes (e.g., SHA2-based, Haraka-based)


# Security

The security architecture of emCA ensures the protection of the CA’s private key and issued certificates against physical, logical, and network threats.

<figure><img src="/files/aV4ZojWiThLECm2OvP10" alt=""><figcaption></figcaption></figure>

**Physical Security**

* **HSM (Hardware Security Module)**\
  The CA’s private key is stored in an HSM, which provides tamper detection and key destruction in the event of physical attacks.
* **Isolation**\
  The HSM is isolated from the rest of the emCA system to prevent physical and side-channel attacks.

**Logical Security**

* **Encryption**\
  All communication between emCA components is encrypted using TLS/SSL protocols to protect data integrity and confidentiality.
* **Access Control**\
  emCA restricts access to authorized users through role-based access control (RBAC), multi-factor authentication (MFA), and audit logging.
* **Audit Logging**\
  emCA logs all activities for monitoring and security incident detection.

**Data Security**

* **Encryption at Rest and in Transit**

  Sensitive data, certificate metadata, and audit logs, is encrypted at rest and in transit using AES-256.
* **Key Management**\
  Private keys are securely stored, with strict access control policies enforced.
* **Backup and Recovery**\
  Data backups are encrypted and stored in secure, access-controlled environments. Backup data retention and disposal are managed according to defined lifecycle policies to ensure compliance.

**Role Based Access Control**

To ensure security, the emCA application is designed such that each role has a unique set of permissions. The following are the roles and their corresponding duties.

**CA Administrator**

* **Initial setup:** Completes the initial setup process of the emCA application.
* License registration: Generates a license request and uploads the license to register the emCA application.
* **User management:** Creates and manages Administrator users.
* **Certificate authority (CA) management:** Deletes Root CA, CA, and Sub/Issuing CA certificates and key pairs.

**Administrator**

* **Certificate profile management:** Creates and manages certificate profiles.
* **Key profile management:** Creates and manages key profiles.
* **User management:** Creates and manages Officer, Auditor, and Operator users.

**Officer**

* **CA key generation:** Generates CA keys.
* **CA hierarchy management:** Creates and manages the CA hierarchy.
* **Certificate revocation list (CRL)/Online Certificate Status Protocol (OCSP) service management:** Creates and manages CRL/OCSP services.
* **Certificate management:** Creates and manages CA, user, and OCSP certificates using certificate profiles created by the Administrator.
* **Scheduler configuration:** Configures the scheduler.
* **Certificate revocation and reinstatement:** Revokes and reinstates certificates as needed.
* **Key recovery:** Performs complete key recovery activities.

**Auditor**

* **Audit log management:** Views and downloads audit logs.
* **Report generation:** Generates various types of reports.

**Operator**

* Backup and restore: Performs backup and restore operations.


# Security Support and Cybersecurity Updates Policy

**Security Support Commitment**

eMudhra Limited is committed to maintaining the security and integrity of emCA Certificate Manager throughout its operational lifecycle. This document outlines our security support policy and the availability of cybersecurity updates for emCA v5.0.0 and subsequent releases.

### Security Support Period

#### emCA v5.0.0 Security Support Duration: 5 Years

* General Availability Date: December 15, 2025
* Security Support End Date: December 15, 2030
* Extended Support: Available upon request for mission-critical deployments

#### What Security Support Includes:

Critical Security Patches

* Vulnerabilities rated CVSS 9.0-10.0 (Critical): Patch released within 72 hours of verification
* Vulnerabilities rated CVSS 7.0-8.9 (High): Patch released within 7 days of verification
* Vulnerabilities rated CVSS 4.0-6.9 (Medium): Patch released within 30 days of verification
* Vulnerabilities rated CVSS 0.1-3.9 (Low): Addressed in quarterly maintenance releases

#### Security Update Delivery Mechanisms

1. Security Advisory Notifications

Registered customers receive immediate notifications via:

* Email alerts to designated security contacts
* Postings on the emCA Support Center

2. Patch Distribution Channels

Security updates are distributed through:

* Direct Support Delivery: Critical patches delivered directly by eMudhra support engineers for high-assurance environments

3. Update Package Integrity

All security updates are:

* Digitally signed using eMudhra's code signing certificate
* Accompanied by SHA-256 hash verification values

### Version Support Policy

Current Version (v5.0.0 and later)

* Full Security Support: 5 years from General Availability
* All security updates provided as outlined above
* Technical support for security-related issues available 24/7/365 for Enterprise customers

#### Previous Versions (Last 5 versions)

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><strong>Version</strong></td><td valign="top"><strong>Release Date</strong></td><td valign="top"><strong>Security Support End Date</strong></td><td valign="top"><strong>Status</strong></td></tr><tr><td valign="top">V5.0.0</td><td valign="top">Dec 15, 2025</td><td valign="top">Dec 15, 2030</td><td valign="top">Supported</td></tr><tr><td valign="top">v4.3.1</td><td valign="top">Jul 10, 2025</td><td valign="top">Jul 10, 2030</td><td valign="top">Supported</td></tr><tr><td valign="top">v4.2.7</td><td valign="top">May 30, 2025</td><td valign="top">May 30, 2030</td><td valign="top">Supported</td></tr><tr><td valign="top">v4.2.6</td><td valign="top">Jan 01, 2025</td><td valign="top">Jan 01, 2030</td><td valign="top">Supported</td></tr><tr><td valign="top">v4.2.5</td><td valign="top">Sep 19, 2024</td><td valign="top">Sep 19, 2029</td><td valign="top">Supported</td></tr></tbody></table>

{% hint style="info" %}
**Note:** Customers using versions approaching end-of-support are strongly encouraged to upgrade to the latest version to continue receiving security updates.
{% endhint %}

### Vulnerability Response Process

Vulnerability Identification

eMudhra actively monitors security vulnerabilities through:

* Internal security testing and code audits
* Third-party penetration testing
* Responsible disclosure program (see Security Contact information)
* Mention a point about CVE tracking

### Compliance with Regulatory Requirements

Compliance updates with:

* eIDAS Regulation: Trust service provider obligations
* Common Criteria EAL4+ Certification: Security update procedures maintain certification compliance
* ISO/IEC 27001: Information security management systems
* GDPR Compliance: [eMudhra | Data Security - India](https://emudhra.com/en-in/data-security)

### Customer Responsibilities

To ensure continuous security support, customers must:

1. Register Security Contacts: Maintain current contact information in the emCA Support Portal
2. Monitor Security Advisories: Subscribe to security notifications and regularly check the advisory portal
3. Test Updates Promptly: Evaluate security updates in non-production environments within 7 days of release
4. Deploy Critical Patches: Apply critical security updates within timeframes specified in security advisories
5. Report Vulnerabilities: Immediately report suspected security issues to <security@emudhra.com>
6. Maintain Supported Configurations: Operate emCA on supported platforms and with compatible versions of dependent components

### Security Support Resources

Documentation

* Patch Application Procedures: Step-by-step deployment instructions
* Rollback Procedures: Emergency recovery guidance

Technical Support

1. 24/7/365 Critical Security Support: Enterprise customers
2. Business Hours Support (Mon-Fri): Standard customers
3. Dedicated Security Response Team: For vulnerability reports and security incidents

### Contact Information

Security Support Email: <security@emudhra.com>\
General Support Portal: <https://support.emudhra.com>\
Vulnerability Reporting: <https://emca.emudhra.com/security/security-vulnerability-reporting-guidelines>

Contact Us: <https://emudhra.com/en-in/contact-us>

### Commitment Statement

eMudhra Limited is committed to the security of our customers and the integrity of the PKI ecosystems they operate. We continuously invest in security research, development, and support to ensure emCA Certificate Manager remains a trusted foundation for digital certificate management across cyber environments worldwide.


# Security Vulnerability Reporting Guidelines

**Vulnerability Disclosure and Contact Information**

eMudhra Limited welcomes reports of security vulnerabilities in emCA Certificate Manager from security researchers, customers, and the broader security community. We are committed to addressing security issues promptly and transparently in accordance with responsible disclosure practices.

### Primary Security Contact

Security Team Email: <security@emudhra.com>

Response Time Commitment:

* Initial acknowledgment: Within 24 hours (business days)
* Preliminary assessment: Within 48 hours
* Detailed response with timeline: Within 5 business days

### Manufacturer Information

**Company Name:** eMudhra Limited\
**Corporate Website:** <https://www.emudhra.com>\
**Product Support Portal:** [emCA Certificate Manager | emCA Certificate Manager Support Center](https://emca.emudhra.com/)\
**General Contact:** <https://emudhra.com/en-in/>\
**Emergency Security Hotline:** +91-80-46156902 (For critical vulnerabilities only - Enterprise customers)

### Accepted Methods for Reporting Vulnerabilities

#### Email Submission (Preferred Method)

To: <security@emudhra.com>

Subject Line Format: \[SECURITY] emCA Vulnerability Report - \[Brief Description]

Required Information:

* Your name and contact information
* Organization affiliation (if applicable)
* Product version affected (e.g., emCA v5.0.0)
* Vulnerability type (e.g., authentication bypass, SQL injection, privilege escalation)
* Detailed description of the vulnerability
* Steps to reproduce the issue
* Proof of concept (PoC) code or screenshots (if available)
* Potential impact assessment
* Suggested remediation (optional)
* Whether you plan to publicly disclose this vulnerability

#### Online Contact Form

URL: <https://emudhra.com/en-in/contact-us>

Instructions:

1. Select "Support" from the inquiry type dropdown
2. Provide all required information as listed above

#### Additional Security Resources

Security Documentation

* Security Support Policy: <security@emudhra.com>
* Security Advisories: <https://emudhra.com/security/advisories>

Security Compliance

* Common Criteria EAL4+ Certification: [eMudhra Certification Authority (emCA) v4.0.3 | Cyber Security Agency of Singapore](https://www.csa.gov.sg/our-programmes/certification-and-labelling-schemes/singapore-common-criteria-scheme/product-list/emudhra-certification-authority--emca--v4-0-3/?utm_source=chatgpt.com)
* GDPR Compliance: [eMudhra | Data Security - India](https://emudhra.com/en-in/data-security)
* eIDAS: [eMudhra | Data Security - India](https://emudhra.com/en-in/data-security)
* ISO 27001 Certification: [eMudhra | Data Security - India](https://emudhra.com/en-in/data-security)

#### Questions About This Policy

If you have questions about our vulnerability disclosure policy or the reporting process:

Email: <security@emudhra.com>\
Subject Line: \[POLICY QUESTION] Vulnerability Disclosure Process

We typically respond to policy questions within 2-3 business days.

#### Legal Safe Harbor

eMudhra commits to not pursue legal action against security researchers who:

1. Follow this vulnerability disclosure policy in good faith
2. Avoid privacy violations, data destruction, and service disruption
3. Do not exploit vulnerabilities beyond what is necessary for demonstration
4. Provide reasonable time for remediation before public disclosure

This safe harbour applies to potential violations of:

* Computer misuse laws
* Anti-circumvention provisions
* Terms of service

Note: This policy does not authorize testing against customer production environments. Always test against your own licensed instance of emCA or coordinate with us for access to test environments.

#### Policy Updates

This vulnerability disclosure policy is reviewed semi-annually and may be updated to reflect:

* Industry best practices evolution
* Legal and regulatory requirement changes
* Feedback from security research community
* Internal process improvements

Last Updated: December 15, 2025\
Next Review Date: June 15, 2026\
Policy Version: 1.0

#### Contact Summary

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><strong>Purpose</strong></td><td valign="top"><strong>Contact Method</strong></td><td valign="top"><strong>Response Time</strong></td></tr><tr><td valign="top">Report Security Vulnerability</td><td valign="top"><a href="mailto:security@emudhra.com">security@emudhra.com</a></td><td valign="top">24 hours acknowledgment</td></tr><tr><td valign="top">Critical Security Emergency</td><td valign="top">+91-80-46156902</td><td valign="top">Immediate (Enterprise customers)</td></tr><tr><td valign="top">Policy Questions</td><td valign="top"><a href="mailto:security@emudhra.com">security@emudhra.com</a></td><td valign="top">2-3 business days</td></tr><tr><td valign="top">General Product Support</td><td valign="top"><a href="https://emca.emudhra.com/">emCA Certificate Manager | emCA Certificate Manager Support Center</a></td><td valign="top">Per support SLA</td></tr><tr><td valign="top">Business Inquiries</td><td valign="top"><a href="https://emudhra.com/en-in/contact-us">https://emudhra.com/en-in/contact-us</a></td><td valign="top">1-2 business days</td></tr></tbody></table>


# Getting Started

This section covers the emCA deployment in your environment, from prerequisites, installation to initial setup and configuration.


# Deployment Models

emCA supports Single Instance, High Availability, Hybrid, and Cloud deployment models to meet diverse infrastructure needs. Each model is designed to offer flexibility in terms of scalability, reliability, and integration with existing systems.


# Single Instance

In a Single Instance deployment, the emCA application server, OCSP server, TSA server, and DB server are installed on individual servers within a secure zone. The Hardware Security Module (HSM) is isolated in a highly trusted zone to safeguard cryptographic keys.

<figure><img src="/files/c64HiR9Z6gOaovXqMaYH" alt=""><figcaption></figcaption></figure>

**Key Components**

* **emCA CA Application Server** **–** Generates and issues certificates, manages the CA’s certificate pool, and handles certificate lifecycle events.
* **Timestamping Authority (TSA) Server** **–** Issues trusted timestamps for digital signatures, maintaining long-term certificate validity and integrity.
* **OCSP Application Server –** Responds to Online Certificate Status Protocol requests to confirm certificate revocation status.
* **Database Server –** Stores CA certificate records, user data, device details, and related metadata.
* **Hardware Security Module (HSM) –** Secure, tamper-resistant storage for private keys and sensitive cryptographic material.
* **Offline emCA –** Provides certificate generation capability when the primary CA server is unavailable.
* **Network Access –** Accessible via internet or intranet for authorized certificate requests and management.

**Deployment**

All components are hosted on individual servers for each function within the secure zone. Network protection is enforced using routers and firewalls.

**Advantages**

* Simplified deployment and management.
* Lower infrastructure cost compared to distributed models.
* Suitable for organizations with moderate certificate issuance needs.

**Limitations**

* Limited scalability for high-volume environments.
* Single point of failure risk if a server is compromised or fails.

Requires strict configuration control and continuous security monitoring.


# High Availability

In a High Availability deployment, emCA components are clustered across multiple nodes to ensure uninterrupted service. A load balancer directs traffic to healthy servers and reroutes requests if a node fails. Two HSMs are deployed in a trusted zone for redundancy.

<figure><img src="/files/IWaPrj9KcIfNNOdoixGv" alt=""><figcaption></figcaption></figure>

**Key Components**

* **Load Balancer**\
  Distributes client requests, monitors server health, and redirects traffic on failure.
* **Clustered CA Servers**\
  Multiple emCA nodes handle certificate issuance, lifecycle events, and certificate pool management.
* **Redundant TSA Servers**\
  Provide timestamping services with failover capability.
* **Clustered OCSP Servers**\
  Host OCSP responders for real-time revocation status checks.
* **Database Cluster**\
  Multiple database instances store certificates, user data, and audit records with data replication.
* **HSM Cluster**\
  Two or more FIPS-compliant modules store private keys and sensitive material, ensuring key availability.

#### **Multi-Tenancy Support**

emCA natively isolates multiple tenants within one CA infrastructure:

* **Tenant Isolation**\
  Separate namespaces for certificates, CRLs, audit logs, and keys.
* **Dedicated Policies**\
  Tenant-specific certificate profiles, templates, and workflows.
* **Scoped RBAC**\
  Administrative roles confined to each tenant’s domain.
* **Horizontal Scaling**\
  Onboard additional tenants without impacting performance.
* **Tenant-Level Auditing**\
  Exportable logs for compliance reporting.


# Hybrid Deployment

The hybrid deployment model for emCA integrates cloud infrastructure with on-premises Hardware Security Modules (HSMs) to balance operational efficiency with stringent cryptographic security.

<figure><img src="/files/dTbkhPMGJsVIyfurchlP" alt=""><figcaption></figcaption></figure>

**Key Components**

* **Cloud-Hosted emCA Services**\
  emCA application servers, OCSP responders, TSA, and database run in a cloud environment (for example, AWS, Azure, GCP).
* **On-Premises HSMs**\
  Private keys and sensitive cryptographic material reside in local HSMs deployed in the data center or secure colocation.
* **Secure Connectivity**\
  VPN or dedicated private link encrypts all API calls between cloud components and on-premises HSMs.
* **Cloud Network Control**
  * Load balancer distributes traffic across cloud instances.
  * Web application firewall (WAF) filters HTTP threats.
  * Threat monitoring service (for example, GuardDuty) detects suspicious activity.


# Cloud Deployment

The cloud deployment model for emCA leverages AWS infrastructure to provide a secure, scalable, and high-availability environment for certificate management operations.

<figure><img src="/files/yblasnQpNlimB89IbWwg" alt=""><figcaption></figcaption></figure>

**Key Components**

* **Application Layer**\
  Two or more EC2 instances in public subnets, behind an Application Load Balancer. AWS WAF filters HTTP(S) traffic and GuardDuty monitors for threats.
* **Database Layer**\
  Two MySQL 8.0 RDS instances in private subnets, configured as master and replica for high availability.
* **Key Storage**\
  AWS CloudHSM cluster holds CA private keys and sensitive cryptographic material.
* **Persistent Storage**\
  Amazon EBS volumes provide durable storage for application and database data.
* **Networking Controls**\
  VPC subnets and security groups isolate services, routing and VPN links secure hybrid connections.
* **Operational Notes**
  * Auto Scaling groups adjust EC2 capacity to demand.
  * RDS Multi-AZ deployment ensures failover capability.
  * All inter-service communication uses encrypted channels.


# Installation Guide

**Deployment of emCA Components**

This section provides the detailed steps involved in the deployment of the following components of emCA (eMudhra’s Certificate Lifecycle Manager) product and its related components.

**Components and WAR Files**

* emCA Core (emCA.war)
* emCA API (emCAServices.war)
* OCSP Core (OcspResponderCore.war)
* OCSP Responder (OcspResponderWeb.war)
* TSA Core (emTSA.war and eTSA.war)
* TSA Web (WebTSA.war)
* emCA Scheduler (scheduler.war)
* LDAP

**Deployment Notes**

* Install each WAR file on the application server according to its standard deployment procedure.
* Configure database connectivity via JNDI or data source definitions.
* Integrate the LDAP server for user and RA lookups.
* Ensure network and security settings permit inter-component communication.


# Prerequisites

The following table summarizes the overall deployment recommendations for emCA components. These recommendations are based on a logical partitioning of the various services that must run to support a minimum Certifying Authority infrastructure.&#x20;

For production environments, it is recommended to install each component on a separate physical server or virtual machine.

| ***Component***                       | **Server Requirement** | **Configuration**                                 |
| ------------------------------------- | ---------------------- | ------------------------------------------------- |
| *emCA Core*                           | Physical or Virtual    | High Availability – configured to a load balancer |
| *emCA API*                            | Physical or Virtual    | High Availability – configured to a load balancer |
| *OCSP Core*                           | Physical or Virtual    | High Availability – configured to a load balancer |
| *OCSP Responder Web*                  | Physical or Virtual    | High Availability – configured to a load balancer |
| *Timestamping Authority Core*         | Physical or Virtual    | High Availability – configured to a load balancer |
| *Timestamping Authority Web*          | Physical or Virtual    | High Availability – configured to a load balancer |
| *LDAP*                                | Physical or Virtual    | High Availability                                 |
| *Database for emCA Core*              | Physical or Virtual    | Clustered                                         |
| *Database for Timestamping Authority* | Physical or Virtual    | Clustered                                         |

### Hardware Requirements <a href="#toc82804551" id="toc82804551"></a>

The hardware requirements listed below are the minimum recommended requirements.&#x20;

The product may function at lower configurations for test or proof-of-concept (PoC) environments, but the performance and user experience may not be guaranteed, and there could be slowness or intermittent errors.

#### Application Server <a href="#toc82804552" id="toc82804552"></a>

**emCA Core and API**

| ***No. of Servers***                        | **2 Nos. for High Availability**                         |
| ------------------------------------------- | -------------------------------------------------------- |
| *Server Configuration:*                     | Can either by physical server or virtual machines        |
| *Processor*                                 | Quad-Core Processor (Intel Xeon Recommended) with 2.6GHz |
| *RAM*                                       | 8 GB                                                     |
| *Storage*                                   | 100 GB                                                   |
| *Hardware Security Module (HSM) (Optional)* | Any FIPS Certified Hardware Security Module (HSM)        |

**OCSP Core & Time Stamping Authority Core**

| ***No. of Servers***                        | **2 Nos. for High Availability**                         |
| ------------------------------------------- | -------------------------------------------------------- |
| *Server Configuration:*                     | Can either by physical server or virtual machines        |
| *Processor*                                 | Quad-Core Processor (Intel Xeon Recommended) with 2.6GHz |
| *RAM*                                       | 8GB                                                      |
| *Storage*                                   | 100GB                                                    |
| *Hardware Security Module (HSM) (Optional)* | Any FIPS Certified Hardware Security Module (HSM)        |

**OCSP Web and Time Stamping Authority Web**

| ***No. of Servers***    | **2 Nos. for High Availability**                         |
| ----------------------- | -------------------------------------------------------- |
| *Server Configuration:* | Can either by physical server or virtual machines        |
| *Processor*             | Quad-Core Processor (Intel Xeon Recommended) with 2.6GHz |
| *RAM*                   | 8GB                                                      |
| *Storage*               | 100GB                                                    |

**LDAP**

| ***No. of Servers***    | **2 Nos. for High Availability**                         |
| ----------------------- | -------------------------------------------------------- |
| *Server Configuration:* | Can either by physical server or virtual machines        |
| *Processor*             | Quad-Core Processor (Intel Xeon Recommended) with 2.6GHz |
| *RAM*                   | 8GB                                                      |
| *Storage*               | 100GB                                                    |

#### Database Server <a href="#toc82804557" id="toc82804557"></a>

**emCA Core & API**

| ***No. of Servers***    | **Depends on configuration (Master – Slave or Clustered architecture \*)** |
| ----------------------- | -------------------------------------------------------------------------- |
| *Server Configuration:* | Can either by physical server or virtual machines                          |
| *Processor*             | Quad-Core Processor (Intel Xeon Recommended) with 2.6GHz                   |
| *RAM*                   | 16GB                                                                       |
| *Storage*               | 250GB                                                                      |

**Time stamping Authority Core**

| ***No. of Servers***    | **Depends on configuration (Master – Slave or Clustered architecture \*)** |
| ----------------------- | -------------------------------------------------------------------------- |
| *Server Configuration:* | Can either by physical server or virtual machines                          |
| *Processor*             | Quad-Core Process (Intel Xeon Recommended) with 2.6GHz                     |
| *RAM*                   | 16GB                                                                       |
| *Storage*               | 250GB                                                                      |

\* Please refer to the client-specific hardware specification recommendation document

### Software Requirements <a href="#toc82804560" id="toc82804560"></a>

**Application Servers**

**emCA, OCSP & Timestamping Authority**

| ***Item***           | **Description**                                                            |
| -------------------- | -------------------------------------------------------------------------- |
| *Operating System*   | Support for RHEL 7+, Ubuntu v18+, CentOS v7+, Windows Server Edition 2016+ |
| *Application Server* | Tomcat v 11+, JBOSS v7+, Websphere v8+, Weblogic v10+                      |
| *JAVA Environment*   | JDK 21                                                                     |

#### Database Server <a href="#toc82804563" id="toc82804563"></a>

**emCA & Timestamping Authority**

| *Item*             | Description                                                                |
| ------------------ | -------------------------------------------------------------------------- |
| *Operating System* | Support for RHEL 7+, Ubuntu v18+, CentOS v7+, Windows Server Edition 2019+ |
| *Database Server*  | MySQL v 8+                                                                 |

### Network Specifications <a href="#toc82804566" id="toc82804566"></a>

#### Domain Names <a href="#toc82804567" id="toc82804567"></a>

| ***Record Type*** | **Name**             | **Function**                                                                  | **Value**  | **Weight** | **Visibility** |
| ----------------- | -------------------- | ----------------------------------------------------------------------------- | ---------- | ---------- | -------------- |
| *A*               | emca.example.com     | This is required for accessing emCA web application internally                | IP address | NA         | Trusted Zone   |
| *A*               | Ocspcore.example.com | This is required for accessing OCSP Responder internally                      | IP Address | NA         | Trusted Zone   |
| *A*               | TSAcore.example.com  | This is required for accessing TSA application internally                     | IP Address | NA         | Trusted Zone   |
| *A*               | emcaapi.example.com  | This is required for accessing emCA web application internally                | IP address | NA         | Trusted Zone   |
| *A*               | Ocsp.example.com     | This is required for accessing OCSP Responder externally (Internet/Intranet)  | IP Address | NA         | DMZ            |
| *A*               | TSA.example.com      | This is required for accessing TSA application externally (Internet/Intranet) | IP Address | NA         | DMZ            |

### Firewall Policies

| ***Source***                                                   | **Destination**             | **Port**                         | **Protocol** | **Action** | **Comment**                                                                                                                                                                                                |
| -------------------------------------------------------------- | --------------------------- | -------------------------------- | ------------ | ---------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| *emCA Core App Server*                                         | emCA Core DB Server         | 3306 & 6446 (MySQL)              | TCP          | Add        | Access from app to db server                                                                                                                                                                               |
| *emCA API App Server*                                          | emCA Core DB Server         | <p>3306 & 6446</p><p>(MySQL)</p> | TCP          | Add        | Access from app to db server                                                                                                                                                                               |
| *OCSP Core App Server*                                         | emCA Core DB Server         | <p>3306 & 6446</p><p>(MySQL)</p> | TCP          | Add        | Access from app to db server                                                                                                                                                                               |
| *TSA Core App Server*                                          | TSA Core DB Server          | <p>3306 & 6446</p><p>(MySQL)</p> | TCP          | Add        | Access from app to db server                                                                                                                                                                               |
| *OCSP Responder App Server*                                    | OCSP Core APP Server        | 8080/443/80                      | TCP          | Add        | Access from app-to-app server                                                                                                                                                                              |
| *TSA Web App Server*                                           | TSA Core App Server         | 8080/443/80                      | TCP          | Add        | Access from app-to-app server                                                                                                                                                                              |
| *TSA Web App Server*                                           | TSA Core DB Server          | <p>3306 & 6446</p><p>(MySQL)</p> | TCP          | Add        | Access from app to db server                                                                                                                                                                               |
| *emCA App Server*                                              | LDAP Server                 | 389/636                          | TCP          | Add        | For updating Certificates & CRLs                                                                                                                                                                           |
| *Console*                                                      | emCA Servers                | 3389                             | RDP          | Add        | To access emCA servers remotely – Internal RDP within the Enterprise network.                                                                                                                              |
| *User Machines*                                                | TSA, emCA and OCSP webpages | 443/80                           | HTTP, HTTPS  | Add        | For accessing TSA, OCSP and emCA webpages of emsigner from user’s machine                                                                                                                                  |
| *Internet Users*                                               | TSA                         | 443/80                           | HTTP, HTTPS  | Add        | External users accessing internet application                                                                                                                                                              |
| *Internet User*                                                | OCSP                        | 80                               | HTTP         | Add        | For external users                                                                                                                                                                                         |
| emBridge - installed on User machine (Client-side application) | For emCA application        | 26769 & 26770                    | TCP          | Add        | This port needs to be opened on the machine where emCA application will be accessed. The reason being web based emCA application invokes and makes connection with the emBridge (client-side application). |
| *HSM Client installed on the server*                           | HSM                         | 9000/9004                        | TCP          | Add        | This is required to access and manage HSM                                                                                                                                                                  |

#### IP Address Requirements

In case the Enterprise intend to deploy applications in HA mode then additional servers and load balancers as mentioned below are required

| ***Server/Application***                                                  | **IP Address - Internal** |
| ------------------------------------------------------------------------- | ------------------------- |
| *emCA core and API Application Server 1*                                  |                           |
| *emCA core and API Application Server 2*                                  |                           |
| *Software/Hardware Load Balancer for emCA core and API applications*      |                           |
| *emCA core and API Database Server 1*                                     |                           |
| *emCA core and API Database Server 2*                                     |                           |
| *OCSP core and TSA Core Application Server 1*                             |                           |
| *OCSP core and TSA Core Application Server 2*                             |                           |
| *Software/Hardware Load Balancer for OCSP core and TSA Core applications* |                           |
| *TSA Core Database Server 1*                                              |                           |
| *TSA Core Database Server 2*                                              |                           |
| *OCSP Responder and TSA Web Application Server 1*                         |                           |
| *OCSP Responder and TSA Web Application Server 2*                         |                           |
| *Software/Hardware Load Balancer for OCSP Web and TSA Web applications*   |                           |
| *LDAP Server*                                                             |                           |

### Database Requirement

The following applications require database. So, it is mandatory that the database is installed before proceeding with the deployment of applications.

* emCA Core
* emCA API *\[Uses the database installed for emCA Core. So separate installation of the database is not required]*
* TSA Core
* TSA Web *\[Uses the database installed for TSA Core. So separate installation of the database is not required]*

emCA uses a hibernate framework for cross-database support. As a result, it is compatible with any open source as well as Off The Shelf (OTS) databases.

### LDAP Requirement

This is an optional requirement. Mainly used for publishing certificates and CRLs and generation of LDIF files.&#x20;

The emCA application supports Active Directory and Open LDAP. The administrator can download LDAP from respective vendors’ website and then install the same.

Following link can be used to download OpenLDAP:

<https://www.openldap.org/software/download/>

For installation and configuration of OpenLDAP, documentation can be downloaded from below link:

<https://www.openldap.org/doc/>

Download and installation of LDAP is out of scope and should be done by the customer.


# Deployment Build Files

## emCA

This section describes the procedure for configuring the environment variables required for emCA.

### Configuration

{% hint style="info" %}
**Note:** All actions required for setting up and configuring emCA should be done using administrator privileges.
{% endhint %}

### **Environment Variables**

**For emCA.properties**

In emCA application deployment, the configuration of properties file is done through environment variables. In this case, the user has to place the emCA.properties file on the server and make a note of the location of properties file. The same path needs to be provided during environment variables configuration. This file is used to configure database, logs and truststore.

Following is the procedure for configuring emCA.properties file in environment variables. The same Variable Name that is defined below has to be used during configuration.

Variable name: <mark style="color:yellow;">EMCA\_CONFIGURATION\_PATH</mark>

Variable value: <mark style="color:yellow;">location of property files (emCA.properties)</mark>

#### For Java

To deploy emCA war, java environment has to be set. Please follow the below procedure. If it is already configured, then please ignore this step.

To correctly set the JAVA\_HOME variable for all users, you should choose the first option, "Edit the system environment variables." Here's the corrected instruction:

Search for Environment Variables:

* Type "environment variables" in the Windows search bar.
* Click on "Edit the system environment variables".

System Properties Window:

* In the System Properties window that opens, click on the "Environment Variables" button.

<figure><img src="/files/av4ccLznpJaWH478zB9l" alt=""><figcaption></figcaption></figure>

Edit System Variables:

* Under "System variables," find the JAVA\_HOME variable.
* If the variable exists:
* Select it and click "Edit."
* In the "Variable value" field, enter the full path to your JDK 21 installation directory (e.g., C \Program Files\Java\jdk-21.
* If the variable does not exist:
* Click "New."
* Enter JAVA\_HOME as the variable name.
* Enter the full path to your JDK 21 installation directory as the variable value.

&#x20;Save Changes:

* Click "OK" to save the changes in the Environment Variables window.
* Click "OK" to close the System Properties window.

<figure><img src="/files/IY4HPVU0erQAXEwTNqmb" alt=""><figcaption></figcaption></figure>

In emCA application deployment, the configuration of properties file is done through environment variables. In this case, the user has to place the emCA.properties file on the server and make a note of the location of properties file. The same path needs to be provided during environment variables configuration. This file is used to configure database, logs and truststore.

Following is the procedure for configuring emCA.properties file in environment variables. The same Variable Name which is defined below has to be used during configuration.

#### **For Windows**

Go to Advanced System Settings -> Click on Environment Variables -> Click on New; then Enter the following as shown below figure

Variable name: <mark style="color:yellow;">EMCA\_CONFIGURATION\_PATH</mark>

Variable value: <mark style="color:yellow;">location of property files (emCA.properties)</mark>

<figure><img src="/files/ISItIybmEMpE7QgBo5SH" alt=""><figcaption></figcaption></figure>

It is recommended to restart the system after setting the environment variables

#### **For Linux**

For setting environment variables in Linux run the following command

&#x20;             <mark style="color:yellow;">sudo -H gedit  /etc/environment</mark>

It will open the environment folder and set the emCA core path inside the folder.

<mark style="color:yellow;">EMCA \_CONFIGURATION\_PATH for emCA.properties file</mark>

<figure><img src="/files/GfEN7B64c1ZM6ugLg0pZ" alt=""><figcaption></figcaption></figure>

Once the Environment variable is set for emCA.properties, the user can open the emCA.properties to configure various options which include configuring of database as well as logs.

It is recommended to restart the system after setting the environment variables.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           &#x20;

### **Snapshot**

Please find below is the emCA.properties file snapshot along with description of properties:

```
#########################################################
##                 General Information                 ##
#########################################################
## Boolean values = "yes" or "no"                      ##
## String values  = base64 encoded                     ##
## Passwords      = encrypted with PasswordSecure.jar  ##
## Time intervals = in days if not specified otherwise ##
## Paths          = always absolute paths              ##
## Optionals      = set to empty if not needed         ##
## ENV Overrides  = Uppercase, dots -> underscores     ##
#########################################################

#######################################
##          MySQL Properties         ##
#######################################

# Hibernate Dialect
# ENV: DATASOURCE_HIBERNATE_DIALECT
datasource.hibernate.dialect=org.hibernate.dialect.MySQL8Dialect

# JDBC Configuration
# ENV: DATASOURCE_DRIVER_CLASS_NAME
datasource.driver.class.name=com.mysql.cj.jdbc.Driver

# ENV: EMCA_DATASOURCE_URL
emca.datasource.url=jdbc:mysql://localhost:3306/emca_prod

# ENV: EMCA_DATASOURCE_DEFAULT_TENANT_NAME
emca.datasource.default.tenant.name=emca_prod

# ENV: EMCA_DATASOURCE_APPLICATION_USERNAME
emca.datasource.application.username=emca_app

# ENV: EMCA_DATASOURCE_APPLICATION_PASSWORD
emca.datasource.application.password=EncryptedPasswordFor_emca_app

# ENV: DATASOURCE_HOST
datasource.host=localhost

# ENV: DATASOURCE_PORT
datasource.port=3306

# ENV: EMCA_DATASOURCE_ROLE_ACCESS_ENABLED
emca.datasource.role.access.enabled=true


########################################
##     Role-Based DB Credentials      ##
########################################

# CA Administrator
# ENV: EMCA_DATASOURCE_ROLE_CAADMINISTRATOR_USERNAME
emca.datasource.role.caadministrator.username=ca_admin

# ENV: EMCA_DATASOURCE_ROLE_CAADMINISTRATOR_PASSWORD
emca.datasource.role.caadministrator.password=EncryptedPasswordFor_ca_admin

# Administrator
# ENV: EMCA_DATASOURCE_ROLE_ADMINISTRATOR_USERNAME
emca.datasource.role.administrator.username=emca_admin

# ENV: EMCA_DATASOURCE_ROLE_ADMINISTRATOR_PASSWORD
emca.datasource.role.administrator.password=EncryptedPasswordFor_emca_admin

# Officer
# ENV: EMCA_DATASOURCE_ROLE_OFFICER_USERNAME
emca.datasource.role.officer.username=security_officer

# ENV: EMCA_DATASOURCE_ROLE_OFFICER_PASSWORD
emca.datasource.role.officer.password=EncryptedPasswordFor_emca_officer

# Auditor
# ENV: EMCA_DATASOURCE_ROLE_AUDITOR_USERNAME
emca.datasource.role.auditor.username=audit_user

# ENV: EMCA_DATASOURCE_ROLE_AUDITOR_PASSWORD
emca.datasource.role.auditor.password=EncryptedPasswordFor_emca_auditor


#############################################
##       Application Folder and Logging     ##
#############################################

# ENV: EMCA_APPLICATION_FOLDERS_LOCATION
emca.application.folders.location=/opt/emca/config

# ENV: EMCA_LOG4J_FILE_PATH
emca.log4j.file.path=/opt/emca/config/log4j.xml

#EMCA_ENVIRONMENT_IS_PRODUCTION
environment.isProduction = false

#######################################
##    PQC Service Configuration      ##
#######################################

# PQC Service URL (when running in Tomcat, use context path)
pqc.service.url=http://localhost:8080/emCA-PQC-Service/api/v1/pqc

# Enable/Disable PQC Service
# ENV: PQC_SERVICE_ENABLED
pqc.service.enabled=true

# PQC Service Timeout (milliseconds)
# ENV: PQC_SERVICE_TIMEOUT
pqc.service.timeout=30000


#######################################
##  Approval Workflow Configuration  ##
#######################################

# Enable/Disable Approval Workflow
# ENV: APPROVAL_WORKFLOW_ENABLED
# Note: Additional settings (minimum approvals, approver roles) are configured in EMCAUsersMetrix table
approval.workflow.enabled=true

```

{% hint style="info" %}
Use either a new database user or an existing one as the username in the above

The password for the database user must be encrypted using the PasswordSecure.jar tool. Please refer to Section 7. DB Password ENCRYPTOR
{% endhint %}

### **Database**

Open the *emCA.properties* file and based on the type of database used; the corresponding values need to be updated. Please find the below sample Database configuration provided for MySQL database.

&#x20;Example: for #MySQL database, use the below-mentioned values in the table:

<table data-header-hidden><thead><tr><th width="189.33333333333331"></th><th width="240"></th><th></th></tr></thead><tbody><tr><td><strong>Parameter</strong></td><td><strong>Description</strong></td><td><strong>Values to be Replaced</strong></td></tr><tr><td>datasource.hibernate.dialect</td><td>[DialectInfo] refers to Dialect information</td><td>org.hibernate.dialect.MySQLDialect</td></tr><tr><td>datasource.driver.class.name</td><td>[DriverClassName] refers to Driver class name</td><td>com.mysql.jdbc.Driver</td></tr><tr><td>emca.datasource.url</td><td>[URL] refers to Database URL</td><td>jdbc:mysql://127.0.0.1:3306/emca</td></tr><tr><td>emca.datasource.application.username</td><td>[UserName] refers to UserName who has access to this schema</td><td>root</td></tr><tr><td>emca.datasource<em>.application.password</em></td><td>[Password] refers to Password for the user</td><td>nNh0bStJeJxo3eu3taSY2Q==</td></tr></tbody></table>

### **Logs**

In the emCA.properties file also configure the logs path for capturing events. Provide the log file path to capture logs.

```
#Configure the log4j.xml path [This property is meant to configure local server path of log4j file]
logFilePath=C:/emCA/emCAPropertyFiles/log4j.xml
```

{% hint style="info" %}
**Note:** If java.util.logging.FileHandler is not configured then application logs will not be generated.
{% endhint %}

```
?xml version="1.0" encoding="UTF 8"? 
 Configuration status="WARN" monitorInterval="30">
 ! Logging Properties  
 <Properties>
 <Property name="LOG_PATTERN"> %d{yyyy-MM-dd HH:mm:ss.SSS	%pid 
 %p	%m%n</Property>
 <Property name="APP_LOG_ROOT" >E:\emCAv4\emCAProperties\logs\emca</Property>
</Properties>
 Appenders>
 ! Console Appender  
 Console name="Console" target="SYSTEM_OUT" follow="true">
 PatternLayout disableAnsi="false" pattern="$ CONSOLE_LOG_PATTERN " />
</Console>
 RollingFile name="warnLog" fileName="$ APP_LOG_ROOT /emCA-warn.log" filePattern="$ APP_LOG_ROOT /emCA-warn-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
LevelRangeFilter minLevel="WARN" maxLevel="WARN" onMatch="ACCEPT" onMismatch="DENY"/>
PatternLayout pattern="$ LOG_PATTERN "/>
Policies>
 OnStartupTriggeringPolicy />
 SizeBasedTriggeringPolicy size="10MB" />
</Policies>
 DefaultRolloverStrategy max="30000"/>
</RollingFile>
 RollingFile name="infoLog" fileName="$ APP_LOG_ROOT /emCA-info.log" filePattern="$ APP_LOG_ROOT /emCA-info-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
 LevelRangeFilter minLevel="INFO" maxLevel="INFO" onMatch="ACCEPT" onMismatch="DENY"/>
 PatternLayout pattern="$ LOG_PATTERN "/>
 Policies>
 OnStartupTriggeringPolicy />
 SizeBasedTriggeringPolicy size="10MB" />
</Policies>
 DefaultRolloverStrategy max="30000"/>
</RollingFile>
 RollingFile name="errorLog" fileName="$ APP_LOG_ROOT /emCA-error.log" filePattern="$ APP_LOG_ROOT /emCA-error-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
 PatternLayout pattern="$ LOG_PATTERN "/>
 Policies>
 OnStartupTriggeringPolicy />
 SizeBasedTriggeringPolicy size="10MB" />
</Policies>
 DefaultRolloverStrategy max="30000"/>
</RollingFile>
 RollingFile name="debugLog" fileName="$ APP_LOG_ROOT /emCA-debug.log" filePattern="$ APP_LOG_ROOT /emCA-debug-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
 LevelRangeFilter minLevel="DEBUG" maxLevel="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/>
 PatternLayout pattern="$ LOG_PATTERN "/>
 Policies>
 OnStartupTriggeringPolicy />
 SizeBasedTriggeringPolicy size="10MB" />
</Policies>
 DefaultRolloverStrategy max="30000"/>
</RollingFile>
</Appenders>
 Loggers>
 AsyncRoot level="debug" includeLocation="false">
 AppenderRef ref="infoLog" />
 AppenderRef ref="errorLog" />
 AppenderRef ref="warnLog" />
 AppenderRef ref="debugLog" />
 AppenderRef ref="Console" />
</AsyncRoot>
</Loggers>
</Configuration>

```

### **Deployment** <a href="#toc82804581" id="toc82804581"></a>

The following component is required for deployment:

&#x20;                     <mark style="color:green;">emCA application (emCA.war file)</mark>

emCA application package is provided as a war file which has to be deployed on the application server. Please configure and save all the properties in the file defined in section –‘For emCA.properties’ under Environment Variables

Please find the following steps to deploy the application:

* Copy the emCA.war inside Tomcat->Web apps folder *apache-tomcat-7.0.37\webapps.*
* Windows run services.msc.
* Select the service name Apache Tomcat and Click Start.

### Quick Check Guide <a href="#toc82804582" id="toc82804582"></a>

To verify if the application has been successfully deployed, please follow the below steps:

Once deployment is completed and server is started, open any browser like IE, Google Chrome, Firefox etc. and enter URL - <https://www.example.com/emCA/login.htm>

emCA login page should be displayed as shown below

<figure><img src="/files/jQq5kxZ2lrNrFF95KhYY" alt=""><figcaption></figcaption></figure>

After successful deployment of the emCA application, check if all the Tables have been created in the specified schema in the database.

Also, check for log file generation in the path mentioned (Configuration->Log Properties).

{% hint style="info" %}
Note: java.util.logging.FileHandler.pattern   = \<LogFolderPath>//emca\_debug.log

Please verify the specified highlight in the log4j.xml location and ensure that the logs folder has been successfully generated.
{% endhint %}

A log file should have been generated in the above-mentioned path.

## emCA API

This section provides the procedure for emCA API deployment and configuration. emCA API (emcaServices) provides an open API (Application Programming Interface) for integrating certificate services with third-party applications and devices. emCA API supports REST in JSON format. emCA APIs are light weight and flexible.

{% hint style="info" %}
Note:

The emCA API supports the following features:

&#x20;`/rest/certificates/request`,&#x20;

`/rest/certificates/request/keystore`,&#x20;

`/rest/certificates/export`,&#x20;

`/rest/certificates/revoke`,&#x20;

`/rest/certificates/suspend`,&#x20;

`/rest/certificates/reinstate`, and&#x20;

`/rest/certificates/request/regenerate`.
{% endhint %}

**Requirement**

* emcaServices.war package

**Deploy WAR**

* Copy emcaServices.war to \<APP\_SERVER>/webapps/
* Configure EMCA\_CONFIGURATION\_PATH
* Define datasource or JNDI for API database access

**Start Service**

* Restart application server
* Verify endpoint availability at https\://\<host>:\<port>/emCA/api/health

**Authentication & Transport**

* All endpoints require TLS
* Use token-based authentication in HTTP headers

**Supported REST Methods**

**CA Management:**

| GET  | <p> </p><p>getKeyProfiles</p><p> </p>            |
| ---- | ------------------------------------------------ |
| POST | <p> </p><p>createCA</p><p> </p>                  |
| POST | <p> </p><p>createCSR</p><p> </p>                 |
| POST | <p> </p><p>importCertificate</p><p> </p>         |
| POST | <p> </p><p>createOrUpdateCRLProfile</p><p> </p>  |
| POST | <p> </p><p>createOrUpdateCRL</p><p> </p>         |
| POST | <p> </p><p>getCRL</p><p> </p>                    |
| GET  | <p> </p><p>getCRL</p><p> </p>                    |
| POST | <p> </p><p>revoke/suspend</p><p> </p>            |
| POST | <p> </p><p>reinstateCA</p><p> </p>               |
| POST | <p> </p><p>createOrUpdateUserProfile</p><p> </p> |
| POST | <p> </p><p>createUserCertificate</p><p> </p>     |

**Certificate Management:**

| POST | getJwt-token            |
| ---- | ----------------------- |
| POST | createCertificate       |
| POST | createCertificates      |
| POST | createCustomCertificate |
| POST | createKeyStore          |
| POST | rekey                   |
| POST | regenerateKeyStore      |
| POST | revoke                  |
| POST | suspend                 |
| POST | reinstate               |
| POST | getCertificate          |
| POST | getProfiles             |
| POST | getProfileInfo          |
| POST | getCertInfo             |
| POST | getCertCount            |
| POST | getExpiringSoonCertInfo |
| POST | getCAs                  |
| POST | getCertificateChain     |
| GET  | getCAs                  |
| GET  | getCertificateChain     |
| GET  | getProfileInfo          |
| GET  | getProfiles             |
| GET  | getCertificate          |

### Configuration

{% hint style="info" %}
Note: All actions required for setting up and configuring emCA should be done using administrator privileges.
{% endhint %}

### **Environment Variables**

#### **Application.properties**

This file is used to configure database-related properties like dialect, driver class name, URL, Username, password (database user should have full privilege to the schema created for emCA application) as well as logs.

#### For Java

To deploy emCA war, java environment has to be set. Please follow the below procedure. If it is already configured, then please ignore this step.

To correctly set the JAVA\_HOME variable for all users, you should choose the first option, "Edit the system environment variables." Here's the corrected instruction:

Search for Environment Variables:

* Type "environment variables" in the Windows search bar.
* Click on "Edit the system environment variables".

System Properties Window:

* In the System Properties window that opens, click on the "Environment Variables" button.

<figure><img src="/files/sXtUnMLX0OqCZZBPh5Id" alt=""><figcaption></figcaption></figure>

Edit System Variables:

* Under "System variables," find the JAVA\_HOME variable.
* If the variable exists:
* Select it and click "Edit."
* In the "Variable value" field, enter the full path to your JDK 21 installation directory (e.g., C \Program Files\Java\jdk-21 .
* If the variable does not exist:
* Click "New."
* Enter JAVA\_HOME as the variable name.
* Enter the full path to your JDK 21 installation directory as the variable value.

Save Changes:

* Click "OK" to save the changes in the Environment Variables window.
* Click "OK" to close the System Properties window.

<figure><img src="/files/LJ9rQ7AtpE6zQEDP9033" alt=""><figcaption></figcaption></figure>

The variable value should point out the physical path of the JDK 21. And click ok. For Application.properties

This file is used to configure database-related properties like dialect, driver class name, URL, Username, password (database user should have full privilege to the schema created for emCA application) as well as logs.

#### **For Windows**

Configure the property file path in environment variables as shown in below figure .

<figure><img src="/files/jvp2cMWqBUmJo8kDAb1c" alt=""><figcaption></figcaption></figure>

Variable name: <mark style="color:yellow;">EMCA\_SERVICES\_CONFIGURATION\_PATH</mark>

&#x20;Variable value: <mark style="color:yellow;">location of property files (application.properties)</mark>

#### **For Linux**

For setting environment variable in Linux, run following command.

<mark style="color:yellow;">sudo -H gedit  /etc/environment</mark>

It will open the environment folder and set the emCA and emCA Services path inside the folder.

EMCA\_SERVICES\_CONFIGURATION\_PATH for application.properties file as shown in the below figure.

<figure><img src="/files/zOL0RCrPKFqCda7pjL4L" alt=""><figcaption></figcaption></figure>

Once the Environment variable is set for application.properties, the user can open the application.properties to configure various options which includes configuring of database as well as logs.

### **Snapshot**

&#x20;Application.properties file snapshot for reference:

```
#########################################################
##                 General information                 ##
#########################################################
## Boolean values = "yes" or "no"                      ##
## String values  = base64 encoded                     ##
## Passwords      = encrypted with PasswordSecure.jar  ##
## Time intervals = in days if not specified otherwise ##
## Paths          = always absolute paths              ##
#########################################################

#######################################
##          MySQL Connection                            ##
#######################################

#API_JPA_PROPERTIES_HIBERNATE_DIALECT
datasource.hibernate.dialect=org.hibernate.dialect.MySQL8Dialect

#API_DATASOURCE_DRIVER_CLASS_NAME
datasource.driver.class.name=com.mysql.jdbc.Driver

#API_DATASOURCE_URL
api.datasource.url=jdbc:mysql://127.0.0.1:3306/emca_prod

# API_DATASOURCE_NAME
api.datasource.default.tenant.name=emca_prod

#API_DATASOURCE_USERNAME
api.datasource.username=root

# API_DATASOURCE_PASSWORD
api.datasource.password=Licm/hHGkujCreZ7KcZcRw==

#EMCA.APPLICATION.FOLDERS.LOCATION
emca.application.folders.location=D:/TestEnvronment/emCAProperties

#######################################
##       OAUTH2 Configuration                         ##
#######################################

#SECURITY.OAUTH.ENABLED
security.oauth2.enabled=false

#SECURITY.OAUTH2.RESOURCE_SERVER.URI
security.oauth2.resource.server.uri=http://<host>:<ip>
```

### **Database**

Open the *application.properties* file and based on the type of database used; the corresponding values need to be updated. Please find below a sample Database configuration provided for MySQL database.

&#x20;Example: for #MySQL database, use below mentioned values in the table:

\#Hibernate properties:

| ***Parameter***                       | **Description**                                               | **Values to be replaced**           |
| ------------------------------------- | ------------------------------------------------------------- | ----------------------------------- |
| *database.hibernate.dialect*          | \[DialectInfo] refers to Dialect information                  | org.hibernate.dialect.MySQL5Dialect |
| *spring.datasource.driver.class.name* | \[DriverClassName] refers to Driver class name                | com.mysql.jdbc.Driver               |
| *api.datasource.url*                  | \[URL] refers to Database URL                                 | jdbc:mysql://127.0.0.1:3306/emca    |
| *api.datasource.username*             | \[UserName] refers to UserName who has access to this schema  | Root                                |
| *api.datasource.password*             | \[Password] refers to Password for the user (Refer Section 6) | nNh0bStJeJxo3eu3taSY2Q==            |

&#x20;  Ex:

&#x20;\#MySQL

DialectInfo= “org.hibernate.dialect.MySQLDialect”

DriverClassName=” com.mysql.jdbc.Driver”

URL= “jdbc:mysql://<127.0.0.1:3306>/ emca”

UserName=”root”

Password=”root”

{% hint style="info" %}
**Note:** The same schema which is used for the emCA application should be used for the emCA API as well
{% endhint %}

### **Logs**

The application uses Log4j for logging. Please specify the local server path for collecting the logs in the log4j.xml file. The local server path of the log4j.xml file needs to be provided in the application.properties file which is set in the environment variables&#x20;

Log4J XML file as shown below:

```
?xml version="1.0" encoding="UTF 8"? 
 Configuration status="WARN" monitorInterval="30">
! Logging Properties  
 <Properties>
 <Property name="LOG_PATTERN">%d{yyyy-MM-dd HH:mm:ss.SSS	%pid 
 %p	%m%n</Property>
<Property
name="APP_LOG_ROOT">E:\emCAv4\emCAProperties\logs\api</Property>
</Properties>
 Appenders>
 ! Console Appender  
 Console name="Console" target="SYSTEM_OUT" follow="true">
 PatternLayout disableAnsi="false" pattern="$ CONSOLE_LOG_PATTERN " />
</Console>
 RollingFile name="debugLog" fileName="$ APP_LOG_ROOT /emCA_API debug.log" filePattern="$ APP_LOG_ROOT /emCA_API-debug-%d{yyyy-MM dd}_%i.log" immediateFlush="true" append="true">
 LevelRangeFilter minLevel="DEBUG" maxLevel="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/>
PatternLayout pattern="$ LOG_PATTERN "/>
 Policies>
 OnStartupTriggeringPolicy />
 SizeBasedTriggeringPolicy size="10MB" />
</Policies>
DefaultRolloverStrategy max="30000"/>
</RollingFile>
 RollingFile name="warnLog" fileName="$ APP_LOG_ROOT /emCA_API-warn.log" filePattern="$ APP_LOG_ROOT /emCA_API-warn-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
 LevelRangeFilter minLevel="WARN" maxLevel="WARN" onMatch="ACCEPT" onMismatch="DENY"/>
 PatternLayout pattern="$ LOG_PATTERN "/>
 Policies>
 OnStartupTriggeringPolicy />
 SizeBasedTriggeringPolicy size="10MB" />
</Policies>
 DefaultRolloverStrategy max="30000"/>
</RollingFile>
 RollingFile name="infoLog" fileName="$ APP_LOG_ROOT /emCA_API-info.log" filePattern="$ APP_LOG_ROOT /emCA_API-info-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
 LevelRangeFilter minLevel="INFO" maxLevel="INFO" onMatch="ACCEPT" onMismatch="DENY"/>
 PatternLayout pattern="$ LOG_PATTERN "/>
 Policies>
 OnStartupTriggeringPolicy />
SizeBasedTriggeringPolicy size="10MB" />
</Policies>
 DefaultRolloverStrategy max="30000"/>
</RollingFile>
 RollingFile name="errorLog" fileName="$ APP_LOG_ROOT /emCA_API-error.log" filePattern="$ APP_LOG_ROOT /emCA_API-error-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
 LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
 PatternLayout pattern="$ LOG_PATTERN "/>
 Policies>
 OnStartupTriggeringPolicy />
 SizeBasedTriggeringPolicy size="10MB" />
</Policies>
 DefaultRolloverStrategy max="30000"/>
</RollingFile>
</Appenders>
 Loggers>
 AsyncRoot level="debug" includeLocation="false">
 AppenderRef ref="infoLog"/>
 AppenderRef ref="errorLog"/>
  AppenderRef ref="warnLog"/>
 AppenderRef ref="debugLog"/>
 AppenderRef ref="Console" />
</AsyncRoot>
</Loggers>
</Configuration>
```

In the above LOCAL SERVER PATH, the administrator has to provide folder path where in the log files get generated.

{% hint style="info" %}
Note: The highlight location differs between Windows and Linux systems. Please refer to the path specific to your environment. Additionally, the Log4j file will be included as part of the deployment package.
{% endhint %}

### Deployment <a href="#toc82804591" id="toc82804591"></a>

The following component is required for deployment:

&#x20;<mark style="color:green;">emCAServices.war</mark>

emCAServices comes as a war file that has to be deployed on the application server. Server provides configuration through the properties file.

Please configure and save all the properties defined in the properties file. Then deploy the configured emCAServices war file.

Please find below the steps to deploy the application:

* Copy the emcaServices war inside Tomcat ->Web apps folder apache-tomcat-7.0.37\webapps.
* Windows run services.msc.
* Select the service Apache Tomcat and click start.

### **Quick Check Guide** <a href="#toc82804592" id="toc82804592"></a>

Once deployment is completed and the server is started, Open any browser like Internet Explorer, Google Chrome, Firefox, etc. and enter the URL- https\:/[www.example.com/emcaServices](http://www.example.com/emcaServices)

Example: <https://www.example.com/emCAServices> in the enter address field&#x20;

The following message will be displayed as shown below.

<figure><img src="/files/9D9Jdc6QUPJe9CLJsPBT" alt=""><figcaption></figcaption></figure>

## OCSP Core

This section provides the step-by-step guide for installation, configuration, and usage of OCSP Core. Online Certificate Status Protocol (OCSP) is an [Internet](https://en.wikipedia.org/wiki/Internet) [protocol](https://en.wikipedia.org/wiki/Communication_protocol) used for obtaining the revocation status of an [X.509](https://en.wikipedia.org/wiki/X.509) [digital certificate](https://en.wikipedia.org/wiki/Digital_certificate). An OCSP responder (a server typically run by the certificate issuer) may return a signed response signifying that the certificate specified in the request is 'good', 'revoked', or 'unknown'.

### Configuration <a href="#toc82804594" id="toc82804594"></a>

{% hint style="info" %}
Note: All actions required for setting up and configuring OCSP Core should be done using administrator privileges.
{% endhint %}

#### **Environment Variables**

#### **For ocspcore.properties**

This file is used to configure database related properties like dialect, driver class name, URL, Username, password (database user should have full privilege to the schema created for emCA application) as well as logs.

#### **For Linux**

For setting environment variable in Linux run following command

&#x20;        <mark style="color:yellow;background-color:yellow;">sudo -H gedit  /etc/environment</mark>

It will open environment folder and set OCSP Core path inside that

OCSPCORE\_CONFIGURATION\_PATH for ocspcore.properties file as shown in below figure

<figure><img src="/files/Odoa2umykueZUM3oUd0U" alt=""><figcaption></figcaption></figure>

Once the Environment variable is set for ocspcore.properties, the user can open the ocspcore.properties to configure various options which includes configuring of database as well as logs.

### **Snapshot**

Please find the below ocspcore.properties file snapshot for reference:

```
#EMOCSPRESPONDER_CONFIGURATION_PATH
#########################################################
##                 General information                 ##
#########################################################
## Boolean values = "yes" or "no"                      ##
## String values  = base64 encoded                     ##
## Passwords      = encrypted with PasswordSecure.jar  ##
## Time intervals = in days if not specified otherwise ##
## Paths          = always absolute paths              ##
## Optionals      = set to empty if not needed         ##
#########################################################

#######################################
##          MySQL Properties         ##
#######################################

# DATASOURCE_DRIVER_CLASS_NAME
datasource.driver.class.name=com.mysql.cj.jdbc.Driver

# HIBERNATE_DIALECT
datasource.hibernate.dialect=org.hibernate.dialect.MySQL8Dialect

# DATASOURCE_URL
ocspcore.datasource.url=jdbc:mysql://localhost:3306/<databaseName>

# DATASOURCE_USERNAME
ocspcore.datasource.username=[Username]

# DATASOURCE_PASSWORD
ocspcore.datasource.password=[Encryppt Password]

# DATASOURCE_DATABASE_NAME
ocspcore.default.database.name=[default databaseName]

#######################################
##      Encryption Keys path         ##
#######################################

# EMCA_AES_KEY_PATH
emca.aes.key.path=/home/emCA/emCAProperties/key/aes.key

# EMCA_DB_AES_KEY_PATH
# optional if subscriber encryption mode is database
emca.db.aes.key.path=/home/emCA/emCAProperties/key/subscriber-aes.key


#######################################
##       log4j Configuration         ##
#######################################

# LOG4J_FILE_PATH
ocspcore.log.file.path=/home/emCAv4Solution/emCAv4OCSP/OCSPProperties/ocspcore/log4j.xml
```

### **Database**

ocspcore.properties file is used to configure database related properties where we can configure database properties like dialect, driver class name, URL, Username, password (database user should have full privilege to the schema created for OCSP).

Open the ocspcore.properties file and change the below DB configuration:&#x20;

| <p> </p><p><strong>Parameter</strong></p><p> </p> | <p> </p><p><strong>Description</strong></p>                    |
| ------------------------------------------------- | -------------------------------------------------------------- |
| datasource.hibernate.dialect                      | \[DialectInfo] refers to Dialect information                   |
| datasource.driver.class.name                      | \[DriverClassName] refers to Driver class name                 |
| ocspcore.datasource.url                           | \[URL] refers to Database URL                                  |
| ocspcore.datasource.username                      | \[UserName] refers to UserName who has access to this schema   |
| ocspcore.datasource.password                      | \[Password] refers to Password for the user ( Refer Section 6) |

{% hint style="info" %}
**Note:** Default values in the configuration file will be used if it’s not changed as per the requirement. Please configure as per your requirement.

OCSP Responder will connect with the same schema which is connected to the emCA Application&#x20;
{% endhint %}

### **Logs**

The application uses Log4j for logging. Please specify the local server path for collecting the logs in the log4j.xml file. The local server path of log4j.xml file need to be provided in ocspcore.properties file which is set in the environment variables \[please refer section 6.3.1.1]

Log4J XML file as shown below:

```
<?xml version="1.0" encoding="UTF-8"?>
<Configuration status="WARN" monitorInterval="30">

    <!-- Logging Properties -->
    <Properties>
        <Property name="LOG_PATTERN">[%d{yyyy-MM-dd HH:mm:ss.SSS}] -- {%pid} [%p] - %m%n</Property>
        <Property name="APP_LOG_ROOT">E:/OCSP/logs/ocspcore</Property>
    </Properties>
    <Appenders>
        <!-- Console Appender -->
        <Console name="Console" target="SYSTEM_OUT" follow="true">
            <PatternLayout disableAnsi="false" pattern="${CONSOLE_LOG_PATTERN}" />
        </Console>				<RollingFile name="debugLog" fileName="${APP_LOG_ROOT}/OCSPResponderCore-debug.log" filePattern="${APP_LOG_ROOT}/OCSPResponderCore-debug-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="DEBUG" maxLevel="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="warnLog" fileName="${APP_LOG_ROOT}/OCSPResponderCore-warn.log" filePattern="${APP_LOG_ROOT}/OCSPResponderCore-warn-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="WARN" maxLevel="WARN" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="infoLog" fileName="${APP_LOG_ROOT}/OCSPResponderCore-info.log" filePattern="${APP_LOG_ROOT}/OCSPResponderCore-info-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="INFO" maxLevel="INFO" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="errorLog" fileName="${APP_LOG_ROOT}/OCSPResponderCore-error.log" filePattern="${APP_LOG_ROOT}/OCSPResponderCore-error-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
    </Appenders>

    <Loggers>
        <AsyncRoot level="debug" includeLocation="false">
            <AppenderRef ref="infoLog"  />
            <AppenderRef ref="errorLog" />
            <AppenderRef ref="warnLog" />
			<AppenderRef ref="debugLog" />
           <AppenderRef ref="Console" />
        </AsyncRoot>
    </Loggers>

</Configuration>
```

In the above LOCAL SERVER PATH, the administrator has to provide a folder path where in the log files get generated.

### Deployment <a href="#toc82804601" id="toc82804601"></a>

The following component is required for deployment:

<mark style="color:green;">OCSP CORE(ocsprespondercore.war file)</mark>

OCSPCORE comes as a war file which has to be deployed on the application server. Server provides configuration through properties file.

Please configure and save all the properties defined in the properties file defined in section -‘(B) For ocspcore.properties’ under section 5.6.1.1. Environment Variables.

Then deploy the configured OCSP Core war file.

Please find below steps to deploy the application:

* Copy the ocsprespondercore.war inside Tomcat ->Web apps folder apache-tomcat\webapps
* Windows run services.msc
* Select Apache Tomcat and click Start

### Quick Check Guide <a href="#toc82804602" id="toc82804602"></a>

Once deployment is successfully done and the server is started, Open any browser like Internet Explorer, Google Chrome, Firefox etc. and enter URL-  as mentioned below

<https://www.example.com/ocsprespondercore> in enter address field place (For ex: https\:// 127.0.0.1:8080/ocsprespondercore)

The following message is displayed. This implies that the application is deployed properly.

<mark style="color:yellow;">“HTTP Status 405 - OCSP only supports POST”.</mark>

&#x20;To verify whether logs are getting generated as per the path defined, please open the folder that is mentioned in the configuration path set in log4j.xml file (Configuration->log4j.xml).

```
"[Local Server Path]/ocspresponder.log
```

Please make sure that the log file is created in the above-mentioned path.

## OCSP Responder Web

This section provides step by step guide for installation, configuration and usage of OCSP Web. This is generally deployed in the DMZ for external applications to interface. OCSP Web will in turn interfaces with OCSP Core that is deployed in the MZ where in only selected internal application will have access to it.

### Configuration <a href="#toc82804604" id="toc82804604"></a>

{% hint style="info" %}

<pre><code><strong>Note – all actions required for setting up and configuring OCSP Web should be done using administrator privileges
</strong></code></pre>

{% endhint %}

#### **Environment Variables - For ocspweb.properties**

This file is used to configure logs.

#### For Windows

Search for Environment Variables:

* Type "environment variables" in the Windows search bar.
* Click on "Edit the system environment variables".

System Properties Window:In the System Properties window that opens, click on the "Environment Variables" button.

Edit System Variables:

* Under "System variables," find the JAVA\_HOME variable.
* If the variable exists:
* Select it and click "Edit."
* In the "Variable value" field, enter the full path to your JDK 21 installation directory (e.g., C \Program Files\Java\jdk-21
* If the variable does not exist:
* Click "New."
* Enter JAVA\_HOME as the variable name.
* Enter the full path to your JDK 21 installation directory as the variable value.

Save Changes:

* Click "OK" to save the changes in the Environment Variables window.
* Click "OK" to close the System Properties window

<figure><img src="/files/TjYgY7dGLL5rcQG4MpvX" alt=""><figcaption></figcaption></figure>

Environment Variables: OCSPWEB\_CONFIGURATION\_PATH=E:\OCSP\OCSPProperties\ocspweb

#### **For Linux**

For setting the environment variable in Linux, run following command:

&#x20;  <mark style="color:yellow;">sudo -H gedit  /etc/environment</mark>

It will open environment folder and set OCSP Web path inside that

OCSPWEB\_CONFIGURATION\_PATH  for ocspweb.properties file as shown in below figure

<figure><img src="/files/jvYGVpuHhrqOMOd6xbY5" alt=""><figcaption></figcaption></figure>

Once the Environment variable is set for ocspweb.properties, the user can open the ocspweb.properties to configure logs.

### **Snapshot**

Please find below is the ocspweb.properties file snapshot for reference:

```
#OCSPWEB_CONFIGURATION_PATH


# EMCA_OCSP_URL
emca.ocsp.url=http://127.0.0.1/OCSPResponderCore/ocsp

# EMCA_OCSP_REDIRECT_URL
# Redirect the url ocsp web if required
#emca.ocsp.redirect.url=https://google.com/

#######################################
##       log4j Configuration         ##
#######################################

# LOG4J_FILE_PATH
log4j.file.path=/home/emCAv4Solution/emCAv4OCSP/OCSPProperties/ocspweb/log4j.xml

#######################################
##      Spring Configuration         ##
#######################################

# SPRING_MVC_VIEW_PREFIX
spring.mvc.view.prefix=/WEB-INF/View/

# SPRING_MVC_VIEW_SUFFIX
spring.mvc.view.suffix=.jsp
```

### **Connection**

OCSP Web has to connect to OCSP Core for passing the requests received by OCSP Web to OCSP Core. For connecting to OCSP Core, in the properties file as shown below

```
# URL where ocspcore is deployed
emca.ocsp.url=http://<ipaddress>:<port>/OCSPResponderCore/ocsp
```

### **Logs**

The application uses Log4j for logging. Please specify the local server path for collecting the logs in the log4j.xml file. The local server path of log4j.xml file need to be provided in ocspweb.properties file which is set in the environment variables \[please refer section 6.4.1.1]

Log4J XML file as shown below:

```
<?xml version="1.0" encoding="UTF-8"?>
<Configuration status="WARN" monitorInterval="30">
    <!-- Logging Properties -->
    <Properties>
        <Property name="LOG_PATTERN">[%d{yyyy-MM-dd HH:mm:ss.SSS}] -- {%pid} [%p] - %m%n</Property>
        <Property name="APP_LOG_ROOT">E:/OCSP/logs/ocspweb</Property>
    </Properties>
    <Appenders>
        <!-- Console Appender -->
        <Console name="Console" target="SYSTEM_OUT" follow="true">
            <PatternLayout disableAnsi="false" pattern="${CONSOLE_LOG_PATTERN}" />
        </Console>
        <RollingFile name="debugLog" fileName="${APP_LOG_ROOT}/OCSPResponderWeb-debug.log" filePattern="${APP_LOG_ROOT}/OCSPResponderWeb-debug-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="DEBUG" maxLevel="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="warnLog" fileName="${APP_LOG_ROOT}/OCSPResponderWeb-warn.log" filePattern="${APP_LOG_ROOT}/OCSPResponderWeb-warn-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="WARN" maxLevel="WARN" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="infoLog" fileName="${APP_LOG_ROOT}/OCSPResponderWeb-info.log" filePattern="${APP_LOG_ROOT}/OCSPResponderWeb-info-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="INFO" maxLevel="INFO" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="errorLog" fileName="${APP_LOG_ROOT}/OCSPResponderWeb-error.log" filePattern="${APP_LOG_ROOT}/OCSPResponderWeb-error-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
    </Appenders>

    <Loggers>
        <AsyncRoot level="debug" includeLocation="false">
            <AppenderRef ref="infoLog"  />
            <AppenderRef ref="errorLog" />
            <AppenderRef ref="warnLog" />
            <AppenderRef ref="debugLog" />
            <AppenderRef ref="Console" />
        </AsyncRoot>
    </Loggers>
</Configuration>
```

In the above LOCAL SERVER PATH, the administrator has to provide folder path where in the log files get generated.

### Deployment <a href="#toc82804611" id="toc82804611"></a>

The following components are required for deployment:

<mark style="color:green;">OCSP Web (ocspresponderweb.war file)</mark>

OCSP Web comes as a war file which has to be deployed on the application server. Server provides configuration through properties file.

Please configure and save all the properties. Then deploy the configured OCSP Web war file.

Please find below steps to deploy the application:

* Copy the ocspresponderweb.war inside Tomcat->Web apps folder apache-tomcat\webapps
* Windows run services.msc
* Go to Apache Tomcat and click Start

### Quick Check Guide <a href="#toc82804612" id="toc82804612"></a>

These endpoints are used when the OCSP service is running in single-tenant, or where no specific tenant identifier is required in the URL.&#x20;

OCSP Core (Default Tenant)

```
https://www.example.com/OCSPResponderWeb/ocsp
```

Use these endpoints when the OCSP service is operating in multi-tenant mode, where each group name is identified using a {tenantId} path variable.

OCSP Core (Multi-Tenant)

```
https://www.example.comOCSPResponderWeb/ocsp/{tenantId}
```

To verify whether logs are getting generated as per the path defined, please open the folder that is mentioned in the configuration path set in log4j.xml file (Configuration->log4j.xml)

```
 "[Local Server Path]/OCSPResponderWeb.log
```

Please make sure that the log file is created in the above-mentioned path.

## TSA Core

This section provides step by step guide for installation, configuration, and usage of TSA Core. TSA Core including (emTSA and eTSA)  is used for timestamping the requests received. And also help in managing timestamping Signers as well as keys.

### Configuration <a href="#toc82804614" id="toc82804614"></a>

{% hint style="info" %}
Note: All actions required for setting up and configuring TSA Core should be done using administrator privileges
{% endhint %}

### **Environment Variables**

**tsacore.properties**

This file is used to configure database related properties like dialect, driver class name, URL, Username, password (database user should have full privilege to the schema created for TSA application) as well as logs.

#### For Windows

Configure the property file path in environment variables as shown below in figure

<figure><img src="/files/gQucrdb48laZVFMvvJhc" alt=""><figcaption></figcaption></figure>

Variable name:TSACORE\_CONFIGURATION\_PATH=E:\TSA\TSAProperties\tsacore

#### **For Linux**

For setting the environment variable in Linux, run the following command.

&#x20;       <mark style="color:yellow;">sudo -H gedit  /etc/environment</mark>

It will open environment folder and set TSA Core path inside that

TSACORE\_CONFIGURATION\_PATH for tsacore.properties file as shown in below figure

<figure><img src="/files/d7qV2X0bszloLAhIP0pK" alt=""><figcaption></figcaption></figure>

Once the Environment variable is set for tsacore.properties, the user can open the tsacore.properties to configure various options which includes configuring of database as well as logs.

### **Snapshot**

Please find below is the tsacore.properties file snapshot for reference:

```
# Configure ENV on the server 
# ENV Variable : TSACORE_CONFIGURATION_PATH

# HIBERNATE_DIALECT
datasource.hibernate.dialect=org.hibernate.dialect.MySQL8Dialect
datasource.driver.class.name=com.mysql.jdbc.Driver
emtsa.datasource.url=jdbc:mysql://localhost:3306/emtsa
emtsa.datasource.username=root
emtsa.datasource.password=sTc6+9CC0MxOcqVgaJzbhg==

application.aes.key.path=D:/TestEnvronment/emCAProperties/key/aes.key

emtsa.pkcs12.type.key.profiles.path=D:/TestEnvronment/PKCS12
emtsa.pkcs11.type.key.profiles.path=D:/TestEnvronment/PKCS11

#For Logs
emtsa.log4j.file.path=D:/TestEnvronment/Logs/tsa/log4j.xml

#crlMapRefresh
time.enabled=24

# APPLICATION_AES_KEY_PATH
application.aes.key.path=[AES Key file path]

# PKCS12_TYPE_KEY_PROFILES_LOCATION
pkcs12.type.key.profiles.location=/home/emCAv4Solution/emCAv4TSA/TSAProperties/tsacore/pkcs12

# PKCS11_TYPE_KEY_PROFILES_LOCATION
pkcs11.type.key.profiles.location=/home/emCAv4Solution/emCAv4TSA/TSAProperties/tsacore/pkcs11
```

### **Database**

tsacore.properties file is used to configure database related properties where we can configure database properties like dialect, driver class name, URL, Username, password (database user should have full privilege to the schema created for TSA).

Open the tsacore.properties file and change the below DB configuration:&#x20;

| **Parameter**                | **Description**                                                |
| ---------------------------- | -------------------------------------------------------------- |
| datasource.hibernate.dialect | \[DialectInfo] refers to Dialect information                   |
| datasource.driver.class.name | \[DriverClassName] refers to Driver class name                 |
| emtsa.datasource.url         | \[URL] refers to Database URL                                  |
| emtsa.datasource.username    | \[UserName] refers to UserName who has access to this schema   |
| emtsa.datasource.password    | \[Password] refers to Password for the user ( Refer Section 6) |

### **esta Logs**

The application uses Log4j for logging. Please specify the local server path for collecting the logs in the log4j.xml file. The local server path of log4j.xml file need to be provided in tsacore.properties file which is set in the environment variables&#x20;

Log4J XML file as shown below:

```
<?xml version="1.0" encoding="UTF-8"?>
<Configuration status="WARN">
    <!-- Logging Properties -->
    <Properties>
        <Property name="LOG_PATTERN">[%d{yyyy-MM-dd HH:mm:ss.SSS}] -- {%pid} [%p] - %m%n</Property>
        <Property name="CONSOLE_LOG_PATTERN">%d{yyyy-MM-dd HH:mm:ss.SSS} %highlight{${LOG_LEVEL_PATTERN:-%5p}}{FATAL=red, ERROR=red, WARN=yellow, INFO=green, DEBUG=green, TRACE=green} %style{%pid}{magenta} --- [%4.15t] %style{%-20.40c{1.}}{cyan} : %m%n%ex</Property>
        <Property name="APP_LOG_ROOT">E:\TSA\TSAProperties\tsacore\logs\etsa</Property>
    </Properties>
    <Appenders>
        <!-- Console Appender $${date:yyyy-MM}/ -->
        <Console name="Console" target="SYSTEM_OUT" follow="true">
            <PatternLayout disableAnsi="false" pattern="${CONSOLE_LOG_PATTERN}" />
        </Console>
        <RollingFile name="warnLog" fileName="${APP_LOG_ROOT}/eTSA-warn.log" filePattern="${APP_LOG_ROOT}/eTSA-warn-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="WARN" maxLevel="WARN" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="infoLog" fileName="${APP_LOG_ROOT}/eTSA-info.log" filePattern="${APP_LOG_ROOT}/eTSA-info-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="INFO" maxLevel="INFO" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        
        <RollingFile name="debugLog" fileName="${APP_LOG_ROOT}/eTSA-debug.log" filePattern="${APP_LOG_ROOT}/eTSA-debug-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="DEBUG" maxLevel="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
         
        <RollingFile name="errorLog" fileName="${APP_LOG_ROOT}/eTSA-error.log" filePattern="${APP_LOG_ROOT}/eTSA-error-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
             
    </Appenders>
 
    <Loggers>
        <Root level="debug" includeLocation="false">
            <AppenderRef ref="infoLog"  />
            <AppenderRef ref="errorLog" />
            <AppenderRef ref="warnLog" />
            <AppenderRef ref="debugLog" />
           <AppenderRef ref="Console" /> 
        </Root>
    </Loggers>
 
</Configuration>
<RollingFile name="debugLog" fileName="${APP_LOG_ROOT}/eTSA-debug.log" filePattern="${APP_LOG_ROOT}/eTSA-debug-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="DEBUG" maxLevel="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        
        <RollingFile name="warnLog" fileName="${APP_LOG_ROOT}/eTSA-warn.log" filePattern="${APP_LOG_ROOT}/eTSA-warn-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="WARN" maxLevel="WARN" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="infoLog" fileName="${APP_LOG_ROOT}/eTSA-info.log" filePattern="${APP_LOG_ROOT}/eTSA-info-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="INFO" maxLevel="INFO" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="errorLog" fileName="${APP_LOG_ROOT}/eTSA-error.log" filePattern="${APP_LOG_ROOT}/eTSA-error-%d{yyyy-MM-dd}_%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>	    
    </Appenders>
    <Loggers>
        <AsyncRoot level="debug" includeLocation="false">
            <AppenderRef ref="infoLog" />
            <AppenderRef ref="errorLog" />
            <AppenderRef ref="warnLog" />
			<AppenderRef ref="debugLog" />
        </AsyncRoot>
    </Loggers>
</Configuration>

```

In the above  LOCAL SERVER PATH, the administrator has to provide folder path where in the log files get generated.

#### **emTSA Logs**

The application uses emTSA-Log4j for logging. Please specify the local server path for collecting the logs in the emTSA-log4j.xml file. The local server path of emTSA-log4j.xml file need to be provided in tsacore.properties file which is set in the environment variables.

Log4J XML file as shown below:

```
<?xml version="1.0" encoding="UTF-8"?>
<Configuration status="DEBUG" >
    <!-- Logging Properties -->
    <Properties>
        <Property name="LOG_PATTERN">[%d{yyyy-MM-dd HH:mm:ss.SSS}] -- {%pid} [%p] - %m%n</Property>
        <Property name="CONSOLE_LOG_PATTERN">%d{yyyy-MM-dd HH:mm:ss.SSS} %highlight{${LOG_LEVEL_PATTERN:-%5p}}{FATAL=red, ERROR=red, WARN=yellow, INFO=green, DEBUG=green, TRACE=green} %style{%pid}{magenta} --- [%4.15t] %style{%-20.40c{1.}}{cyan} : %m%n%ex</Property>
        <Property name="APP_LOG_ROOT">E:\TSA\TSAProperties\tsacore\logs\emtsa</Property>
    </Properties>
    <Appenders>
        <!-- Console Appender -->
        <Console name="Console" target="SYSTEM_OUT" follow="true">
            <PatternLayout disableAnsi="false" pattern="${CONSOLE_LOG_PATTERN}" />
        </Consol
        <!-- File Appenders on need basis -->
        <!-- <RollingFile name="frameworkLog" fileName="${APP_LOG_ROOT}/app-framework.log" filePattern="${APP_LOG_ROOT}/app-framework-%d{yyyy-MM-dd}-%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <SizeBasedTriggeringPolicy size="1MB" />
            </Policies>
            <DefaultRolloverStrategy max="10"/>
        </RollingFil
        <RollingFile name="debugLog" fileName="${APP_LOG_ROOT}/TSA-debug.log" filePattern="${APP_LOG_ROOT}/app-debug-%d{yyyy-MM-dd}-%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="DEBUG" maxLevel="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="1MB" />
            </Policies>
            <DefaultRolloverStrategy max="10"/>
        </RollingFile>
        <RollingFile name="infoLog" fileName="${APP_LOG_ROOT}/TSA-info.log" filePattern="${APP_LOG_ROOT}/app-info-%d{yyyy-MM-dd}-%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="INFO" maxLevel="INFO" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="1MB" />
            </Policies>
            <DefaultRolloverStrategy max="10"/>
        </RollingFile>
        <RollingFile name="errorLog" fileName="${APP_LOG_ROOT}/TSA-error.log" filePattern="${APP_LOG_ROOT}/app-error-%d{yyyy-MM-dd}-%i.log" immediateFlush="true" append="true">
            <LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="1MB" />
            </Policies>
            <DefaultRolloverStrategy max="10"/>
        </RollingFile>     
        <!-- <RollingFile name="perfLog" fileName="${APP_LOG_ROOT}/app-perf.log" filePattern="${APP_LOG_ROOT}/app-perf-%d{yyyy-MM-dd}-%i.log" immediateFlush="false" append="true" >
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <SizeBasedTriggeringPolicy size="1MB" />
            </Policies>
            <DefaultRolloverStrategy max="1"/>
        </RollingFile> -->
        <!-- <RollingFile name="traceLog" fileName="${APP_LOG_ROOT}/app-trace.log" filePattern="${APP_LOG_ROOT}/app-trace-%d{yyyy-MM-dd}-%i.log" immediateFlush="false" append="true">
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <SizeBasedTriggeringPolicy size="1MB" />
            </Policies>
            <DefaultRolloverStrategy max="1"/>
        </RollingFile> -->
    </Appenders>
     <Loggers>
        <Root level="debug" includeLocation="false">
            <AppenderRef ref="debugLog" />
            <AppenderRef ref="infoLog"  />
            <AppenderRef ref="errorLog" />
            <AppenderRef ref="Console" />
        </Root>
    </Loggers>
</Configuration>

```

In the above highlighted LOCAL SERVER PATH, the administrator has to provide folder path where in the log files get generated.

### Deployment <a href="#toc82804621" id="toc82804621"></a>

The following component is required for deployment:

<mark style="color:green;">TSA CORE(emTSA.war and eTSA.war file)</mark>

TSA CORE comes as 2 war files which has to be deployed on the application server. Server provides configuration through properties file.

Please configure and save all the properties defined in section - ‘(B) For tsacore.properties’ under section 5.8.1.1. Environment Variables. Then deploy the configured TSA Core war file.

Please find below steps to deploy the application:

* Copy the eTSA.war inside Tomcat ->Web apps folder apache-tomcat\webapps
* Windows run services.msc
* Go to Apache Tomcat and Click start

### Quick Check Guide <a href="#toc82804622" id="toc82804622"></a>

Once deployment is successfully done and the server is started, Open any browser like internet explorer, Google Chrome, Firefox etc. and enter URL-  as mentioned below

<https://www.example.com/eTSA> in enter address field place (For ex: https\:// 127.0.0.1:8080/eTSA)

The TSA Login page will be displayed.

To verify whether logs are getting generated as per the path defined, please open the folder that is mentioned in the configuration path set in log4j.xml file (Configuration->log4j.xml)

```
"[Local Server Path]/eTSA.log
```

Please make sure that the log file is created in the above-mentioned path.

## TSA Web

This section provides step by step guide for the installation, configuration, and usage of TSA Web. This is generally deployed in the DMZ for external applications to interface. TSA Web will in turn interface with TSA Core that is deployed in the Militarized Zone/ Trusted Zone where in only selected internal applications will have access to it.

### Configuration <a href="#toc82804624" id="toc82804624"></a>

{% hint style="info" %}
Note: All actions required for setting up and configuring TSA Web should be done using administrator privileges.
{% endhint %}

### **Environment Variables**&#x20;

**tsaweb.properties**

This file is used to configure connections with TSA Core as well as logs.

In order to deploy WebTSA.war, java environment has to be set. Please follow the below procedure. If this is already configured, then please ignore this section.

To correctly set the JAVA\_HOME variable for all users, you should choose the first option, "Edit the system environment variables." Here's the corrected instruction:

Search for Environment Variables:

* Type "environment variables" in the Windows search bar.
* Click on "Edit the system environment variables".

System Properties Window:

* In the System Properties window that opens, click on the "Environment Variables" button.

Edit System Variables:

* Under "System variables," find the JAVA\_HOME variable.
* If the variable exists:
* Select it and click "Edit."
* In the "Variable value" field, enter the full path to your JDK 21 installation directory (e.g., C \Program Files\Java\jdk-21
* If the variable does not exist:
* Click "New."
* Enter JAVA\_HOME as the variable name.
* Enter the full path to your JDK 21 installation directory as the variable value.

Save Changes:

* Click "OK" to save the changes in the Environment Variables window.
* Click "OK" to close the System Properties window.

Variable value: location of property files (tsaweb.properties) E:\TSA\TSAProperties\tsaweb

#### **For Linux**

For setting the environment variable in Linux, run the following command.

&#x20;         <mark style="color:green;">sudo -H gedit  /etc/environment</mark>

It will open environment folder and set TSA Web path inside that

TSAWEB\_CONFIGURATION\_PATH for tsaweb.properties file as shown in below figure

<figure><img src="/files/U5CqD74UVXAs6QmRjEBh" alt=""><figcaption></figcaption></figure>

Once the Environment variable is set for tsaweb.properties, the user can open the tsaweb.properties to configure various options which includes configuring of connection to TSA Core well as logs.

### **Snapshot**

For your reference, we have attached a snapshot of the tsaweb.properties file below:

```
# Configure ENV on the server
# ENV Variable : TSAWEB_CONFIGURATION_PATH

# eTSA
timestamp.service.url=http://localhost:8080/eTSA/timestamp/request
# Verify Request
datasource.hibernate.dialect=org.hibernate.dialect.MySQLDialect
datasource.driver.class.name=com.mysql.jdbc.Driver
emtsa.datasource.url=jdbc:mysql://localhost:3306/emtsa
emtsa.datasource.username=root
emtsa.datasource.password=sTc6+9CC0MxOcqVgaJzbhg==

application.aes.key.path=D:/OneDrive - eMudhra Limited/D_Drive/TestEnvronment/emCAProperties/key/aes.key
 
# Log4j
webtsa.log4j.file.path=D:/TestEnvronment/emCAProperties/webtsa-log4j.xml

```

### **Connection**

TSA Web has to connect to TSA Core for passing the requests received by TSA Web to TSA Core. For connecting to TSA Core, in the properties file as shown below

```
#URL where tsacore is deployed
emca.tsa.url=http://localhost/eTSA/etsa
```

### **Logs**

The application uses Log4j for logging. Please specify the local server path for collecting the logs in the log4j.xml file. The local server path of log4j.xml file need to be provided in tsaweb.properties file which is set in the environment variables \[please refer section 6.6.1.1]

Log4J XML file as shown below:

```
<?xml version="1.0" encoding="UTF-8"?>
<Configuration status="WARN">
    <!-- Logging Properties -->
    <Properties>
        <Property name="LOG_PATTERN">[%d{yyyy-MM-dd HH:mm:ss.SSS}] -- {%pid} [%p] - %m%n</Property>
        <Property name="CONSOLE_LOG_PATTERN">%d{yyyy-MM-dd HH:mm:ss.SSS} %highlight{${LOG_LEVEL_PATTERN:-%5p}}{FATAL=red, ERROR=red, WARN=yellow, INFO=green, DEBUG=green, TRACE=green} %style{%pid}{magenta} --- [%4.15t] %style{%-20.40c{1.}}{cyan} : %m%n%ex</Property>
        <Property name="APP_LOG_ROOT">E:\TSA\TSAProperties\tsaweb\logs</Property>
    </Properties>
    <Appenders>
        <!-- Console Appender $${date:yyyy-MM}/ -->
        <Console name="Console" target="SYSTEM_OUT" follow="true">
            <PatternLayout disableAnsi="false" pattern="${CONSOLE_LOG_PATTERN}" />
        </Console>
        <RollingFile name="warnLog" fileName="${APP_LOG_ROOT}/WebTSA-warn.log" filePattern="${APP_LOG_ROOT}/WebTSA-warn-%d{yyyy-MM-dd}_%i.log" immediateFlush="true">
            <LevelRangeFilter minLevel="WARN" maxLevel="WARN" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="debugLog" fileName="${APP_LOG_ROOT}/WebTSA-debug.log" filePattern="${APP_LOG_ROOT}/WebTSA-debug-%d{yyyy-MM-dd}_%i.log" immediateFlush="true">
            <LevelRangeFilter minLevel="DEBUG" maxLevel="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="infoLog" fileName="${APP_LOG_ROOT}/WebTSA-info.log" filePattern="${APP_LOG_ROOT}/WebTSA-info-%d{yyyy-MM-dd}_%i.log" immediateFlush="true">
            <LevelRangeFilter minLevel="INFO" maxLevel="INFO" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="errorLog" fileName="${APP_LOG_ROOT}/WebTSA-error.log" filePattern="${APP_LOG_ROOT}/WebTSA-error-%d{yyyy-MM-dd}_%i.log" immediateFlush="true">
            <LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
    </Appenders>
    <Loggers>
        <Root level="debug" includeLocation="false">
            <AppenderRef ref="infoLog" />
            <AppenderRef ref="warnLog" />
            <AppenderRef ref="errorLog" />
            <AppenderRef ref="warnLog" />
            <AppenderRef ref="Console" />
        </Root>
    </Loggers>
</Configuration>
```

In the above  LOCAL SERVER PATH, the administrator has to provide folder path where in the log files get generated.

### Deployment <a href="#toc82804631" id="toc82804631"></a>

Following components are required for deployment:

<mark style="color:green;">TSA Web(WebTSA.war file)</mark>

TSA Web comes as a war file which has to be deployed on the application server. Server provides configuration through properties file.

Please configure and save all the properties defined in section - ‘(B) For tsaweb.properties’ under section 5.9.1.1. Environment Variables. Then deploy the configured TSA Core war file.

Please find below steps to deploy the application:

* Copy the WebTSA.war inside Tomcat->Web apps folder apache-tomcat\webapps
* Windows run services.msc
* Go to Apache Tomcat and click Start

### **Quick Check Guide**

Once deployment is successfully done and the server is started, Open any browser like internet explorer, Google Chrome, Firefox etc. and enter URL-  as mentioned below

<https://www.example.com/WebTSA> in enter address field place (For ex: https\:// 127.0.0.1:8080/WebTSA)

Following page is displayed . This implies that the application is deployed properly.

<figure><img src="/files/wmd6tVhmrUJ7gmuDecqa" alt=""><figcaption></figcaption></figure>

To verify whether logs are getting generated as per the path defined, please open the folder that is mentioned in the configuration path set in log4j.xml file (Configuration->log4j.xml)

```
"[Local Server Path]/WebTSA.log
```

Please make sure that the log file is created in the above-mentioned path.

## Schedular

This section provides a step-by-step guide to installing, configuring, and using the Scheduler.

### Configuration <a href="#toc82804634" id="toc82804634"></a>

{% hint style="info" %}
**Note** – all actions required for setting up and configuring emCA Scheduler should be done using administrator privileges
{% endhint %}

### &#x20;**Environment Variables**

**scheduler.properties**

This file is used to configure database related properties like dialect, driver class name, URL, Username, password (database user should have full privilege to the schema created for emCAScheduler) as well as logs.

Variable name: <mark style="color:yellow;">EMCA\_SCHEDULER\_CONFIGURATION\_PATH</mark>

Variable value: <mark style="color:yellow;">location of property files (scheduler.properties)</mark>

#### **For Linux**

For setting the environment variable in Linux, run the following command.

&#x20;         <mark style="color:yellow;">sudo -H gedit  /etc/environment</mark>

It will open the environment folder and set emCAScheduler path inside that

EMCA\_SCHEDULER\_CONFIGURATION\_PATH for scheduler.properties file .

<figure><img src="/files/BxI9fTNcV6TU8NbGkCBo" alt=""><figcaption></figcaption></figure>

Once the Environment variable is set for scheduler.properties, the user can open the scheduler.properties to configure various options which includes configuring of connection to emCASheduler well as logs.&#x20;

### **Snapshot**

Please find below is the scheduler.properties file snapshot for reference:

```
[This property is meant for configuring MySQL database connection]
hibernate.dialect=org.hibernate.dialect.MySQLDialect
jdbc.driverClassName=com.mysql.jdbc.Driver
jdbc.url=jdbc:mysql://127.0.0.1:3306/emca
jdbc.username=[EMCA DB User]
jdbc.password=[ENCRYPTED DB PASSWORD]
[This property is meant for checking the certificate status]
reinstatedays=1
revokeCertificate=true
updatecrl=true
#FTP scheduler
emca.repository.crl=false
emca.repository.cert=true
emca.repository.upload=true
#FTP Details[This property is meant for checking the certificates copied into file folder]
server = 127.0.0.1
port = 21
user = [FTP USER]
pass = [FTP PASSWORD]
path=[FTP FOLDER NAME]
#Ldap Config [This property is meant for checking the certificates published to LDAP server]
emca.ldap.crl=true
emca.ldap.cert=true
emca.ldap.os=w
#Local Repository
localFilePath=[LOCAL Repository PATH TO PUBLISH THE CRL'S]
emca.local.crl=true

```

### **Deployment**

The following component is required for deployment.

<mark style="color:yellow;">emCAScheduler.bat</mark>

emCAScheduler comes as a .bat file which has to run and provide configuration through properties file.

Please configure and save all the properties defined in section –‘(B) For scheduler.properties’. Environment Variables. Then run the emCASchedule .bat file.

Please find below steps to run the scheduler in windows:

Copy the emCAScheduler.bat inside C:\emCA

run emCAScheduler.bat you will get the window as given below:

<figure><img src="/files/11UvBPKU9cBqEDkN6di6" alt=""><figcaption></figcaption></figure>

For scheduling task or emCAScheduler  follow the steps given below :

1. Go to start in windows → search for Task Scheduler and open it as shown below

<figure><img src="/files/mSlGFY3H0VNo4dbUAPH7" alt=""><figcaption></figcaption></figure>

2. Click on ‘Create Basic Task’ from the right side of window. The Create Basic Task Wizard window will be displayed. Enter the Name of the scheduler as required. The Description is optional as shown below.

<figure><img src="/files/m0fsuKQVmCrYnSlTnr9g" alt=""><figcaption></figcaption></figure>

3. Click on Next. You will be redirected to another window where the Task start time can be selected.

<figure><img src="/files/vxc3KfwxEb8oOJ9PDMzK" alt=""><figcaption></figcaption></figure>

4. Click on ‘Next’. You will be redirected to another window. Set the date and time as given below:

<figure><img src="/files/RPkfN595YgEaO2zyfid4" alt=""><figcaption></figcaption></figure>

5. Click on ‘Next’. Select the ‘Action’ as shown below.

<figure><img src="/files/TBz8dlFcJbSB2JX7qkRV" alt=""><figcaption></figcaption></figure>

6. Once done, enter the Program/Script to start a program and enter the argument to run the scheduler. Argument can be either single or multiple. Arguments can be entered with space as follows:

crl file suspendedCerts ftp ldap

a) crl : Run the command ‘crl scheduler’ to update the CRL where validity is less than the current date.

b) file: Run the command ‘file scheduler’ to copy all the CRL into local file folder.

c) suspendedCerts : Run the command ‘suspendedCerts’ to revoke the suspended certificates.

d) ftp: Run the command ‘ftp’ to copy all the Root, CA, certificates which is created through emCA application into a file server.

f) ldap: Run the command ‘ldap’ to publish all the Root, CA and User certificates in LDAP server.

7. Click on ‘Next’ button. The following window will be displayed.

<figure><img src="/files/Rw0HgJ2hOsYKKYz3MX50" alt=""><figcaption></figcaption></figure>

8. Click on ‘Finish’. You can see the task scheduled as ‘emCAScheduler’ by clicking on ‘Task Scheduled Library’ on the left side of the window given below.

<figure><img src="/files/duLDhnUl1i0026qYd3ve" alt=""><figcaption></figcaption></figure>

#### Quick Check Guide <a href="#toc82804640" id="toc82804640"></a>

To verify if the emCAScheduler is successfully run, follow the below steps.

FTP:  View the certificate in FTP with the credentials given in properties as FTP details:

<figure><img src="/files/Svip57naLp6OyEZBwWrQ" alt="" width="322"><figcaption></figcaption></figure>

Give the Login Url: ftp\:// 127.0.0.1. in the properties file  (server: 127.0.0.1). The system will request for username and password as shown below:

* Enter the user name and password as mentioned in the properties file: user = \[FTP USER], pass = \[FTP PASSWORD], and click on the Sign in button.
* Now click on the folder as given in the properties file: path=\[FTP FOLDER NAME] . you can see all the certificates.

## emOCSP

This section provides step by step guide for installation, configuration and usage of emOCSP. This is generally deployed in the DMZ for external applications to interface. emOCSP is deployed in the MZ where in only selected internal application will have access to it.

### Configuration <a href="#toc169084684" id="toc169084684"></a>

Note – all actions required for setting up and configuring emOCSP should be done using administrator privileges

### Environment Variables <a href="#toc169084685" id="toc169084685"></a>

#### For Java

In order to deploy emocsp.war, java environment has to be set. Please follow the below procedure. If this is already configured, then please ignore this section.

To correctly set the JAVA\_HOME variable for all users, you should choose the first option, "Edit the system environment variables." Here's the corrected instruction:

Search for Environment Variables:

* Type "environment variables" in the Windows search bar.
* Click on "Edit the system environment variables".

System Properties Window:

* In the System Properties window that opens, click on the "Environment Variables" button.

<figure><img src="/files/3PEtP64kZpQXfSA1e5FG" alt=""><figcaption></figcaption></figure>

Edit System Variables:

1. Under "System variables," find the JAVA\_HOME variable.
2. If the variable exists:
   * Select it and click "Edit."
   * In the "Variable value" field, enter the full path to your JDK 21 installation directory (e.g., C:\Program Files\Java\jdk-21).
3. If the variable does not exist:
   * Click "New."
   * Enter JAVA\_HOME as the variable name.
   * Enter the full path to your JDK 21 installation directory as the variable value.

Save Changes:

* Click "OK" to save the changes in the Environment Variables window.
* Click "OK" to close the System Properties window.

For emocsp.properties

This file is used to configure logs.

#### **For Windows**

Configure the property file path in environment variables as

Variable name: EMOCSP\_CONFIGURATION\_PATH

Variable value: E:\OCSP\OCSPProperties\emocsp

#### &#x20;**For Linux**

* For setting environment variable in Linux, run following command.

sudo -H gedit  /etc/environment

* It will open the environment folder and set the tsacore path inside the folder.

EMOCSP\_CONFIGURATION\_PATH for ocspcore.properties file as shown in figure 9.

#### **Snapshot**

Please find below is the ocspweb.properties file snapshot for reference:

```
hibernate.dialect=org.hibernate.dialect.MySQL8Dialect
jdbc.driverClassName=com.mysql.jdbc.Driver
jdbc.url=jdbc:mysql://127.0.0.1:3306/emca
jdbc.dbName=emca
jdbc.username=[DB_USERNAME]
jdbc.password=[DB_PASSWORD_ENCRYPTED]
jdbc.dbHost=127.0.0.1
jdbc.dbPort=3306
#output to a temp_folder/file
emOCSPlogFilePath=E:/OCSP/OCSPProperties/emocsp/log4j.xml
#PKCS12 Keyprofile Location
Pkcs12TypeKeyProfilesLocation=E:/OCSP/OCSPProperties/PKCS12
pkcs11TypeKeyProfilesLocation=E:/OCSP/OCSPProperties/PKCS11

```

#### **Connection**

OCSP Web has to connect to OCSP Core for passing the requests received by OCSP Web to OCSP Core. For connecting to OCSP Core, in the properties file as shown below

```
# URL where ocspcore is deployed
emca.ocsp.url=http://<ipaddress>:<port>/ocsprespondercore
```

#### **Logs**

The application uses Log4j for logging. Please specify the local server path for collecting the logs in the log4j.xml file. The local server path of log4j.xml file need to be provided in ocspweb.properties file which is set in the environment variables

Log4J XML file as shown below:

```
<?xml version="1.0" encoding="UTF-8"?>
<Configuration status="WARN">
    <!-- Logging Properties -->
    <Properties>
        <Property name="LOG_PATTERN">[%d{yyyy-MM-dd HH:mm:ss.SSS}] -- {%pid} [%p] - %m%n</Property>
        <Property name="CONSOLE_LOG_PATTERN">%d{yyyy-MM-dd HH:mm:ss.SSS} %highlight{${LOG_LEVEL_PATTERN:-%5p}}{FATAL=red, ERROR=red, WARN=yellow, INFO=green, DEBUG=green, TRACE=green} %style{%pid}{magenta} --- [%4.15t] %style{%-20.40c{1.}}{cyan} : %m%n%ex</Property>
        <Property name="APP_LOG_ROOT">E:\TSA\TSAProperties\tsaweb\logs</Property>
    </Properties>
    <Appenders>
        <!-- Console Appender $${date:yyyy-MM}/ -->
        <Console name="Console" target="SYSTEM_OUT" follow="true">
            <PatternLayout disableAnsi="false" pattern="${CONSOLE_LOG_PATTERN}" />
        </Console>
        <RollingFile name="warnLog" fileName="${APP_LOG_ROOT}/WebTSA-warn.log" filePattern="${APP_LOG_ROOT}/WebTSA-warn-%d{yyyy-MM-dd}_%i.log" immediateFlush="true">
            <LevelRangeFilter minLevel="WARN" maxLevel="WARN" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="debugLog" fileName="${APP_LOG_ROOT}/WebTSA-debug.log" filePattern="${APP_LOG_ROOT}/WebTSA-debug-%d{yyyy-MM-dd}_%i.log" immediateFlush="true">
            <LevelRangeFilter minLevel="DEBUG" maxLevel="DEBUG" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile
        <RollingFile name="infoLog" fileName="${APP_LOG_ROOT}/WebTSA-info.log" filePattern="${APP_LOG_ROOT}/WebTSA-info-%d{yyyy-MM-dd}_%i.log" immediateFlush="true">
            <LevelRangeFilter minLevel="INFO" maxLevel="INFO" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
        <RollingFile name="errorLog" fileName="${APP_LOG_ROOT}/WebTSA-error.log" filePattern="${APP_LOG_ROOT}/WebTSA-error-%d{yyyy-MM-dd}_%i.log" immediateFlush="true">
            <LevelRangeFilter minLevel="ERROR" maxLevel="ERROR" onMatch="ACCEPT" onMismatch="DENY"/>
            <PatternLayout pattern="${LOG_PATTERN}"/>
            <Policies>
                <OnStartupTriggeringPolicy />
                <TimeBasedTriggeringPolicy />
                <SizeBasedTriggeringPolicy size="10MB" />
            </Policies>
            <DefaultRolloverStrategy max="30000"/>
        </RollingFile>
    </Appenders>
    <Loggers>
        <Root level="debug" includeLocation="false">
            <AppenderRef ref="infoLog" />
            <AppenderRef ref="warnLog" />
            <AppenderRef ref="errorLog" />
            <AppenderRef ref="warnLog" />
            <AppenderRef ref="Console" />
        </Root>
    </Loggers>
</Configuration>
```

In the above highlighted LOCAL SERVER PATH, the administrator has to provide folder path where in the log files get generated.

#### Deployment

Following component required for deployment:

* emOCSP (emOCSP.war file)

emOCSP comes as a war file which has to be deployed on the application server. Server provides configuration through properties file.

Please configure and save all the properties defined in the properties file then deploy the configured emOCSP Web war file.

Please find below steps to deploy the application:

* Copy the emOCSP.war inside Tomcat->Web apps folder apache-tomcat\webapps
* Windows run services.msc
* Go to Apache Tomcat and click Start

#### Quick Check Guide

* Once deployment is successfully done and the server is started, Open any browser like internet explorer, Google Chrome, Firefox etc. and enter URL-  as mentioned below

<https://www.example.com/OCSPResponderWeb> in enter address field place (For ex: https\:// 127.0.0.1:8080/OCSPResponderWeb)

Following message is displayed. This implies that the application is deployed properly.

“HTTP Status 405 - OCSP only supports POST”.

* To verify whether logs are getting generated as per the path defined, please open the folder that is mentioned in the configuration path set in log4j.xml file (Configuration->log4j.xml)

```
"[Local Server Path]/emOCSP.log
```

Please make sure that the log file is created in the above-mentioned path.

## Setting Up Environment Variables and Managing Tomcat Service

### Java Home for OpenJDK 21 and Application-Related

Step 1: Edit the \`/etc/profile\` File

* Open the \`/etc/profile\` file in a text editor (e.g., nano or vim):

```
sudo nano /etc/profile
```

* Add the following lines at the end of the file to set the environment variables for Java and other application-specific configurations:

````
```bash
   export JAVA_HOME=/usr/lib/jvm/java-21-openjdk
   export PATH=$JAVA_HOME/bin:$PATH
   export JRE_HOME=$JAVA_HOME/jre
   export CLASSPATH=.:$JAVA_HOME/lib:$JAVA_HOME/jre/lib
   ```
````

* Ensure that the path \`/usr/lib/jvm/java-21-openjdk\` matches your Java 21 installation location.&#x20;
* To verify the installation path, you can use the following command:

```
update-alternatives --config java
```

Alternatively, check the contents of \`/usr/lib/jvm/\`.

Add any “application-specific environment variables” in the same manner:

```
export EMCA_CONFIGURATION_PATH=/home/emCAv4Solution/emCAv4/emCAProperties
```

Step 2: Save and Exit the File

* For “nano editor”:
* Press \`Ctrl + O\`, then press \`Enter\` to save.
* Exit using \`Ctrl + X\`.

Step 3: Apply the Changes

* Reload the \`/etc/profile\` file to apply the changes:

```
source /etc/profile
```

Step 4: Verify the Environment Variables

* Confirm that the environment variables are correctly set:

```
echo $JAVA_HOME
  echo $PATH
```

### Manage the Tomcat Service

Verify Tomcat Status

* Check if the Tomcat service is running:

```
 sudo systemctl status tomcat
```

* Start the Tomcat Service
  * To start the Tomcat service:

```
sudo systemctl start tomcat
```

* Restart the Tomcat Service
  * To restart the Tomcat service:

```
sudo systemctl restart tomcat
```

* Stop the Tomcat Service
  * To stop the Tomcat service:

```
sudo systemctl stop tomcat
```

{% hint style="info" %}
Note: Ensure that the Tomcat service is properly registered with \`systemctl\` before performing these operations.
{% endhint %}


# Other Installations

After successfully configuring and deploying the emCA application, authorized users can perform various activities on the application based on their assigned roles. However, before using the emCA application, please ensure that the following things are set up properly to ensure seamless usage of the application:

After deploying the application, the CA Administrator needs to follow a short process (refer to emCA Deployment document) to set up the application

* Post deployment of application, there is a short process \[please refer emCA Deployment document] to setup the application by CA Administrator which includes

&#x20;               o   Registration of emCA application by generation of Generate ID  (license request) and license registration

&#x20;               o   Creation of Administrators

* Installation of token drivers. This is required for users to use their tokens in the application.&#x20;
* Installation of emCA WebSocket. This is required for token-based signing and authentication.
* Creation of other users by Administrator. This includes the creation of Officers and auditors.&#x20;


# Token Drivers

Based on the token opted by the Enterprise for its CA users, the respective token drivers need to be installed. Please find below token driver installation procedure for Safenet tokens:

* Download Token drivers from the eMudhra website&#x20;
* Upon download of drivers, double click on the file displays the below figu
* Click on Next button, displays below screen

<figure><img src="/files/A1ZnITUK4G4aQtfH9jDc" alt=""><figcaption></figcaption></figure>

* Select the language for eToken PKI client and click on “Next” as shown in above Figure

<figure><img src="/files/vcF6D84mwih4xZK4tPDP" alt=""><figcaption></figcaption></figure>

* Select “I Accept license agreement”, and then click on “Next” as shown in above Figure.

<figure><img src="/files/VrM6LdqHtw1WkuaJTmx7" alt=""><figcaption></figcaption></figure>

* Click on “Next” as shown above figure

<figure><img src="/files/PEv6hXMlpbUBBDHdQfSd" alt=""><figcaption></figcaption></figure>

* Please wait until installation complete

<figure><img src="/files/52q1z3io4QRlUnuXjjHg" alt=""><figcaption></figcaption></figure>

* Click on “Finish” as shown in above figure. The token driver is successfully installed.


# emCA Websocket

The emCA web socket utility is used to identify the certificate in the token. Installation requires an ‘Administrator’ privilege

* Open any browser like Internet Explorer or Google Chrome or Firefox etc. and enter the URL, for example URL- “<http://emca.emudhra.com/emCA/login.htm”> in enter address field.
* If the web socket is not installed, then the following page will be displayed, as shown in the below Figure. Otherwise, the user will be displayed on the login page.

<figure><img src="/files/SVosDnulpg2grmJPj1Ct" alt=""><figcaption></figcaption></figure>

* Click on download button as shown in above figure and save the setup file on the machine. Double click on the emCA.msi file, below pop up box will open as shown below.

<figure><img src="/files/5S0ilNrAJPEyrhfIPcS2" alt=""><figcaption></figcaption></figure>

* Click on Next as shown above figure

<figure><img src="/files/VumfKzhOTRRQCTIRAvbo" alt=""><figcaption></figcaption></figure>

* By default, it will show the path of installation. To install to a different folder, enter the path or browse the path as shown above figure. Click on the “Next” button.

<figure><img src="/files/6mCt2fCLkbKHcvuwmuzS" alt=""><figcaption></figcaption></figure>

* Click “Install” to begin the installation as shown above Figure.

* On click of Install, a pop-up box will open showing the below message.

  “Do you want to allow the following program to install software on this computer?”

* Click on the “YES” button

* emCA web socket utility starts installing. Wait till the installation completes, as shown in the above figure.

<figure><img src="/files/pvlab6SrZy7g7CFb04L1" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/VSPvHmdYbOiRprlL8FZF" alt=""><figcaption></figcaption></figure>

* Once installation is completed, click on Finish as shown in figure 12. You are done with emCA utility is installation and ready to use.
* Now the user can see emCA utility running in the system either in the desktop or in the start menu.

o Double-click or Right click on “emCA” icon

o   Click on the “Run as Administrator” option.

* This opens the emCA utility successfully with the “Service started successfully” message as shown below figure.

&#x20;                  ![](/files/NJ08Mq49CfSKvZAXbRxQ)

Now the user can go back to login page for logging into emCA Application based on the role.


# Initial Setup and Configuring License

## Password Encryptor

**Encrypting Stored Passwords (AES-256)**

This section explains how users can upload or generate an AES-256 key, used for encrypting and decrypting passwords. If the sealed AES key is not found in the configured directory, the application will automatically redirect the user to the Encryption/Decryption page.

**Steps**

1. **Redirect to Encryption/Decryption Page**\
   If the application does not find the sealed AES key in the designated directory, it automatically redirects the user to the Encryption/Decryption page.
2. **Provide or Generate AES-256 Key**

* **Option A** — Provide Your Own Key\
  If you already have a valid AES-256 key, paste the Base64-encoded key into the AES Key field

<figure><img src="/files/reqzSJ2fxlsZAsVqUBjf" alt=""><figcaption></figcaption></figure>

* **Option B** — Generate a New Key  \
  If you prefer to generate a new AES-256 key, click on the Generate AES-256 Key button. The application will generate a random key and store it securely in the application’s configured directory, encrypted using a salt mechanism.

<figure><img src="/files/bEbWHPnr8KxirTooZqyI" alt=""><figcaption></figcaption></figure>

3. **Encryption/Decryption**
   * **Encrypting Passwords**\
     After generating or providing the AES key, enter the value to be encrypted in the Input field, and click Encrypt. The encrypted value will appear in the Output field.
   * **Decrypting Passwords**\
     To verify or migrate existing encrypted data, paste the encrypted value in the Input field and click Decrypt to view the plaintext password in the Output field.
4. **Key Storage and Security**
   * The sealed AES key is saved in a secure directory. Ensure the directory is properly secured with restricted access permissions.
   * If the server is restarted or the application is moved, the same AES key must be present in the same directory to ensure continued functionality.

{% hint style="info" %}
Notes:

* The key must be properly stored in a secure directory as per the configuration in the emCA.properties file. If it is missing or moved, the application will prompt the user to generate or upload a valid AES-256 key.
* Ensure that the generated or provided key is backed up securely, as it is critical for decrypting data.
  {% endhint %}

## emCA Set up

After successfully deploying the emCA application, follow these steps for the initial setup:

1. Access the emCA setup by entering the URL provided for the application.
2. The setup will direct you to the emCA welcome page, which will guide you through the configuration process.

Example:\
To access the login page, enter the following URL in the address field:\
https\://\<ip\_address>:\<port>/emCA/login.htm

<figure><img src="/files/yaaSaYuGq8q9w5W2g742" alt=""><figcaption></figcaption></figure>

If you have a backup and wish to restore the previous configuration, click Restore to use the backup data and continue from where you left off.

If you are setting up emCA for the first time, click Next to proceed with configuring CA administrator settings and user setup.

<figure><img src="/files/XpLcv905LCiB92n4l0KC" alt=""><figcaption></figcaption></figure>

When creating a CA Administrator, choose 'Single' or 'Multiple' and specify the number of administrators.

**Set Login Attempt Limit**\
Specify the number of incorrect login attempts allowed, with a maximum of 10 attempts.

After selecting the necessary options, click Proceed to move to the Verify and Confirm page.

<figure><img src="/files/GQDJBw9Ag2dF0V72t1Iu" alt=""><figcaption></figcaption></figure>

**Confirm and Create Admin**\
Click Confirm to finalize the CA Admin configuration. To create the CA Admin, click Next Step: Create CA Administrators. This will bring up the Create CA Administrator page.

<figure><img src="/files/WTid4TXwPnYNeZ5jzOoH" alt=""><figcaption></figcaption></figure>

Enter all the necessary information for the CA Admin and select the User Login Type (Password, Hard, or Soft Token) as shown below.

<figure><img src="/files/EJbZpQ9r1DAczn7KtLRT" alt=""><figcaption></figcaption></figure>

Click on “Proceed” after entering details to proceed, where entered details will be displayed.

<figure><img src="/files/nxjZFyyTnY2Xyw1SoOLN" alt=""><figcaption></figcaption></figure>

“Vierify & Confirm” and simply click on the "Create User" button to create the CA Administrator.

<figure><img src="/files/SeFzxBifaaMoFcyKRI98" alt=""><figcaption></figcaption></figure>

When selected to create “Multiple” Administrators, you can add more before **“Proceed to Login”.**

## Login and Licence Registration

To access the emCA application, the CA Administrator must use the provided User Login Type (Password, Hard, or Soft token).

click on the "Login" button, as shown in the figure below.

<figure><img src="/files/bCE21vkRpkZNp8cYqYir" alt=""><figcaption></figcaption></figure>

Upon login, the following steps need to be performed by the CA Administrator.

Step 1: License Registration

Step 2: Setup Authorization Matrix

Step 3: Generate AES Key

Step 4: Generate Signer Key

**License Registration**

The CA Administrator must complete the license setup as a one-time activity through the License Registration window.

Follow the prompts to proceed with the license generation and registration process.

After logging in, select No when asked if you have a pre-generated license file. Then, click Generate ID

<figure><img src="/files/GW4R2FRgahqAVSqkn5W7" alt=""><figcaption></figcaption></figure>

When you click the "Generate ID" button in the emCA application, a license request file will be generated.

You can then download this file by clicking on the "Download" button as shown below.

<figure><img src="/files/nirEK9WgdWM62wZ0ITfj" alt=""><figcaption></figcaption></figure>

Upon downloading the license request, it should be sent to eMudhra for generating the license file.

Please click on the 'Next' button.

After receiving the license file from eMudhra, the CA Administrator can select the ‘Yes’ option.

<figure><img src="/files/qmdjoKhZOmb8Zb58ek2u" alt=""><figcaption></figcaption></figure>

Please click on the 'Choose File' button to upload the license file that you have received from eMudhra.

<figure><img src="/files/XcELaTW6BCUzoT4ze7yE" alt=""><figcaption></figcaption></figure>

After uploading the license file, the CA Administrator must "Authenticate” by entering their Username and Password as shown in the following figure.

<figure><img src="/files/zJ48A5OgQuACodiMJSSY" alt=""><figcaption></figcaption></figure>

After authentication, click Register to complete the license registration process.

A success message will confirm that the registration is complete.

After registration, click Setup Authorization Matrix to proceed to the next configuration step.

Setup Authorization Matrix

Define M of N Authentication: The CA Administrator configures M of N authentication by specifying the minimum and maximum number of users required for each role (Administrator, Officer, Auditor).

<figure><img src="/files/L1hafNMInYEnXAmqRcdC" alt=""><figcaption></figcaption></figure>

Click on “Proceed” after entering the required minimum and maximum number of users in the provided fields, as shown in the setup interface.

<figure><img src="/files/zwzxRZOwHqmdz1a6r5p3" alt=""><figcaption></figcaption></figure>

The CA Administrator must "Authenticate” by entering their Username and Password as shown in the following figure.

<figure><img src="/files/CHlUFRLi24WX8JdqPAuz" alt=""><figcaption></figcaption></figure>

Once you have successfully completed the authentication process, please click on the "Confirm" button.

<figure><img src="/files/3a8kJhIiwj1AudVgCOTG" alt=""><figcaption></figcaption></figure>

A success message will confirm the Authorization Metrix setup confirmation.

Click on "Proceed to generate AES Key " for encryption key generation.

**Generate AES Key**

In this step, the CA Administrator is presented with the option "Are you generating keys on an HSM?" as shown below.

<figure><img src="/files/nzzCejSgXRjvmWewrhz3" alt=""><figcaption></figcaption></figure>

If the CA Administrator selects ‘No’ and clicks ‘Next’, they will be prompted to select the ‘Subscriber Encryption Mode’ on the following page.

<figure><img src="/files/c90reez9j5TSTcDc5U1N" alt=""><figcaption></figcaption></figure>

On the page, choose whether to store the encryption key in the database or the BYOK and then click on 'Proceed'.

You will see the authentication screen next.

<figure><img src="/files/VL7MpgdDkUVePCzNOHUT" alt=""><figcaption></figcaption></figure>

Authenticate by entering your Username and Password. Once authenticated, click 'Generate AES Key'.

<figure><img src="/files/28xP6hchmUHt0MX7Yk4W" alt=""><figcaption></figcaption></figure>

A message will confirm AES key generation and “Proceed to dashboard”.

If selected “Yes” …

<figure><img src="/files/IULOJuyd3KUICcZauRBD" alt=""><figcaption></figcaption></figure>

User can select “Yes” if generating key on HSM and click “Next”.

<figure><img src="/files/zpavmLw6zdTh29ld27K3" alt=""><figcaption></figcaption></figure>

CA Administrator can enter mentioned HSM configuration details.

<figure><img src="/files/dJZGbgGMCgZ6imMLzTfQ" alt=""><figcaption></figcaption></figure>

Test the HSM connection, confirmation will be provided over a success response.

<figure><img src="/files/5IywCgQFF3apDNkAOYtl" alt=""><figcaption></figcaption></figure>

Authenticate by entering your Username and Password. Once authenticated, click 'Generate AES Key'.

<figure><img src="/files/A2399Z8dZ7Op9GY0rHfM" alt=""><figcaption></figcaption></figure>

A message will confirm AES key generation and “Proceed to dashboard”.

<figure><img src="/files/ynVCAeg9rNdc8HIGkxXq" alt=""><figcaption></figcaption></figure>

CA Administrator will be redirected to the Dashboard.


# Manage Users and Roles

**CA Administrator**

CA Admin can create and manage Admin Users accounts through various functions available.

**Create New Admin User**

Click on the "+ New User" button to create a new user.

<figure><img src="/files/jPJeGyR9Qo7eszDcVhlp" alt=""><figcaption></figcaption></figure>

The following dialog box will appear:

<figure><img src="/files/kxyXXdvXWHYtRe3IARXn" alt=""><figcaption></figcaption></figure>

When creating a new user, the CA Administrator requires the user's information to be provided in three sections:

**1. Map to group -** CA Admin can select a group and access type from a dropdown.

**2. Basic Information -** contains basic details about the user. As Role, “Administrator” is the default and only available.

**3. Other Details -** details such as the login type authentication using password, hard, or soft token, and validation for the token or user.

**Administrator**

Admins can create and manage Officers, Auditors, and other Administrators User accounts.

<figure><img src="/files/nTI3LnqtoEfuYAFutEr6" alt=""><figcaption></figcaption></figure>

**Create Users**

Click on the "+ New User" button to create a new user.

<figure><img src="/files/81VfMJ5Q8yXR8bAso2wf" alt=""><figcaption></figcaption></figure>

When creating a new user, the Administrator requires the user's information to be provided in two sections:

**1. Basic Information -** contains basic details about the user. As Role, Administrator, Officer, and Auditor can be selected.

**2. Other Details -** details such as the login type authentication using password, hard, or soft token, and validation for the token or user.


# Configuring Certificate Profiles

## **Certificate Profile**

**Define Certificate Profiles**\
Certificate profiles define the parameters of certificates issued by a Certificate Authority (CA), such as key usage, extended key usage, and validity periods.

**Ensure Security and Consistency**\
Profiles ensure that certificates align with organizational security policies, providing a consistent and secure approach to certificate issuance.

**Access Certificate Profile Functions**\
Certificate profiles are managed through the Certificates Profiles sub-menu in emCA, where administrators can configure the desired parameters.

The below shows the user interface of the certificate profiles.

<figure><img src="/files/5KAdqfQT4vOMAnYx3ToN" alt=""><figcaption></figcaption></figure>

An Administrator can perform the following actions for certificate profiles by accessing sub-menu:

**Create New Profile**\
Click + New Profile to open the Certificate Profile Edit Dialog. Select the certificate type (X.509, CVC, or EMV) based on the setup configuration. Once a type is selected, the relevant options are activated.

**View Profile**\
Click the view icon to open a read-only version of the Certificate Profile Edit Dialog.

**Edit Profile**\
Click the edit icon to modify an existing certificate profile.

**Clone Profile**\
Click the clone icon to copy all details of an existing profile (except the profile name) to create a new profile.

**Delete Profile**\
Click the delete icon, authenticate with your Administrator token, and confirm to permanently remove the profile.

**Deactivate Profile**\
Click the deactivate icon to disable the certificate profile. Authenticate with your Administrator token and confirm the action.

**Activate Profile**\
Click the activate icon to enable the certificate profile. The process is the same as deactivation.

**Search Profile**\
Use the search function to filter certificate profiles. Apply criteria with equal or contains comparators.

**X509 certificate profile**

Certificate profiles define the technical parameters that can be part of a given certificate such as X.509 Certificate extensions, Subject DN, Key usages, Extended key usages, etc. Certificate profiles are extendable and upgradeable.

## **CA Certificate Profile**

The user must select the X.509 certificate type to generate a CA certificate profile. The default certificate type is "X509".

There are three types of X.509 certificate profiles, each explained in the following section:

* CA Certificate Profiles.
* User Certificate Profiles.
* OCSP Certificate Profiles.

In order to create a root CA OR Sub CA certificate profile, the admin must select the CA Certificate Profile and fill in all mandatory fields in the Certificate Profile Edit Dialog, which contains three sections:

* Basic Information.
* Subject DN Details.
* X.509 Extensions.

**Basic Information**

The following image displays the Basic Information section of the Certificate Profile Edit Dialog.

<figure><img src="/files/1k9WQYk0PjyoNHz8Cq6b" alt=""><figcaption></figcaption></figure>

**Profile Type Selection:** Choose "User" as the profile type.

**Profile Name Entry:** Enter a unique "Profile Name" in the corresponding field, using any printable characters.

**Validity Fields:** When filling in the "validity" fields, ensure it is less than the remaining validity of the issuing CA. Be mindful of leap days, especially when exceeding leap years.

**Issuing CA Selection:** Select the corresponding issuing CA for "Self Signed" in order to create root CA else select any existing CA in order to SUB CA.

**Choose Algorithm:** Choose an algorithm from the list that is supported by emCA and select the corresponding signature algorithm.

Users have choices when it comes to "Signature Algorithms." Here are the options explained:

**DSA Algorithm:** If you choose "DSA," the corresponding signature algorithm is "SHA1WithDSA."

<figure><img src="/files/R6mTibcV6y0tmPxmW7Cc" alt=""><figcaption></figcaption></figure>

**RSA Algorithm:** Opting for "RSA" gives you signature algorithms like "SHA1WithRSA," "SHA256WithRSA," "SHA384WithRSA," and "SHA512WithRSA."

<figure><img src="/files/sFXOiBsFUTUEGLT4Q7i9" alt=""><figcaption></figcaption></figure>

**ECDSA Algorithm:** Going with "ECDSA" means signature algorithms such as "SHA1WithECDSA," "SHA256WithECDSA," "SHA384WithECDSA," and "SH512WithECDSA."

<figure><img src="/files/v9TiygPUtkZMrZNgrpjX" alt=""><figcaption></figcaption></figure>

**EDDSA Algorithm:** If you go for "EDDSA," the associated signature algorithm is "Ed25512."

<figure><img src="/files/VhFO5b8h8OR0uL4vZjKs" alt=""><figcaption></figcaption></figure>

**PQC Algorithm:** Choosing "PQC" Algorithm opens up signature algorithms like "DILITHIUM2," "DILITHIUM3," "DILITHIUM5," "FALCON-512," "FALCON 1024," and "SPHINCSPlus."

<figure><img src="/files/XAderMh4q8zWYS1MxJ5h" alt=""><figcaption></figcaption></figure>

**Edit Subject DN Details**

The following image displays the Subject DN Details section of the Certificate Profile Edit Dialog.

<figure><img src="/files/2uj4kHd7B99R6O2qCDak" alt=""><figcaption></figcaption></figure>

The Subject Distinguished Name (Subject DN) is the unique name that is attributed to the certificate owner.

In order to create a Subject DN, you need to choose from a list of Subject DN attributes. The image above shows a pre-defined subset of the available attributes. To choose the attributes that you want to include in your certificate, simply select the corresponding checkbox. Any unselected attributes will be ignored.

Users can rearrange the order of certificate elements by dragging and dropping the Subject DN attribute.

The first element in the Subject DN is the top element in the UI.

By clicking + Subject OID, you may add additional Subject DN attributes to your list.

Users can rearrange the order of certificate elements by dragging and dropping the Subject DN attribute.

The first element in the Subject DN is the top element in the UI.

By clicking + Subject OID, you may add additional Subject DN attributes to your list.

<figure><img src="/files/23rCdZFNGySFbXIsTjdR" alt=""><figcaption></figcaption></figure>

Object Identifiers (OIDs) identify Subject DN attributes. Customize your OID in the field above.

To choose an attribute encoding, simply use the dropdown list located in the middle of each row.

<figure><img src="/files/C3rZVSCXf0dMbkxOgV8B" alt=""><figcaption></figcaption></figure>

In most cases, PrintableString or UTF8String are used. For more information, refer to RFC 5280.

Please choose either "Mandatory" or "Optional" from the last dropdown menu.

<figure><img src="/files/sUXh3UFdLdnvvA35bgkO" alt=""><figcaption></figcaption></figure>

Mandatory fields are required for certificate generation. Failure results from missing data.

During certificate generation, optional attributes may be provided. Empty fields are not added to the certificate.

**X.509 Certificate Extensions**

The following is the list of extensions available for selection as part of the ‘X.509' Certificate Extensions’ section. To select a specific extension, select the ‘Use’ checkbox attached to the respective extension. In addition, for selected extensions, an option to mark a specific section as ‘Critical’ is also provided.

<figure><img src="/files/uTLpBPiJ7BN7nPizzBlP" alt=""><figcaption></figcaption></figure>

* Select the checkbox 'Use' in order to include specific extensions in the certificate. Note that some extensions must be filled with content if selected in accordance with RFC 5280.
* Select the checkbox 'Critical' in order to set the critical flag in the certificate for this extension. If a critical extension fails validation, the certificate is not valid.
* Users can reorder X.509 Extensions via drag and drop.
* Basic Constraint (mandatory) - By default, the Basic Constraint "None" is selected. The administrator can choose to maintain up to 6 sub-CAs or a certificate hierarchy. This option is only available for CAs.
* Key Usage (mandatory) - Please select the 'Usage' option from the dropdown menu. Make sure to select at least one key.

<figure><img src="/files/4D16nyuhx50kyoWyXp8B" alt=""><figcaption></figcaption></figure>

**Authority Key Identifier**\
This optional extension helps identify the public key used to sign a certificate.

**Issuer Alternative Name**\
Allows additional identities to be associated with the issuer of a Certificate Revocation List (CRL).

**Subject Key Identifier**\
Mandatory extension that provides details for accessing services related to the certificate's subject.

**Authority Information Access**\
Optional extension indicating how to access CA information and services for the issuer of the certificate.

**Subject Alternative Name**\
Optional extension allowing additional identities (email, DNS, IP, URI) to be associated with the certificate's subject.

**CRL Distribution Points**\
Optional extension that identifies how CRL information is obtained.

**Certificate Policy**\
Mandatory extension that defines the roles and duties of entities within a PKI. Clicking (+) allows optional entry.

**Policy Mapping**\
Optional extension containing OID pairs linking an issuer’s domain policy to a subject CA’s domain policy.

**Policy Constraints**\
Optional extension used to prohibit policy mapping or require valid policy identifiers in each certificate path.

**Inhibit Any Policy**\
Optional extension indicating that the 'anyPolicy' OID is not an explicit match for other certificate policies.

**Freshest URL**\
Optional extension pointing to the CRL containing the most current revocation information.

**Subject Information Access**\
Optional extension that specifies how to access services for the certificate's subject.

**Subject Directory Attributes**\
Optional extension for conveying identification attributes of the subject.

**Save Certificate profile**

Click "Proceed" to confirm saving the profile will redirect to the next page you will then be prompted to authenticate the action using your Administrator Username, and Token Pin and click on the ‘Authenticate’ button. The admin credentials will be validated

Click "Confirm" to finalize the certificate profile and view the success message as shown below.

<figure><img src="/files/OsWSbF1e4XuxdrywLpQ2" alt=""><figcaption></figcaption></figure>

You can create new profiles by clicking on "+New" or return to the Certificate Profile overview by clicking "View All".

This way, you can easily set up an X509 CA profile with the necessary details for your specific use.

## **User Certificate Profile**

emCA allows users to generate various X509 certificate types within the certificate framework, as subtypes including New, DS, MLS, and DLS certificates.

Click on + New Profile to create a new certificate profile. This will open the Certificate Profile Edit Dialog.

**Basic Information**

The Basic Information section of the Certificate Profile Edit Dialog is displayed in the following image:

The administrator provides the basic information

<figure><img src="/files/lUmnS5Zwm24GMnX5amIW" alt=""><figcaption></figcaption></figure>

**Profile Type Selection:** Choose "User" as the profile type.

**Profile Name Entry:** Enter a unique "Profile Name" in the corresponding field, using any printable characters.

**Validity Fields:** When filling in the "validity" fields, ensure it is less than the remaining validity of the issuing CA. Be mindful of leap days, especially when exceeding leap years.

**Issuing CA Selection:** Select the corresponding issuing CA for "Issuing CA" to filter Signature Algorithm values to those supported by the issuing CA.

**Signature Algorithm:** Choose a "signature algorithm" that is supported by the options available under the Signature Algorithm.

**Certificate Recovery Option:** If you wish to enable the recovery of user certificates, select "Is KRS Enabled."

**Certificate Transparency Logs:** Select "Is CT Logs Enabled" to create Certificate Transparency (CT) Logs for user certificates. This enables selection between Manual or Automatic Process Types for SCT Requests.

**Manual Authorization:** Choose "Is Manual Authorization Enabled" to ensure that an officer must authorize during creation.

**Customize Validity Support:** Select "Support Customize Validity" to allow different validity values from CSR.

**Link Check:** To include link checks for user certificates, check 'Is Link Check Enabled'.

**Subject DN Details:**

The following image displays the Subject DN Details section of the Certificate Profile Edit Dialog.

<figure><img src="/files/8p9oNXpjVLFKT61N2rNN" alt=""><figcaption></figcaption></figure>

Subject DN (Common name, Country, Email, organization etc.) attributes can be added by selecting the checkbox of the respective attribute. Once the attribute is selected, use the dropdown menu to define the relevant string from the options: Printable String, BitString, IA5String, BMPString, and UTF8String.

The option to make an attribute Mandatory (or) Optional is also provided.

In addition to these options, the order of attributes can also be rearranged using the option next to Mandatory/optional.

Optional: The option to customize OID is also offered. To add a custom Subject DN, click on ‘+ Subject OID’ option.

Enter a valid OID and select the corresponding values to include this OID to the Certificate creation process.

**X.509 Certificate Extensions:**

The following are the list of extensions available for selection as part of the ‘X.509 Certificate Extensions’ section. To select a specific extension, select the ‘Use’ checkbox attached to the respective extension. In addition to it, for selected extensions, an option to mark a specific section as ‘Critical’ is also provided.

<figure><img src="/files/XjgivE4MEwnhq1BcXaik" alt=""><figcaption></figcaption></figure>

**Basic Constraints:** To use the Basic Constraints extension, select the Use Basic Constraints checkbox.

**Key Usage:** From the Key Usage dropdown menu, select the appropriate key usage options.

**Enhanced Key Usage (optional):** From the Enhanced Key Usage dropdown menu, select the appropriate key usage options.

**Authority Key Identifier (optional):** To use the Authority Key Identifier extension, select the Use Authority Key Identifier checkbox.

**Issuer Alternate Name (optional):** To use the Issuer Alternate Name extension, select the Use Issuer Alternate Name checkbox.

**Subject Key Identifier (mandatory):** The Subject Key Identifier extension is mandatory.

**Authority Information Access (optional):** To use the Authority Information Access extension, select the Use Authority Information Access checkbox.

**Subject Alternative Names (optional):** To use the Subject Alternative Names extension, select the Use Subject Alternative Names checkbox.

**CRL Distribution Points (optional):** To use the CRL Distribution Points extension, select the Use CRL Distribution Points checkbox.

**Certificate Policy (mandatory):** The Certificate Policy extension is mandatory. To enter the Certificate Policy, click the (+) button.

**Freshest CRL URL (optional):** To use the Freshest CRL URL extension, select the Use Freshest CRL URL checkbox.

**Subject Information Access (optional):** To use the Subject Information Access extension, select the Use Subject Information Access checkbox.

**Subject Directory Attributes (optional):** To use the Subject Directory Attributes extension, select the Use Subject Directory Attributes checkbox.

**Private Key Usage Period:** To Configure the private key lifetime by providing the validity

**Save Certificate profile**

Click "Proceed" to confirm saving the profile will redirect to the next page you will then be prompted to authenticate the action using your Administrator Username, and Token Pin and click on the ‘Authenticate’ button. The admin credentials will be validated

Click "Confirm" to finalize the certificate profile and view the success message as shown below.

<figure><img src="/files/c2PJrcw1vvlw7jGpwauQ" alt=""><figcaption></figcaption></figure>

You can create new profiles by clicking on "+New" or return to the Certificate Profile overview by clicking "View All".

This way, you can easily set up an X509 User profile with the necessary details for your specific use.

## **OCSP Certificate Profile**

Click on the "+ New Profile" button to create a new certificate profile. This will open the Certificate Profile Edit Dialog.

**Basic Information:**

The image below displays the "Basic Information" section of the Certificate Profile Edit Dialog:

<figure><img src="/files/SFJpMG4xrae9eujs3n61" alt=""><figcaption></figcaption></figure>

**OCSP Selection:** Choose OCSP by selecting the OCSP radio button.

**Profile Name Entry:** Give your profile a unique name.

**Validity Duration:** Choose how long the certificate should be valid in terms of days, hours, minutes, and seconds.

**Issuing CA Selection:** Pick the issuing CA from the dropdown.

Signature Algorithm Selection: Choose the signature algorithm that suits your needs.

**Subject DN Details:**

The following image displays the Subject DN Details section of the Certificate Profile Edit Dialog.

<figure><img src="/files/TTh2k2JLyC8JSeoEglE0" alt=""><figcaption></figcaption></figure>

**Subject DN Attributes**

Subject DN attributes can be added to a certificate by selecting the checkbox for the desired attribute. Once an attribute is selected, use the dropdown menu to specify the data type. The data types available are Printable String, BitString, IA5String, BMPString, and UTF8String.

Attributes can be marked as Mandatory or Optional. The order of attributes can also be changed using the arrows next to the Mandatory/Optional checkbox.

**Optional: Custom Subject DN OIDs**

To add a custom Subject DN OID, click the "+ Subject OID" button. Enter a valid OID and select the corresponding values to include this OID in the certificate creation process.

**X.509 Certificate Extensions:**

The following are the list of extensions available for selection as part of the ‘X.509 Certificate Extensions’ section. To select a specific extension, select the ‘Use’ checkbox attached to the respective extension. In addition, for selected extensions, an option to mark a specific section as ‘Critical’ is also provided.

* **Key Usage:** This tells how you can use your certificate key. For example, you can use it to sign other certificates or revoke them. You can pick one option from the dropdown list. The default option is Key Agreement, Key Certificate, CRL Sign.
* **Enhanced Key Usage:** This adds more ways to use your certificate key, besides the basic ones. You can pick one option from the dropdown list. This feature is optional.
* **Authority key identifier:** This helps to identify the key that signed your certificate. This feature is optional.
* **Issuer alternate name:** This adds more names for the issuer of CRL. CRL is a list of revoked certificates. This feature is optional.
* **Subject Key Identifier:** This tells how to find information and services for your certificate. This feature is mandatory.
* **Authority Information Access:** This tells how to find information and services for the issuer of your certificate. This feature is optional.
* **Subject alternative names:** This adds more names for your certificate, besides the one you already have. It can be an email, a website, an IP address, or a web address. This feature is optional.
* **CRL distribution points:** This tells how to get the list of revoked certificates. Revoked certificates are the ones that are no longer valid. This feature is optional.
* **Certificate policy:** This tells the rules and responsibilities of the certificate issuer and user. The issuer is the one who gives you the certificate, and the user is you. You can enter your own policy in the text box by clicking on the (+) button. This feature is mandatory.
* **Freshest URL:** This tells how to get the latest information about revoked certificates. This feature is optional.
* **Subject information access:** This tells how to find information and services for your certificate. For example, you can find out how to renew or revoke your certificate. This feature is optional.
* **Subject directory attributes:** This adds more details about your identity, such as your name, address, or phone number. This feature is optional.
* **OCSP No Revocation Checking:** This tells the rules and responsibilities of the certificate issuer and user, without checking for revoked certificates. This feature is optional.

**Save Certificate profile**

Click "Proceed" to confirm saving the profile will redirect to the next page you will then be prompted to authenticate the action using your Administrator Username, and Token Pin and click on the ‘Authenticate’ button. The admin credentials will be validated

Click "Confirm" to finalize the certificate profile and view the success message as shown below.

<figure><img src="/files/sblri7arqRyiupR9qn89" alt=""><figcaption></figcaption></figure>

You can create new profiles by clicking on "+New" or return to the Certificate Profile overview by clicking "View All".

This way, you can easily create an OCSP profile with specific details for your use case.


# Manage emCA

This section explains daily operations after installation. It covers creating root and issuing CAs, configuring OCSP and timestamping, and defining certificate profiles and lifecycles. It includes user and role management, keystore/HSM administration, external integrations and APIs, and protocol setup (ACME, EST, SCEP, CMP).

You will also find mail/notification setup, reporting, and key-recovery procedures. All actions are role-based, can require M-of-N approvals, and are fully audited.


# Creating a Root Certificate

## **Enroll**

Users with the Officer role can enroll a Root CA from the CA Certificates UI.

The workflow generates an HSM-backed CA key pair and either issues a self-signed root certificate or produces a CSR for external signing, as defined by policy (with M-of-N approvals if enabled

{% hint style="info" %}
Note: CA certificates and OCSP certificates are both generated using this UI.
{% endhint %}

<figure><img src="/files/rdmkvohTxYXcj876Nr16" alt=""><figcaption></figcaption></figure>

## Generate Key Pair

Click on "Generate Key Pair " to open the following dialog:

<figure><img src="/files/1rgZc0r31LtV6hPUlFda" alt=""><figcaption></figcaption></figure>

Enter the number of keys that you want to generate. In general, you will need 1 key for 1 CA and 1 more key, if that CA will receive an OCSP certificate.

Select the "Key Profile" you want to use from the first dropdown list.

<figure><img src="/files/8TXSFUlBukZqmvZNmdbK" alt=""><figcaption></figcaption></figure>

Choose the "Algorithm" from the drop-down

Select the "Signature algorithm". This will filter the element for the third dropdown list accordingly.

<figure><img src="/files/osl92YduDKdczZAYMOC3" alt=""><figcaption></figcaption></figure>

Select the "Key Algorithm" and "Key Size"

<figure><img src="/files/wvSPi55cAHsfU9XoDgNb" alt=""><figcaption></figcaption></figure>

Press "Proceed" to continue and authenticate the action via Username & Password or Hard/ Soft token basis.

<figure><img src="/files/8q2hwLKJ7KepqLqKO1u6" alt=""><figcaption></figcaption></figure>

Click on "Generate Key Pair(s)" to generate the keys

<figure><img src="/files/GRpmkpyCvgZ9TEqqbhRa" alt=""><figcaption></figcaption></figure>

After the successful generation of the key pair, click on "View all" or "+ New" to continue with the new Key Pair creation.

## Generate CA Certificate

After creating a key pair, select the "Generate Certificate" or "CSR" option available in the "Action" column of the created key pair.

<figure><img src="/files/Coyhvq00jqM5S0WmiF9R" alt=""><figcaption></figcaption></figure>

Click on  !\[A black flag on a white background

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAA0ADgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1yLzpYwwcDNP8uf8A56Ci0/491ovLuOxtJLiX7kYyaTdtwSuHlz/89B+VHlz/APPQVi6F4ysNemeO33Iy/wB7vW+rq/3WB+hqrCIvLn/56Cjy5/8AnoKnpAwJ4IOKQytL50UZYuDiin3f/Hu1FABaf8e61HqkSTabOkgypQ8VJaf8e60l/wD8eM3+4amfwsqO6PCZZ5dP1GYWkhiwxAxU8PiPVoGzHeyCquo/8hKf/eqvketEG+VCkveZ0M3jjV5YdgnZTj7wrqPhxqN3etN9qnaX615tXoPwv+9NWsFuZz6HoN3/AMe7UUXf/Hu1FQWFp/x7rSX/APx4zf7hpbT/AI91qSSMSxsjdGGDSkrpoadnc8u8M+F7PxDe3kl5uwj4AWujm+GmjtERGJFbsc1u6RoVvo7zNASfNbcc1qU7KySFrds80Pwun+0cXKeVnp3rsvD/AIatPD8BS3yWb7xNbNFNNpWE1cgu/wDj3aii7/492opDC0/491qeiigAooooAKKKKAILv/j3aiiigD//2Q==) to start generating a CA certificate.

<figure><img src="/files/WN5LjY1knXZeEFXqaIEa" alt=""><figcaption></figcaption></figure>

The above window opens after clicking on “Action”.

There are two different options available for generation:

* Certificate – use the key to generate a new CA certificate directly.
* CSR – use the key to generate a Certificate Signing Request (CSR).

Choose "Certificate" if you want to directly generate a new CA certificate. This option is applicable if the CA is "self-signed" or the "issuing CA" is in the same instance

Choose "CSR" if the issuing CA is not on the same instance. This is the case if ROOT and SUB CAs are not operated on the same system.

{% hint style="info" %}
Note: You can operate CAs using the appliance functionalities that have their trust anchored outside the Appliance using the option CSR.
{% endhint %}

<figure><img src="/files/kgFAIy15qc9JjHEM6XmJ" alt=""><figcaption></figcaption></figure>

CA Administrator created certificate profiles will be available under “Certificate profile” dropdown.

<figure><img src="/files/KtuQ4n7oriIjIFUrHBe1" alt=""><figcaption></figcaption></figure>

For "Subject DN Details", enter all Subject Distinguished Name (Subject DN) information for the CA as per the certificate profile selection.

Press "Proceed" to continue. You will be prompted to authenticate the action using your officer token/ username & password. Press "Authenticate" to proceed.

<figure><img src="/files/xykoqgDniW5jtE8bKhkc" alt=""><figcaption></figcaption></figure>

Officer is required to successfully authenticate and continue with “Create”.

<figure><img src="/files/8qCRgB6T881XxxEgdzAI" alt=""><figcaption></figcaption></figure>

The "Certificate" will be created and downloadable.


# Creating an Issuer CA Certificate

Issuing CA can happen in two flows in emCA. One is through external root, and the other is directly through existing internal root.


# Internal CA Certificate Issuer

Administrator shall crate a Profile under Issuing CA. These steps are covered under [Configure CA Certificate Profile](/getting-started/configuring-certificate-profiles).

## **Officer Login**

Officer can use this profile to Sing the CSR as displayed in the following interface.

## **Generate Key Pair**

Click on "Generate Key Pair " to open the following dialog:

<figure><img src="/files/gPakfBkN3J4Zk2wPBR1T" alt=""><figcaption></figcaption></figure>

Enter the number of keys that you want to generate. In general, you will need 1 key for 1 CA and 1 more key, if that CA will receive an OCSP certificate.

Select the "Key Profile" you want to use from the first dropdown list.

<figure><img src="/files/WfzvAKUlQcxClG5OT2fD" alt=""><figcaption></figcaption></figure>

Choose the "Algorithm" from the drop-down

Select the "Signature algorithm" from the third dropdown list. This will filter the element for the third dropdown list accordingly.

<figure><img src="/files/skECpiGVhzIwKIUOuK3S" alt=""><figcaption></figcaption></figure>

Select the "Key Algorithm" and "Key Size" from the fourth dropdown list.

<figure><img src="/files/DJ6Sasmd0tpydZ5Tjbjm" alt=""><figcaption></figcaption></figure>

Press "Proceed" to continue and authenticate the action.

<figure><img src="/files/wqNuVWFFjkYwK1JnP01x" alt=""><figcaption></figcaption></figure>

Click on "Generate Key Pair(s)" to generate the keys.

<figure><img src="/files/bPEdfrIhdfm7EAzuLTXP" alt=""><figcaption></figcaption></figure>

After the successful generation of the key pair, the success message as shown below.

Click on "View all" or "+ New" to continue with this new Key Pair creation.

## Generate CA Certificate

After creating a key pair, the user needs to select the "Generate Certificate" or "CSR" option available in the "Action" column of the created key pair.

<figure><img src="/files/rwsM6GJM74rADnzUvqUi" alt=""><figcaption></figcaption></figure>

Click on  !\[A black flag on a white background

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAA0ADgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1yLzpYwwcDNP8uf8A56Ci0/491ovLuOxtJLiX7kYyaTdtwSuHlz/89B+VHlz/APPQVi6F4ysNemeO33Iy/wB7vW+rq/3WB+hqrCIvLn/56Cjy5/8AnoKnpAwJ4IOKQytL50UZYuDiin3f/Hu1FABaf8e61HqkSTabOkgypQ8VJaf8e60l/wD8eM3+4amfwsqO6PCZZ5dP1GYWkhiwxAxU8PiPVoGzHeyCquo/8hKf/eqvketEG+VCkveZ0M3jjV5YdgnZTj7wrqPhxqN3etN9qnaX615tXoPwv+9NWsFuZz6HoN3/AMe7UUXf/Hu1FQWFp/x7rSX/APx4zf7hpbT/AI91qSSMSxsjdGGDSkrpoadnc8u8M+F7PxDe3kl5uwj4AWujm+GmjtERGJFbsc1u6RoVvo7zNASfNbcc1qU7KySFrds80Pwun+0cXKeVnp3rsvD/AIatPD8BS3yWb7xNbNFNNpWE1cgu/wDj3aii7/492opDC0/491qeiigAooooAKKKKAILv/j3aiiigD//2Q==) to start generating a CA certificate.

<figure><img src="/files/FxtManpbhdTS9vX85jup" alt=""><figcaption></figcaption></figure>

The above window opens after clicking on “Action”.

Certificate – use the key to generate a new CA certificate directly.

Choose "Certificate" if you want to directly generate a new CA certificate. This option is applicable if the CA is "self-signed", or the "issuing CA" is in the same instance.

<figure><img src="/files/JK7POhMIdW41VIyXnv4s" alt=""><figcaption></figcaption></figure>

CA Administrator created certificate profiles will be available under “Certificate profile” dropdown.

<figure><img src="/files/kxUwXAlv9f55IMS0WX9j" alt=""><figcaption></figcaption></figure>

For "Subject DN Details", enter all Subject Distinguished Name (Subject DN) information for the CA as per the certificate profile selection.

Press "Proceed" to continue. You will be prompted to authenticate the action using your officer token. Press "Authenticate" to proceed.

<figure><img src="/files/ppVSpLwAhYruUMVvkCP5" alt=""><figcaption></figcaption></figure>

Officer is required to successfully authenticate and continue with “Create”.

<figure><img src="/files/HJODe8DMi4Z45IRQyKl7" alt=""><figcaption></figcaption></figure>

The "Certificate" will be created, and the user is able to download the certificate.


# External CA Certificate Issuer

## Officer Login

Once the ‘Key Profile’ is created by the CA Administrator, login as ‘Officer’ to create Key Pairs and generate CSR.

## Generate Key Pair

Click on "Generate Key Pair " to open the following dialog:

<figure><img src="/files/qW52A3LeaWmc7cwMh95b" alt=""><figcaption></figcaption></figure>

Enter the number of keys that you want to generate. In general, you will need 1 key for 1 CA and 1 more key, if that CA will receive an OCSP certificate.

Select the "Key Profile" you want to use from the first dropdown list.

<figure><img src="/files/uvbD9IhzXwDcy4lb6T3H" alt=""><figcaption></figcaption></figure>

Choose the "Algorithm" from the drop-down

Select the "Signature algorithm" from the third dropdown list. This will filter the element for the third dropdown list accordingly

<figure><img src="/files/bJNk8MuAs19Sx9OFNiBq" alt=""><figcaption></figcaption></figure>

Select the "Key Algorithm" and "Key Size" from the fourth dropdown list.

<figure><img src="/files/oa6adlVx3z4J0G9xLSnM" alt=""><figcaption></figcaption></figure>

Press "Proceed" to continue and authenticate the action.

<figure><img src="/files/iiqBFvxJ1VY3BSUG9N7C" alt=""><figcaption></figcaption></figure>

Click on "Generate Key Pair(s)" to generate the keys.

<figure><img src="/files/ok2d9p7iIVaIT4Bz2Hpk" alt=""><figcaption></figcaption></figure>

After the successful generation of the key pair, the success message as shown below.

Click on "View all" or "+ New" to continue with this new Key Pair creation.

## Generate CSR

Click on Manage CA Certificate -> Enroll. The following screen will be displayed.

<figure><img src="/files/ujgB6IFF0q2oNTA2q2yw" alt=""><figcaption></figcaption></figure>

Click on Action icon![](data:image/png;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAeACsDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2J3IYBaPn9RQf9aK4Tx7rF7ompQXFrIQMDK54pN2C1zu/npGZ1GTXl4+KV8sR3woW7cV32g6jJquhxXUwAd+uKdhGsDkA0tIv3RS0ARn/AForjfGGhPr+rQWx3LGACWFdhK2xwab5wJzsGfWixVzzy7+FZ3qLe5JXvmu50nTBpGkRWitu2DrVv7R7UjTbhjFAidfuilpF+6KWgR//2Q==)in ‘Action’ column as shown in the above Figure.

The following page will be displayed.

<figure><img src="/files/y7lW9h8NQIlBeLa835Jn" alt=""><figcaption></figcaption></figure>

By default, ‘Certificate’ radio button will be selected. Please change the option to ‘CSR’.

The following options will be displayed.

<figure><img src="/files/2mHDIoSAsK7si6UYfK1T" alt=""><figcaption></figcaption></figure>

Select the ‘Subject DN’ from the drop-down. The following options will be displayed.

<figure><img src="/files/6a3bOrUcwLLPASdLSpHD" alt=""><figcaption></figcaption></figure>

Select ‘Subject DN’ - ‘Common Name’ from the drop-down.

<figure><img src="/files/Qegke3cLGexwqjTpfUTX" alt=""><figcaption></figcaption></figure>

Once the Common Name is selected under Subject DN, click on ‘+’ icon next to the ‘Common Name’ from the drop-down.

A new field will be displayed based on the selection made.

Enter the relevant details in the new field (‘Common Name’ in the current example) as viewed below.

<figure><img src="/files/QjGbLgunv82fcfpctG6J" alt=""><figcaption></figcaption></figure>

Follow the same process to add individual Subject DN details and their relevant values.

Once the details are added, click on ‘Proceed’ button. The following ‘Verify and Confirm’ page will be displayed.

The following ‘Verify & Confirm’ page will be displayed.

<figure><img src="/files/8jhqvk5pce7DEBKo8WFa" alt=""><figcaption></figcaption></figure>

Officer should enter the Username and Token pin and click on ‘Authenticate’.

On successful authentication, click on ‘Create’ button.

CSR will be successfully created as displayed below.

<figure><img src="/files/mo0uWZV7LrZcUCOqq7PO" alt=""><figcaption></figcaption></figure>

Clicking on “Download CSR” will download .csr in the system.

<details>

<summary>Submit the same CSR to the ‘Root Authority’ to get the X509 certificate.</summary>

</details>

To view the CSR created, click on ‘View All’.

Once the CSR is signed by the Root Authority, login as ‘Officer’ to Import the Signed Certificate.

## Import Issuer Certificate

To import ‘Issuer Certificate’, login as ‘Officer’ and click on Manage CA Certificate -> CA Certificates. The following page will be displayed.

<figure><img src="/files/ZTX3tFcV7XazLZ0rUm7r" alt=""><figcaption></figcaption></figure>

Click on ‘Import Issuer Certificate’ on the top right corner of the page.

The following pop-up will be displayed.

<figure><img src="/files/AmeAXvVCx9z2PEbpHZgj" alt=""><figcaption></figcaption></figure>

Click on ‘Choose File’ and upload.

Once the file is uploaded, enter the username and Token Pin of the respective officer and click ‘Authenticate’.

<figure><img src="/files/DxdcD26j6KqPJoVagYdw" alt=""><figcaption></figcaption></figure>

On successful authentication, click on ‘Import X509’ to import the certificate.

<figure><img src="/files/tMLJ8VA7RcXHahzgUaRN" alt=""><figcaption></figcaption></figure>

The Certificate will be imported successfully and the following success message will be displayed.

<figure><img src="/files/OTkzvvJtorjeB4cISQrb" alt=""><figcaption></figcaption></figure>

## Import CA Certificate

Click on Manage CA Certificate -> CA Certificates. The following page will be displayed.

<figure><img src="/files/LOYpvu20FnJMhZS0koxA" alt=""><figcaption></figcaption></figure>

To import CA Certificate signed by CCA, click on ‘Import  ![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABsAAAAcCAIAAAAfs1O6AAAAAXNSR0IArs4c6QAAAAlwSFlzAAAOxgAADsMBl6I51wAAAd1JREFUSEtj/Pf/PwNVARNVTQMZxvj///+PHz9Sbi4/Pz/Es0xA437+/EmhiUAT4M5i/PDhA9A4oA2UGAoxjg9sCPXDcSiYiC8cvz6+cuvVb8zwZRVT05HlRhZHDkecJr7aXlO4hdvWRIwV3cjfr84c/urT3+IpBpdBNpEBGNdAAEyVqODynKiJJ75DxX49uXnuzLlzt558+QUW+X5iYtScy0gaIIYAsx8QseBMNL+5uTkYPlzdPHfaipOvYX5nFTNPryu24+bGEhhQk/DH9dev3EYZHbP6W/OSnRVB3v/96uSUmsW3dWy92XA5Bb+J3NIK0ty83NKqNu7pnV3h0mBTPuw4eEUtJlYHh5EkpEdpaydFsCm/b91/xYwztEgwkUFCUQ1izoNXr3DnWVJMJC7n4zHx9++/cDO+Pr16/vzZW0+hAk9vnT1//urTr9jswJXCf1+Znz3prW+coww3A6u0ttiVnsIZl1CSDKtGcn+TOySVE5VnGP5+vX9o874HIHeImUX4anzd2V44F2YoyLh6dzFY/BCTZzAyEVDgz8sdzVGhoaFRtTte/kFRgJxncOVCbCaCDT2x7gSacUBhZBNHy3DiUjAhVaBwBNaN7OzshFTik4eYAKkLqd8CAAC3AI/6rCnHFAAAAABJRU5ErkJggg==)’ icon available in the ‘Action’ column corresponding to the respective CA Certificate as shown in the above figure.

The following pop-up will be displayed.

<figure><img src="/files/cYFegU4rXpAQRMh4kgsj" alt=""><figcaption></figcaption></figure>

Click on ‘Choose File’ and upload.

Once the file is uploaded, enter the username and Token Pin of the respective officer and click ‘Authenticate’.

<figure><img src="/files/k43K1fcbL2M4J1NV14Dh" alt=""><figcaption></figcaption></figure>

On successful authentication, click on ‘Import X509’ to import the certificate.

<figure><img src="/files/1Mkzpa7WlGJDSme8AfY8" alt=""><figcaption></figcaption></figure>

The Certificate will be imported successfully, and the following success message will be displayed.

<figure><img src="/files/p6V3wI8phlTwSVzimIDi" alt=""><figcaption></figcaption></figure>


# Creating a User Certificate

**Enroll**

Users with the Officer role enroll an Issuing CA under an existing Root or Intermediate CA.

The result of this UI is always both private and public key for a new user.

<figure><img src="/files/YMQ9IbVj2Lev4uFAXScS" alt=""><figcaption></figcaption></figure>

Officers can generate two types of user certificates:

* Soft token – storable in PFX, JKS or JCEKS keystores.
* Hard token – storable in ePass or eToken hard tokens.

**Soft Tokens** are software-based authentication tokens (e.g., keystore files).

This means that they do not have any additional requirements and can be stored and used directly on the user’s system.

Note:

It is highly recommended to enable enhanced security when importing Soft Token.

Enhanced security enforces the entry of the Soft Token password on use. If Soft Token certificates are imported without enhanced security, anyone with access to your browser also has access to your certificates.

**Hard Tokens** are generated onto some hardware token (e.g., secure USB device or smart card).

This means that 2-factor authentication is enforced as a token, and the system can be separated at any time.

emCA supports Hard Token which supports either ePass configuration or eToken configuration.

The following image is an example of a Soft Token UI:

<figure><img src="/files/DOvrA6beV7lwJXlgn5se" alt=""><figcaption></figcaption></figure>

An Officer can choose from all certificate profiles available in his/her group. Depending on the certificate profile additional insert fields will be loaded in.

<figure><img src="/files/46pbUIq7IOFnbrGoijCt" alt=""><figcaption></figcaption></figure>

**Viewing Certificate Profile Details**

To view the details of a certificate profile, click the "View" button next to it. This will open the profile in a read-only view as displayed above.

The fields displayed will depend on the selected certificate profile.

**Subject DN Details**

<figure><img src="/files/MavSlefuDKJ6ISUEdtE4" alt=""><figcaption></figcaption></figure>

For the Subject DN Details section, you must fill in all of the required fields. Optional fields can be left empty and will be ignored during certificate creation.

The information provided in this section will be used to generate the Subject Distinguished Name (Subject DN) of the certificate owner.

**Other Details**

<figure><img src="/files/r4RYbDWogyNNjsSxvBBM" alt=""><figcaption></figcaption></figure>

For the Other Details section, you can leave the subscriber ID field empty, or enter your subscriber ID if you have one.

Select the Key Algorithm and Key Size for the user certificate.

<figure><img src="/files/xHN08BXb2jeLwxiTaZJo" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Note: The Key Algorithm of the issuing CA does not limit the Key Algorithm of the user.

It is however recommended to avoid mixed-cryptography hierarchies because they require additional maintenance effort without real benefits.
{% endhint %}

For Soft Token, select the Keystore Type from the following options:

<figure><img src="/files/FtP6eFZnYn7kzIstVeDQ" alt=""><figcaption></figcaption></figure>

For Hard Token, select the Keystore Config from the following options:

<figure><img src="/files/hHHbUhrmwGfuklGtA6IE" alt=""><figcaption></figcaption></figure>

For Soft Token, insert the password for the Soft Token into Password and confirm it in Confirm Password.

You can inspect the given password policy by hovering above

{% hint style="info" %}
Note: Soft Token Password is only intended as a One-Time-Password (OTP). It is recommended to change the token password after receiving it.
{% endhint %}

For Hard Token, insert the PIN for the Hard Token into Token PIN.

{% hint style="info" %}
Note: The Token PIN is the already established PIN on the Hard Token of your choice.
{% endhint %}

Click "Proceed" to Authenticate.

<figure><img src="/files/OGMCYCBESBfvukk7836I" alt=""><figcaption></figcaption></figure>

You will be prompted to authenticate using Username & Password or Token.

Authenticate using your Officer token and proceed by pressing Authenticate.

Click on "Create" to create the new user certificate.

Depending on the Key Algorithm and Key Size this may take several seconds.

Upon completion, a summary will be displayed. For Soft Tokens, this summary includes the following element:

<figure><img src="/files/dEZ1xycFko7FgzVgIWfh" alt=""><figcaption></figcaption></figure>

Click on "Download Certificate" in order to retrieve the Soft Token of your choice.


# Managing CA Certificates

Officer can create and manage CA Certificates in this section

## Generate CSR

For CSR, the following dialog will be shown:

<figure><img src="/files/SCPWv3hge2LKBm2Kafqz" alt=""><figcaption></figcaption></figure>

Select the DN attribute type from the first dropdown and add it to Subject DN.

The following "DN attributes" are available:

<figure><img src="/files/DbdZu5EbUtaJAZylfLaQ" alt=""><figcaption></figcaption></figure>

Every added DN attribute is marked as required. Remove DN attributes by clicking !\[A white square with black lines

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAdAB0DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD02YebM7PydxAz2pnlL/dFTEfO/wDvn+dVb65ktI1aK0muiTgrFjI9+aAH+Uv90flQZ5LXiI7Q3UU63dpoEkeJ4mYZKP1X2NR3Y5T8aALYXLP/AL5/nS7abdS/ZJim3cGO70xmoft//TMfnQBY21UvRgpn3p/2/wD6Zj86nht11BN7krt4AFAH/9k=)next to them. Click !\[A white square with a black and blue plus symbol

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAmACUDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1eSR5ZX+dlVW2gKcU3af+e0v/AH1TQf3kv/XQ0uaAF2n/AJ7S/wDfVG0/89pf++qqx6jBLfyWalvOjXcwI4x9as5oAa989mQpJkDdM9RRVXUD80f0NFAFknEsv++aqaiuoSRoNNmhicH5jKuQRVlz++l/3zSZoA5S2j1o+IbpY7q2F2Ixvcp8pHsK6ezFylqgvZEknH3mQYBpqWsEd09ysYEzjaz+oqbNHQOpXvjkp9DRSXZyU+lFAFq+X7NMzHlXORVX7Uv900UUAH2pf7po+1L/AHTRRQBbgsheR+YzYHYCiiigD//Z)next to Subject OID’s to add custom DN attributes.

<figure><img src="/files/0FQC3Noo1IwPrVCecFEq" alt=""><figcaption></figcaption></figure>

Enter the OID and value of the custom DN attribute. Remove attributes by clicking the !\[A white square with black lines

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAiACIDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1NgJpJGlG7DFRnsKPJh/55J+VJnDy/wC+aM0AHkw/880/Kl8mLtGoPqKOR1FIGoArNqU6MVDjCnHNFVpP9Y31NFAF8n97L/vmmTx+fbvEHZN4xvXqPcUrnE8o77zSZoAp6dpp093Y3tzcbhjErZA+laG6o80bqAKTn9431NFOaJyxIUkE0UAXdX+WZCOCRzjvWfub+8fzoooANzf3j+dOjJMqgkkEiiigDpFUBQABjFFFFAH/2Q==)icon.

Click !\[A white square with a black and blue plus symbol

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAApACcDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1eSR5ZXAdkVTtAWm7W/57y/8AfVNB/ezf9dDTs0AG1v8AnvL/AN9UbW/57y/99VC13Alytu0qidxlU7kVNmgBGne1G8uzr0Iaiob0/wCjN9RRQA8nE03++arajdXFrbeZaWpupM42A449anY/v5v980ZoA5CfU9QbxFb3DaUy3CoQsO7lh65rpdMvbq8idryyNowbAUnOR60yXThLrEN+ZSGiUrsx1/Gru7NC2B7kd2c25+oopLo/uD9RRQBJMDHcyhuMtkUzcPUVPrPRKyaAL+4eoo3D1FUKKALro0w8uMZY80VPo3V6KAP/2Q==)next to SAN Details to add Subject Alternative Name (SAN) attributes.

<figure><img src="/files/1wSqZGMqY3EPaMN5ifkH" alt=""><figcaption></figcaption></figure>

Select the type of SAN attribute from the dropdown list.

A new text field will appear next to the list. You can insert the value for the SAN attribute into the text field. If you want to remove SAN attributes, just click the !\[A white square with black lines

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAsACwDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1SX/SJ5BJyqHaF7U37PB/zzWlzief/fpc0AN+zwf88xR9nh/55rTs0Z5oAb9nh/55io2vpLRvKHzAdM9qmzWfe83J+goAuk/6RP8A79LmmOcXM/8Av0ZoAp32uafpkqxXk/luwyBjtU9lfW+oW4ntZPMiJxuxiia1trh908EUrDgF1zTooo4E2QxrGn91RgUICbNUbvmc/Sreap3R/fH6CgC3IcXM/wDv03NTaqgixKnDNwazvtD+tAFvNLmqf2h/UUCd/UUAW81VuATKSBmk89/UVt2ttEIFyoJPJJoA/9k=)icon next to them.

Press "Proceed" to continue. You will need to authenticate the action using your Officer token and then press Authenticate.

Click on Create to generate the CSR.

Upon completion, the following view will be displayed:

<figure><img src="/files/ucfStY85Gxo80JpT0f9u" alt=""><figcaption></figcaption></figure>

Click "Download CSR" to download the CSR.

## CA Certificates

An Officer can manage the CA certificates in his/her own group from this interface.

<figure><img src="/files/trddt1xGU5HBx2wNnOuw" alt=""><figcaption></figcaption></figure>

To import an External CA certificate into the emCA Application, click on "Import Issuer Certificate".

Please note that only the CA certificate will be imported, not the CA key.

<figure><img src="/files/SrUGlgnrnZkKfDtDRzBC" alt=""><figcaption></figcaption></figure>

If you want to export the entire table to an XLSX file, click on "Export to Excel". The file will be automatically downloaded to the standard download location of your operating system.

Import Issuer Certificate

To import a CA certificate !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAfABsDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19V3AszMOT3pvmW//AD8L/wB/BVLXGK+HL8qSCI3wRXEX2nWWnadDPH4anuolhV5rgzsASRzgZpXHY9HQRyDKSlh7Nmq8rukrKrtge9YXgm3tWimv9MBjsrkDEBYkxuOD1rbuP9e1Nom4ajavfaNd20RAklRlUnpk1h6jNq9h4OeN9Oikkjj8p1STPyYxuH+FdRD9w/U04gEEEZB4pNFJnnnwwvL0wy2iWwNkrFmnJxg+gHeu1uP9e1Wra1gs4vKtokijyTtUYGTVW4/17U2yUj//2Q==) in response to a CSR, follow these steps:

1\. Click on "Choose File" to select the CA certificate that needs to be imported.

2\. Click on "Import X509" to upload the certificate.

3\. You will be prompted to authenticate the action.

4\. Use your Officer token to authenticate and proceed by pressing "Authenticate".

5\. Click on "Import X509" again to complete the upload process.

<figure><img src="/files/slxIilLEO85wIabTfV45" alt=""><figcaption></figcaption></figure>

View Certificate Details

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAZAB0DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2FEDLk5zk96iuLmztMfabiOHd03ybc/nT3MotJDAAZcNsDdCe2a8qs726U6nPfWb3mslvL2v96BccMintn0pAeqQS211H5lvKkqf3kfcP0pl18m3aSM5715nosuqQeJdPWxQC6kjBvok4TGerAcA4/WvTL3+D8adhXJ4/ufif51VvtG0/UmDXlrFK4GA5GGH4jmon/wBY31NJQMtWWnWmnRlLO3ihU8nYuM/U96S9/g/GqopG6CgD/9k=)to view the CA certificate details:

<figure><img src="/files/8lN4blXaQRnX3TKwamKt" alt=""><figcaption></figcaption></figure>

Download Certificate Details

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAgACMDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BEDgklup70rIiKWZmAAyTu6UsP3D/vH+dZPiXXbTRLEm8WbbMrIrIm4A47+lJuwLUn07VtN1aSRLG7EzRffCseKv+Svq3/fVeS+BNdtNF1O5N0JSbjCRiNNxJzXrincoOCMjoaYupQnZ0mZVdgB70Ul1/wAfD/57UUDL0X3D/vH+deaa38QJHurvTrrTrea2WQxsCxyQO/1r0iOVFBDOoO48E1VfTdJkdne1tGZjkkoMmlYDy7S9S0/Rrzz9EtzqF0csPP8AlEC+g9T716F4S1+5161uHu4Ehlhk2FVOavf2XpA6WloPogqxbx2dopW3WGJSckIAMmmIr3X/AB8P/ntRSXDBp2IIIooGf//Z)to download the user certificate as

<figure><img src="/files/sdfuRZdmYbO7FduqK3l7" alt=""><figcaption></figcaption></figure>

Select the export format of your choice and click Download to start the download of the user certificate.

The user certificate will be downloaded to the standard download location of your OS.

**CSR Creation Using Existing Keypair**

Click on !\[A black arrow in a circle

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAfACEDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19E3liXb7xHBpXRI1LPKyqOpLYApYujf7xrmL3TLzxJ4glhvvOh0m2ACoDt89j7+lIDoYprafPlXSyY5O2QHFPTy5Y98UxdexVsiuA8Q6GulT+X4d0m9inAyJ4XyjZ6giun8G209p4Ygiu4mimG4srDByTTWonoW/Pl/56N+dFMooGacXR/8AeNeY3NzqJ1m9nuJ79tOScx7rdsmM/T0r0pbiOMurEg7j2pqSWkW7y0Vd5y2Fxk+9LrcOljmbrxUb2zXT9AjuLi7kXYJmQqE9ST610unWstnpcME8zTSomHkY5LGnJNbRAiNQueu1cU43kRBG4/lTEZ9FFFAz/9k=)to create a new CSR based on the same key. This option is only available for CA keys with pending CA certificate requests.

You will be forwarded to the following CSR creation UI:

<figure><img src="/files/Myp0Z0lcuKbFYSEwUFpX" alt=""><figcaption></figcaption></figure>

You will have the option to edit the new CSR before creating it.

Click "Proceed" to continue.

You will be prompted to authenticate the action.

Authenticate using your Officer token and proceed by pressing "Authenticate".

Click on "Create" to generate the new CSR.

## Revoke/ Suspend

An Officer can revoke CA certificates in his/her own group manually, if necessary, using this UI.

Revocations of CA certificates may become necessary if keys have been compromised.

<figure><img src="/files/j3XjHtjqGTk790TTxx28" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left. The following search criteria are available:

* Serial Number – the serial number of the CA certificate
* Common Name – the common name (CN) of the CA certificate
* Issuer Name – the CN of the issuer (= CA) of the CA certificate

To search for certificate information, you can enter search criteria in the appropriate fields. For all search criteria except the Issuer Name, you can enter the desired search value in the right field. However, when you search using the Issuer Name, the right field changes to a dropdown box. From this dropdown, you can select the name of any existing Certificate Authority (CA).

The image below illustrates an example of how to filter search results using a specific Issuer Name.

<figure><img src="/files/Y9giYeyPq3hFi7b3Ahuo" alt=""><figcaption></figcaption></figure>

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAoAC4DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19EMhcl2HzEcGneT/ALb/AJ0Q/wAf+8aS6uobK2ee5kWOJBlmY9KAF8n/AG3/ADo8n/bf865KPxxdardOmg6b58MX+snmbao96bJ44u9MkR9W09PsjnAntpN4z70Adf5P+2/51DdboUBR3yT3NOsNQttTtEubSVZYnHBFJf8A+rX60ASw/wAf+8a4b4oxXz2ds8ZY2Sn96F/vdifau5h6P/vGnTQxzxNFMiujDDKwyDSauNOx5bpeuXOjeD4ZNMto50cslyCMlG7E4rL0pZU8O6tLdAraSgbA3QyZ4213kngSK1uZLjRr2WyeTrHjdGfwNIPAv22SN9a1CW7EZyIlARPyFN63FsYnwtivxLcSDIsCMYPQv7V39/8A6tfrUltaw2dukFvGscSDCqo4FR3/APq1+tNu4krD45UQuGYA7j1p/wBoi/56L+dFFIYfaIv+ei/nR9oi/wCei/nRRQAfaIv+ei/nVa8kR41CsCc9qKKAP//Z)to view the CA certificate details:

<figure><img src="/files/sH168qqw2JxT7Sple7qH" alt=""><figcaption></figcaption></figure>

**Revoke Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAiACkDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19UMjOS7jDY4NO8n/AKaP+dEPWT/eNct4w8VXelN9m0y3LTLhnkZflUHoPxpXCx1Pk/8ATR/zo8n/AKaP+dc1b+INY1PT4pdN05fPQ7bhJm27T7eopIde1u31iztNUsYIo7liAyPu6U7a2C+lzpvJ/wCmj/nR5P8A00f86looAih6yf7xrD8bQyS+HZfIheWQOh2ouWIBrch6yf7xqWgaOUt/GSxxxodI1AcAMfJNYev6zq0XiCw87T98iOWtigOJARwD6EV6PTWjRmVmRSy9CRyKOtxdLFfTmu3sYmv1RbgjLqnQH0q1RRQCMudmW4cBiOexpnmP/eb86KKADzH/ALzfnR5j/wB5vzoooAPMf+8350eY/wDeb86KKAP/2Q==)in order to start the revocation process for the selected CA certificate.

<figure><img src="/files/gVdFPOLyDK1OzToF3Sd9" alt=""><figcaption></figcaption></figure>

Select one of the following revocation reasons from the dropdown list:

<figure><img src="/files/r30rVYwgwleyiMP8RaGY" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Note: CA certificates cannot be suspended.
{% endhint %}

Provide an explanation for the revocation/suspension of the certificate in the Remarks section.

Select "Confirm" to proceed. You'll then need to authenticate the revocation by using your Officer token and pressing "Authenticate."

{% hint style="info" %}
Warning: Revocations are permanent! Revoked CA certificates cannot be recovered by any means.
{% endhint %}

Click on "Revoke" to proceed with the revocation process.

## Reinstate

<figure><img src="/files/34wpCMdUOOiptZ4rrNwQ" alt=""><figcaption></figcaption></figure>

## Search

The user can search for CA certificates in his/her own group. The user cannot inspect the certificates of other groups.

<figure><img src="/files/NHb2s1HmXrnXMO3JOlmn" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left.

The following search criteria are available:

* Serial Number – the serial number of the CA certificate
* Common Name – the common name (CN) of the CA certificate
* Issuer Name – the CN of the issuer (= CA) of the CA certificate
* Status – the state of the certificate

“Search for” changes according to “Search by” criteria.

For sample, inserting the “Search by” Status filter, click "Search" to filter for all matching user certificates.

The following image shows an example of a CA-specific filter:

<figure><img src="/files/t0YVfll2cuig3NzT9WRO" alt=""><figcaption></figcaption></figure>

User can view and download the certificates in the available formats.

## Sign CSR

An Officer can use the following UI in order to sign CA CSR from External CAs using existing CAs and certificate profiles from the emCA Application.

<figure><img src="/files/lCQQdNdwymuz27LUXtl2" alt=""><figcaption></figcaption></figure>

**Steps to Generate a Certificate**

1. Select the configuration type, either Upload or Text Area.
2. Click "Choose file" to select the CSR for signing.
3. Pick the desired certificate profile from the dropdown list.
4. Make sure that the certificate profile is of type CA, not Root.
5. Upon selecting a certificate profile, the Certifying Authority field will be filled with the correct CA.

<figure><img src="/files/LuByUzj9MknpjqczzCOR" alt=""><figcaption></figcaption></figure>

Click "View" next to the certificate profile to view it read-only.

Click on "View" next to the issuing CA in order to inspect the CA’s certificate.

To move on to the next stage, simply click on the "Proceed" button.

The following summary of the certificate request will be displayed:

<figure><img src="/files/Qpw2xlMC90mGlQ8ZGfSm" alt=""><figcaption></figcaption></figure>

The CSR Details section displays the data that can be obtained from the CSR (Certificate Signing Request) that has been submitted.

To download the CSR once again, please click on the !\[A blue arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAvACkDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2akpaZL/qXx/dNAFaXVLSF9jzKG+tWY5ElQMjAg9xXhviO5uV1uQCZwN/rXq3g53fRYy7Fjjqa7a+EVKmp33OSjifaTcbG/RRRXEdYlcnr/jNNIuGgdOSMZxXUyTRxffcL9a57xJoWn67aNhkEwHBBrfD8nP+8WhjW5uX3HqeRareC+1Bpx0LZrtfDvjdLK1jtCuTwK4vUNJudOvTbOhJJwpA613Hg7whBBtvNS2huqqTXtYn2XslzaroeTh/a+0909Cs5/tNqkuMbhmp6rxT24AjidcDoAanyPWvn2tT209Dzz4j39zaSKIJSgx2rgk13UVYMLl+K9l17w1DrZBlIGKxB8N7TH3hXrYbFUYU1GS1PNr4erKbcTlbXxpb+QDe2olmUcMRVGbVNY1Z2mtGcQg8Adq7j/hW9p/eFWrbwX9jjMdvMFQ9RVfWsPHWK1J+r13pI4TRLrVrfXrdLuRwrHoe9eoec/8AeNUIfCI+2x3E8gcp0re+xpXLiK8KjTR00KM4Jpn/2Q==)icon provided.

To make changes to the loaded CSR information, simply click 'Edit'.

If the CSR is missing any required data (indicated by \*), fill it in manually.

The Other Details section displays the key size generated by the CSR and the certificate options selected.

You will need to authenticate the generation of the certificate. Use your Officer token to authenticate and press "Authenticate" to proceed.

To finish generating the certificate, simply click on the "Sign CSR" button.

The following UI will be shown upon completion:

<figure><img src="/files/4UQu2UUb9VSG4IxA4zlQ" alt=""><figcaption></figcaption></figure>

To get the latest CA certificate, all you need to do is click on the "Download Certificate" button.

## Import PKCS12

An Officer can import existing PKCS12 keystores into the emCA Application HSM using the following UI.

The PKCS12 keystore must include a CA certificate; user certificates are ignored.

<figure><img src="/files/k6HA1Xd52FVg7dT282lv" alt=""><figcaption></figcaption></figure>

To choose the PKCS12 keystore from your system, simply click on the "Choose file" button.

Please enter the password for the PKCS12 keystore in the "Enter Password" field.

To select the key profile, you must choose an option from the drop-down menu.

To continue, please click on the "Proceed" button.

You will need to authenticate the upload using your Officer token. Press "Authenticate" to proceed.

Click on "Import" to upload the PKCS12 to the EmCA Application HSM.


# Manage User Certificate

Officer can create and manage User Certificates in this section

## **Revoke/Suspend**

An Officer can revoke or suspend user certificates of his/her group manually, if necessary, using this UI.

Revocations or suspensions of certificates may become necessary if keys have been compromised or access must be suspended temporarily for validation purposes.

<figure><img src="/files/KRmbILoUdyPsgk3BdMzU" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left.

The following search criteria are available:

* Serial Number – the serial number of the user certificate.
* Common Name – the common name (CN) of the user certificate.
* Issuer Name – the CN of the issuer (= CA) of the user certificate.
* Subscriber Id – the subscriber ID used to create the user certificate.

<figure><img src="/files/YExGRZTLP7vnhJW0pzA0" alt=""><figcaption></figcaption></figure>

For all search criteria except Issuer Name, the search value can be inserted in the right field.

For Issuer Name, the right field changes to a dropdown box from which you can select any existing CA name.

The following image displays and example for filtering for a specific issuer:

<figure><img src="/files/OSgKtQoPbiHWa2xpPuBa" alt=""><figcaption></figcaption></figure>

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAbAB8DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2FEDLkk5ye5ocRRrudto9WbFCsVhYqNxGSB615dDrP9p6pqF74hinmjs+Es06R84yV74/rSuB6gnlSjMbhx/svmm3ChIWZSwP1NeRJrF3ZW9rqtkPs1w87R+WgwlwvYlfXtkV6yssk+lxyyxmKR0VmQ/wk44p2EWIvufif51l6j4ZsNQuxd7XguwMedC21j9ex/GrBnkRmCtgAntSfaZf7/6CgZVsvClha3aXcvmXVygwkk7Z2fQdBWrdf8e7fh/Oqv2mX+/+gprzyOhDNkfSgD//2Q==)to view the user certificate details:

<figure><img src="/files/Y5utpadDgw4eilKPNzbP" alt=""><figcaption></figcaption></figure>

**Revoke the certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAhACcDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19EMhcl3GGI4NO8n/AKaP+dEP8f8AvGuQ8WeJtVsr2O30q2IVHUPI44cnooovrYDr/J/6aP8AnR5P/TR/zrnRqXiDUreK4020giQjEiXBIZWHX8Kfo2ras+uy6dq0durLEJFMRz3o62DzN/yf+mj/AJ0VLRQBFD/H/vGsHxlbXc9hatZWz3EkNwshROpAreiIG/JH3jT9y+o/OgDnIvEOqzSCI6DdQh/l8w4IQ+prn4pfEp8YPF9njFyYwjXG393sznd9a9D3L6j86Ny56ijrcOlgQEIoY5bHJ9aKXcvqPzooAy5/+Ph/rTKKKACiiigAooooA//Z)to open the following revocation dialog:

<figure><img src="/files/yhwhVNG1kcYfGCAenMUd" alt=""><figcaption></figcaption></figure>

Select one of the following revocation reasons from the dropdown list.

{% hint style="info" %}
Note:&#x20;

Suspension (=Certificate hold) is a special revocation reason.

Certificates which are suspended can be reinstated at a later point in time.

Suspended certificates will be automatically revoked after 15 days of suspension.
{% endhint %}

Please add a comment in the "Remarks" section explaining the reason for revoking or suspending the certificate.

Click on "Confirm" to continue.

You will need to authenticate the revocation using your Officer token and proceed by pressing the Authenticate button.

Click on "Revoke" to proceed with the revocation process.

## **Reinstate**

An officer can manually reinstate suspended user certificates for their group using this UI. Reinstated certificates will be removed from the next corresponding CRL.

<figure><img src="/files/gUzmQKPTNXmIiu3J3ovD" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left. The following search criteria are available:

* Serial Number – the serial number of the user certificate.
* Common Name – the common name (CN) of the user certificate.
* Issuer Name – the CN of the issuer (= CA) of the user certificate.
* Subscriber Id – the subscriber ID used to create the user certificate.

<figure><img src="/files/Dmi1BbcWsJPgC180mCGS" alt=""><figcaption></figcaption></figure>

For all search criteria, except Issuer Name, enter the search value in the right field. However, when searching for Issuer Name, the right field becomes a dropdown box containing all existing CA names.

The following image displays an example for filtering for a specific issuer:

<figure><img src="/files/laXGhFtQH0NBEreL6L5Z" alt=""><figcaption></figcaption></figure>

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAbAB8DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2FEDLkk5ye5ocRRrudto9WbFCsVhYqNxGSB615dDrP9p6pqF74hinmjs+Es06R84yV74/rSuB6gnlSjMbhx/svmm3ChIWZSwP1NeRJrF3ZW9rqtkv2a4edo/LjGEuF7Er69sivWVlefS45ZYzFI6KzIf4SccU7CLEX3PxP86y9R8M2GoXYu9rwXYGPOhbax+vY/jVgzyIzBWwAT2pPtMv9/8AQUDKtl4UsLW7S7l8y6uYxhJJ2zs+g6CtW6/492/D+dVftMv9/wDQU155HQhmyPpQB//Z)to view the user certificate details:

<figure><img src="/files/gh5tJWkCLmzcTGlzFvC7" alt=""><figcaption></figcaption></figure>

**Reinstate the certificate**

Click on !\[A black arrow pointing to the left

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAkACYDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD16JGkiVjK+SKf5J/56vRb/wDHun0ry+PxLqcWs6jp0F4kZlnOJrh/liX0FHWw7aXPUPJP/PV6PJP/AD1euIi8M62sAvtP8SyXT43Ip5RjW74V8QSaxBLBex+VfWzbJk9T6igk07kvAqlZG5Peilv/APVp9aKBk1v/AMe6fSsa48F6HczPLNZIzyHLEk8mtm2/490+lZ2v6Tc6rZqlneyWkyNuR16Z96TGi9ZWVvp1oltaxiOGMYVR2rlNDZbrx/qdxanMCIEcjoWpJNI8XXcf2SbU4Yohw0yD5mFdDoWh22g2It7fLMTl5G6ufWqW9yXtYsX/APq0+tFF/wD6tPrRSGTW3/Hun0qWiigAooooAqX/APq0+tFFFAH/2Q==)to open the following reinstation dialog:

<figure><img src="/files/VSQuGQy0Rdr3GcaKHCnb" alt=""><figcaption></figcaption></figure>

Please provide an explanation as to why the certificate was reinstated into the Remarks section.

Click "Confirm", authenticate with the Officer token, then press "Authenticate"..

To proceed with the reinstatement process, please click on the "Reinstate" button.

## Search

The user can search for their own group's certificates only. Certificates of other groups are not accessible. User certificates refer to non-CA and non-role owner certificates within the EmCA Application database.

<figure><img src="/files/hvJm4wCDgQJLMHkILARF" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left. The following search criteria are available:

* Serial Number – the serial number of the user certificate.
* Common Name – the common name (CN) of the user certificate.
* Issuer Name – the CN of the issuer (= CA) of the user certificate
* Status – the state of the certificate
* Subscriber Id – the subscriber ID used to create the user certificate

<figure><img src="/files/v6rYhMRa7Liblx7dzcal" alt=""><figcaption></figcaption></figure>

For all search criteria except Issuer Name and Status, insert the search value in the right field. For Issuer Name, select an existing CA name from a dropdown box.

For Status, the right field changes to the following dropdown box:

<figure><img src="/files/wDsxVI9g6ue7156pDJOS" alt=""><figcaption></figcaption></figure>

After inserting the search value or selecting the status filter, click Search to filter for all matching user certificates.

The following image shows an example of a CA-specific filter:

<figure><img src="/files/TBewfQ9JlAqmIf2Iajik" alt=""><figcaption></figcaption></figure>

Each entry in the table “Certificate Details” represents one user certificate.

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAmAC0DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19E8wsS7/AHiODT/JH99/++qSHo/+8ag1TVbXR7J7q9kCRr+ZPoKG7AWPJH99/wDvqjyR/ff/AL6rjbXxZrOuCW50uzgt9PizumuCST9AKiPjm+00xzajDbXVhKdq3Fo2cH3B7+1AHb+SP77/APfVVrotCVCO/PvT9P1G21SzS6s5BJE44Ipl/wDeT6GgCxD0f/eNcN8TdIvruGC8t98sEIIeNf4f9qu5h6P/ALxqQgMCCAQeoNJq407HlNpqept4Wgj0FlcKhiuoAoLj/aA96zTbS6P4Vuor8eXLdyL5MB+8MdWI7V6XeeDNJup2njie2nbrJbuUJ/KlsfB+k2U63Bha4nXpLOxc/rT3FsY3w20i+sNPmuLotHFcEGOFu3+1+NdTf/eT6GrgGBgdKp3/AN5PoabdxJWHfalhd1KkncelL9vT+61FFIYfb0/utR9vT+61FFAB9vT+61V7mZZypUEY9aKKAP/Z)to view the user certificate details:

<figure><img src="/files/9IiwXEbuBKaHmeMt4x8K" alt=""><figcaption></figcaption></figure>

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAuADMDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19VaR3/eMMHAAp3kn/nq/50Q/ek/3qloAi8k/89X/ADo8k/8APV/zqprs8ltot1LC22RYyQfSvOfA2ualdeJUhuLuWWNwcqxyKI6uwPRXPUfJP/PV/wA6PJP/AD1f86looAzpZpY5WUSHANFMuP8Aj4f60UAX4fvSf71S1FD96T/erI8VeIT4c05blYPNLNtxnFJuwJXOb8a+JtV02SaxksYvsk67UmycmuF0XV5dD1JLyCJZJFyArdDmuquvH9prUf2PVNO/0eQ4Lg8p7iqUVnpPhqQ3888eotuzbQof1anHR3Y5aqyPRvDl/qGpaYtzqVsls78qik9PWtevObb4oyTXMUX9n4DsF69K9EjbfGrYxuGab7krsZtx/wAfD/Wii4/4+H+tFIZfh+9J/vVl+JfDqeI7FbaSdoQG3blGaum5EEsilSfmpft6/wBw0mrgnY4n/hVEH/QSm/74FPg+FkNtOkseoyblORlARXZ/b1/uGj7ev9w0wOak8BGdo/NvztSTzMLEASa66NNkar12jFVvt6/3DR9vX+4aA8ytcf8AHw/1opsreZIzAYzRQB//2Q==)to download the user certificate as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/fxCokHF8dxy5cyvRaCxQ" alt=""><figcaption></figcaption></figure>

Select the export format of your choice and click "Download" to start the download of the user certificate.

The user certificate will be downloaded to the standard download location of your OS.

## Sign CSR

Officers can generate user certificates based on a Certificate Signing Request (CSR) manually using the following UI.

User certificates are any non-CA and non-role owner certificates in the emCA Application database.

The result of this UI is always just the public key for a new user.

The private key can be stored independently from the PKI.

<figure><img src="/files/zPklwvWKSrZ2umpuTE45" alt=""><figcaption></figcaption></figure>

To begin, choose the configuration type as "Upload". Next, click on "Choose file" to select the CSR.

Once you have done that, select a certificate profile from the dropdown list. This will automatically fill in the correct issuing CA in the "Certifying Authority" field.

<figure><img src="/files/vd6wVfFtdiAEXDjDRXVl" alt=""><figcaption></figcaption></figure>

Click on "View" next to the chosen certificate profile to inspect the profile in a read-only view.

Click on "View" next to the issuing CA in order to inspect the CA’s certificate.

Click "Proceed" to continue to the next stage. The summary of the certificate request will be displayed.

<figure><img src="/files/M7JOLwRimdAVLVehRnu6" alt=""><figcaption></figcaption></figure>

The "CSR Details" section displays information that can be obtained from the given CSR.

Click on !\[A blue arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAmACEDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2aqt/fwadbma5cKg7mrOcVynxAkjfw86h1Jz0BrSjDnmoszqz5IORsaX4hsdXdktZQzDtWnXlHwxZE1GUswX6mvVlZXGVII9q1xVFUanKiMPVdWHMx1FFFcxuMkXfGyg4yMZryHxppWqabdO0srS2shyD6V0HjnxTfaNqKxWpAUiubi8cz3hMGrIsluwweORXq4OhVhaotUzzcVVpz9x6MxtEt767vVh08sHY8kdq9s0Kwm07TkhuJfMk6kmvMU8Q2mljyvDcDNK/JLDmp9P8Y64dTt47pCscj4JIrXFU6lfZWX4meGnCjvqz1jNFZn22T1oryfZSPS9rEp654StNcuBLOSGFZn/CttO/vH8qKK0hiKkVZSIlRpyd2iW3+H9naSiWCQq474q0PCETTRSTTFxG24DHeiih16j3YlRgtkbX2KOiiisueXc15Uf/2Q==)in order to download the CSR again.

Click on "Edit" in order to change the information loaded from the CSR.

If not all required data (marked by \*) is loaded from the CSR, you will need to fill it in manually.

"Other Details" shows the key size that was determined from the CSR as well as the chosen options for the certificate.

You will need to authenticate the generation of the certificate. Use your Officer token to authenticate and press "Authenticate" to proceed.

Click "Sign CSR" to complete certificate generation. After successful signing, the following message will appear.

<figure><img src="/files/zwYcVKCIojXO3S7I4NAH" alt=""><figcaption></figcaption></figure>

Click "Download Certificate" in order to retrieve the new user certificate.

## Bulk Sign CSR

<figure><img src="/files/Qx69c4AWTnFQlKRSlIkV" alt=""><figcaption></figcaption></figure>

## **Manually Authorize Certificate**

If a certificate profile has "Manual Authorization Enabled," an officer can review and approve or reject any certificate requests using this UI.

<figure><img src="/files/5bnmyV6q4autFzAvaXpM" alt=""><figcaption></figcaption></figure>

Click "Export to Excel" to export the entire table to an XLSX file. The file will be downloaded to the standard download location of your OS.

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAkACoDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BE37iWb7xHBp3kj+8/8A31RD0b/eNZHiTxPaeG7QPPmSd/8AVxL1b/61DdgNfyR/ef8A76o8kf3n/wC+q4ka14gk0k6xe3Vvp1k/3EEPmMAehPtTbXx1c6ZexW+uCGa2nG6K8txhWB74o8gO48kf3n/76qg8siuwDtgHHWtCORJolkjYMjDKkdCKzZP9a/1NAGjD0b/eNcD8RPC93eTrqlkrTbU2yRDkgDuBXfQ9G/3jUlJoaZ5FfyXev2kYsNQRICqrPZzSCPy3HfnqKrXGnyaobDRtKzdtbA+bMo+RWPUZ9BXq11oOl3zh7mwt5GHcoKtW9pBaR7LeGOJfRFApiK2h6b/ZGj29l5hkMS4LHuahk/1r/U1q1lSf61/qabd9QSsTNcvFI6rjG49RSfbZf9n8qKKQB9tl/wBn8qPtsv8As/lRRQAfbZfRfyqBjuYk9Sc0UUAf/9k=)to view the user certificate details:

<figure><img src="/files/9IZYsr7DWmZHvrAfbBA8" alt=""><figcaption></figcaption></figure>

**Download Certificate**

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAhACQDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BE3gks3U96d5Sj+Jv++qIvun/eP86oa3rdlolqJL+Ro0kyqkIW5x7UmwQtnqum6hcSW9perNLH99Fc5FXvKH95v++q8h8G61Y6N4hubu9lMcMisFIUnJJ44FevQyrPCkiZ2uAwyMHFPomHWxVuWaOUKjsBj1opL3/Xj/AHaKALcX3T/vGvP/ABB49gNzeaXd6UJ4FcxtmTr7j0NegREbT/vH+dZVx4S0O6uHnn06B5ZDuZjnJNK2oHmlg2jaRere2wfVZCd0FsBgxD1f1Ir0Hwt4ofxDJcxy2TWrQY4Y8nNWE8H6DE26PToUbplSQf51dsdJsdNeR7OBYmkxvYEktjp1qriEvf8AXj/doovP9cP92ikMim/1z/7xqOiigApaKKAENFFFAH//2Q==)to download the user certificate as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/17sbRIfv8Q1TclFxd9bw" alt=""><figcaption></figcaption></figure>

Select your desired "export format" and click Download to obtain your user certificate. The certificate will be automatically saved to the standard download location of your operating system.

**Approve**

Click on !\[A checklist in a box

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAApAC0DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD12JZJIlYysM0/yX/57NRa/wDHun0rN1nxLZ6KwS48zzXHyKFzuPpSuFjS8l/+erUeS/8Az2asG78Uz6dpUF3d6fIGmPEackD3rP8A+FiL/wBAy5/75NMDrvJf/ns1V7mSWBgBITkd6g0HWxrloZhBJDg42uMVNqH+sX6UWC5Ztf8Aj3T6Vi+JNZtNMeEXVi1xIx/ckLn5q2rX/j3T6VieJ9VvtOktBZaat4JHw5IzsHrSe6Givf8AiO50nSILnUtOaaWZv9XGudg96y/+Fhwf9AK5/wC+P/rVveIdW1HT7KCSw037XI/3kx92sD/hK/EX/QtfpR1YuiOm8Oa0ut2TTpZyWoBxtcYzVnUP9Yv0qr4b1G91KyaTULD7HIDgJ61a1D/WL9KpiRZtf+PdPpUtRWv/AB7p9KmpDCiiigAqhqH+sX6VfqhqH+sX6UAf/9k=)icon to open the following approval dialog:

<figure><img src="/files/DTBqDo8TzIZMmxI3eUfB" alt=""><figcaption></figcaption></figure>

Before approval, click "Edit" to correct CSR details if needed.

To validate the CSR, click on the "Approve" button. If you want to reject the CSR instead, click on the "Reject" button.

After approving, you will need to authenticate the action using your Officer token, then proceed by pressing "Authenticate".

To finish the approval action, simply click on the "Confirm" button.

## **STC Requests**

If a certificate request with CT Logs Enabled and Manual Process Type is created, an Officer can import a response, view certificate, and download certificate using this UI.

{% hint style="info" %}
Note: Signing Certificate Timestamps (SCT) is only relevant for public CAs with abide the Certificate Transparency rule defined in RFC 6962.
{% endhint %}

<figure><img src="/files/ynzOTzYuMlJ2geQFWZRn" alt=""><figcaption></figcaption></figure>

Click "Export to Excel" to download the entire table as an XLSX file.

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAfACQDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BEDgkls5PeneUvq3/fRoi+6f94/zrhNd8W3d/r40XSZvs0asVmucZYY64+lHkB3flL6t/wB9Gjyl9W/76Nea3d7HFqy6fpmr3sk3l74roXO9WfGdrL0roPBXi99eElneqFvYRkso4cdM+xoWobHQXLNHKArMBj1opL3/AFw/3aKALcX3T/vH+dctr/gw3epLqukypb3ynLK4+ST610qXEablZsEMe1O+1Rf3v0NAHn8Hg/UIrmR7PS4LS4cEee9xvRM9Si4z+ddR4Y8K23hu2YK3nXMn+smI6+w9BWx9qi/vfoaPtUX979DQBWvf9cP92im3UiySgqcjFFAH/9k=)to view the user certificate details:

<figure><img src="/files/2A7kZ2WgHpoajKCLUFMk" alt=""><figcaption></figcaption></figure>

**Download Certificate**

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAkACgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BE37iWb7xHBp3kj+8/8A31RD0b/eNJcXMNrEZbiVIox1Z2wB+NAFeS8sorkW8l4izHpGZMMfwqz5I/vP/wB9V5D4iuYJvHwnjmR4vNQ+YrZXHHevWrW9tr1SbW4imC8ExsGx+VC1jcHo7Cyx7ImYO+QP71FPn/1D/SigAh6N/vGue8QeJNAiM2las+7cvzpsJ610MPRv941yHiD4fDXdXkvv7QaHeANgjBxikxo4mTwss1wJtOuo30lssbljjylHUMPX+ddp4b8Q+F9Kgh07TZzukYAsUOXb1NUR8K2CFBrEoQnJUR8H6jNX4vh6kd1BKLiFDFIJP3cGCcds5ql2Jfc7Cf8A1D/Siif/AFD/AEopDKj3TxSuq4xuPUUn26X0X8qKKAD7dL6L+VH26X0X8qKKAEa7kdSp24PHSiiigD//2Q==)to download the user certificate as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/TRQGkSdGAaP79S7YwHdY" alt=""><figcaption></figcaption></figure>

Select your preferred export format and click 'Download' to obtain your user certificate. The certificate will be saved to the default download location on your OS.


# Manage Key Stores

The manage keystore feature in emCA allows you to check the status of connected HSMs when creating key profiles, view HSM device information, and see where the HSM is used while creating key profiles. This information can be helpful for troubleshooting HSM-related issues and for ensuring that you are using the correct HSM for your needs.

An officer can inspect the application's connections to various HSMs, as well as the details of the key pairs available in each HSM.

<figure><img src="/files/Ys2f2qEGk7vh3lC21pyY" alt=""><figcaption></figcaption></figure>

Click on !\[A black circle with white text

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAfACEDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19E37iXb7xHBpXRI1LPKyqOpLYApYej/7xryvx5r91f66+nRSOttCwQqpxvJ60r62Gu56fDLb3BIguhIR12SA4/KpTFgH536eteLajH/wi+qwnSprqJwgdhKNpz6Y7ivXdD1IavolveYwZY8ke/eq3VyepH58v/PRvzoplFIZpw9G/wB415h478NXVrrTanBC81tKwZ9g5U16WtxHGXVic7j2pTdwkYJJ/ClbW4/I8g1J7rxjqluLLT5o5FQRMWJIwO5Ner6Npy6To1vZKc+UmCfU96mSe2iBEahc8nauKcbuLB5P5VV9LE9TPooopDP/2Q==)to display the details for the corresponding HSM. The following view will open:

<figure><img src="/files/5x3EX7MEVKEhDoD2nU33" alt=""><figcaption></figcaption></figure>

In order to facilitate the identification of the HSM, the top section displays basic information.

In the lower section, all keys located in the HSM Slot described by the corresponding PKCS11 configuration are listed.

If there are more keys that cannot fit on one page, use the navigation at the bottom of the table to switch pages.

{% hint style="info" %}
Note: Unused keys can be identified by their Alias Name and CN being equal.
{% endhint %}

**Download**

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAzADgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD14B5JH/eMADgAU7yX/wCerUQ/6yX/AHqmoAh8l/8Anq1Hkv8A89WqWvK9c8b6xa69NDBMEijfATFK+qQW0uen+S//AD1ajyX/AOerUzTp2utOt5n+9IgY1ZqmrOwk7q5XlR44mYStkCin3P8Ax7v9KKQxIf8AWS/71TVDD/rJf96nTzxW0TSzOEReSxPSgDI1zxXp/h+WOO+80GQZUqmRXj+r3cV9rE9zDny3fcM9cV6rrV14f12xa3ubuHn7r55U15nfeGr601NLOOMzCU/upF5Vh65qVfmKfwnonh7xrpd0lpp0JmNxsC42cZA9a62uK8MWOi+GYj9pu4Gvz/rGJ+77Cuts9QtdQQtazJKBwdp6VpLUzWhJc/8AHu/0oouf+Pd/pRUlCQ/6yX/erH8ZRvL4aulRGdivRRk1sQ/6yX/eqXrSkrqw07O58+Lp13tH+hXHT/nma2bTWvEFjYfZIYJjHghWaIllB9DXtO1fQflS7V9B+VMR4hBoSXEcclzNcJLISZAYSStdr8NLWS2t7tXjkVd/yl1IzXc7V/uj8qUADoKadhNXI7n/AI93+lFFz/x7v9KKQylcSvHO4RiBmmfaJf75oooAPtEv980faJf75oooAPtEv980faJf75oooAQzyMMM5INFFFAH/9k=)to download the certificate assigned to the key as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/jD6lClgw9byE0jqjYzNB" alt=""><figcaption></figcaption></figure>

Select the desired export format and click "Download" to save the user certificate to your OS's default download location.


# Configure Mail Server

## Mail Settings

An Administrator can view and edit the Email bodies of the different E-Mail Notification Service messages using the following dialog:

<figure><img src="/files/xIFtlsEOCx3GdiOLEbt9" alt=""><figcaption></figcaption></figure>

Click on  to open the editor dialog for the respective mail type.The following is an example from Mail Type Officer:

<figure><img src="/files/ItcnPRO7Y3VFKH3596uL" alt=""><figcaption></figcaption></figure>

Click into the text area to start editing.

Click on Proceed to continue.

You will be prompted to authenticate the registration:

<figure><img src="/files/O6vAGR1orKRogJn6kFnd" alt=""><figcaption></figcaption></figure>

Authenticate using your Administrator token and proceed by pressing Authenticate.

Click Sign and Save to save the changes.


# Reports

**The auditor provides detailed reports of application logs, showing all actions performed by users in a table format.**

**Application Logs**

All user actions are logged in a report table, with the latest appearing first.

<figure><img src="/files/UrTTNcUUldUg4oQvH5F3" alt=""><figcaption></figcaption></figure>

&#x20;The log events can be filtered by the following criteria:

<figure><img src="/files/yZ2gpmC83Ez3PoC8TivI" alt=""><figcaption></figcaption></figure>

Click "Search" to apply the filter of your choice. Click "Reset" to remove the filter again.

Click "Export to Excel" to export the entire Application Log to an XLSX file. The file will be downloaded to the standard download location of your OS.

Click to <img src="/files/dLbCqJuwSeT7C7MGtwPp" alt="" data-size="line">view logs for a detailed report.

<figure><img src="/files/4Qt4X5BQBz2INFAl1XCf" alt="" width="375"><figcaption></figcaption></figure>

Click on the<img src="/files/zIgD3v91IefQnYjj3vkr" alt="" data-size="line"> button to view the signed data. A pop-up window will appear displaying the signed data as shown below.

<figure><img src="/files/X9RO0fUM2bDXbqOehhxg" alt="" width="328"><figcaption></figcaption></figure>

Click to <img src="/files/5ZxgKYVHaDDHr4casw04" alt="" data-size="line">trigger signature verification check on the application log entry.

If tempered, then it will give the failure message given below

<figure><img src="/files/OmrH8mtKG42GuklgvEWB" alt="" width="344"><figcaption></figcaption></figure>

If the data is correct, then give the success message given below:

<figure><img src="/files/iTiYGcv12pTK4uiNyPmp" alt="" width="344"><figcaption></figcaption></figure>

&#x20;


# Recover User key Pair

Enabling KRS (Key Recovery Service) while creating a certificate profile allows users to recover the keypair for the certificates. This is a useful feature for organizations that need to be able to recover the keypair for their certificates in the event of a disaster or other incident.

**Recover**

When Is KRS Enabled is selected in the certificate profile, officers can recover keys using two different modes for user certificates.

* PFX with New Password
* PFX with Old Password.

<figure><img src="/files/HH7Dza6g9VJ122gcRwO8" alt=""><figcaption></figcaption></figure>

Select a search criteria from the dropdown box on the left. The following search criteria are available:

* Serial Number                    – the serial number of the user certificate
* Common Name                  – the common name (CN) of the user certificate
* Issuer Name                       – the CN of the issuer (= CA) of the user certificate
* Status                                 – the state of the certificate
* Subscriber Id                      – the subscriber ID used to create the user certificate

<figure><img src="/files/iAdDo4J3qZffElDzHKX6" alt=""><figcaption></figcaption></figure>

For all search criteria, except Issuer Name and Status, enter the search value in the right field. For Issuer Name, a dropdown box with existing CA names is provided.

For Status, the right field changes to the following dropdown box:

<figure><img src="/files/N05E0uNBUsVrGcxmzZCu" alt=""><figcaption></figcaption></figure>

After inserting the search value or selecting the status filter, click Search to filter for all matching user certificates.

Here's an example of a filter that specifically applies to the "Active" status:

<figure><img src="/files/I48PEUy2B6UCFRI4CcDM" alt=""><figcaption></figcaption></figure>

&#x20;**View**

Click on <img src="/files/MGUxSMmcwAXY6UKAob49" alt="" data-size="line"> to view the user certificate details:

&#x20;

<figure><img src="/files/vIIaN1mg1nXrKC6mIDGq" alt="" width="305"><figcaption></figcaption></figure>

**Download**

&#x20;Click on  <img src="/files/p0B4u0fXIOukVCzhFohP" alt="" data-size="line">to download the user certificate as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/hXocYHViyHiYEn7tDyy3" alt="" width="257"><figcaption></figcaption></figure>

Select the export format of your choice and click Download to start the download of the user certificate. The user certificate will be downloaded to the standard download location of your OS.

**Recover**

Click on  <img src="/files/vefewAheRIFodYkWWfR1" alt="" data-size="line"> icon to start the recovery dialog:

<figure><img src="/files/8sEkuRdVNHSD8pOe1U1M" alt="" width="356"><figcaption></figcaption></figure>

By default, "Keystore with new password" will be selected and you will be prompted to insert a new password.

Enter the new user certificate password in the New Password field. You can view the password policy by hovering over it<img src="/files/Yn5GTm62lAPipY5lXtQL" alt="" data-size="line">.

While "Keystore with old password" will not prompt for a new password but will generate the new user certificate with the old password again.

Press "Authenticate" after confirming and using your Officer token.

To generate a new user certificate key, simply click on the "Recover key" button.

###


# Advanced Capabilities

In addition to standard PKI operations, emCA supports the creation and issuance of specialized certificate types required in regulated and sector-specific infrastructures.&#x20;

These include:

* **EVM certificates** for secure payment ecosystems,&#x20;
* **ePassport certificates** for identity and travel document security, and&#x20;
* **CV2X certificates** for intelligent transport and connected vehicle communication.

| Certificate Type           | Purpose                                                                    | Standards / References                          | Sector / Use Case                                 |
| -------------------------- | -------------------------------------------------------------------------- | ----------------------------------------------- | ------------------------------------------------- |
| **EVM Certificates**       | Secure transactions between EMV chip cards and terminals                   | EMVCo standards                                 | Banking, Payments, POS devices                    |
| **ePassport Certificates** | Secure storage and authentication of identity/biometric data in ePassports | ICAO Doc 9303, EU EAC (BSI TR-03110, TR-03139)  | Government, Border Control, Travel Security       |
| **CV2X Certificates**      | Authenticate V2X messages between vehicles and roadside units              | EU C-ITS Certificate Policy, ETSI ITS standards | Intelligent Transport, Automotive, Traffic Safety |


# Managing EMV Certificates


# Manage EMV Certificate

An officer has the capability to manage EMV certificates within their designated group and generate EMV key pairs through the following user interface. To create an EMV Scheme certificate, the user must follow these two steps:

1. Generate EMV Key Pair
2. Generate a certificate using the generated key pair.

<figure><img src="/files/YHN7noKFp5hYrg1WUKuA" alt=""><figcaption></figcaption></figure>

## Manage EMV Keypair

**Generate EMV Key Pair**

On the "Manage EMV Key Pairs" page, when you click on the "Generate EMV Key Pair" button, the following steps will be presented to you:

\
1\. Enter the number of keys needed.\
2\. Public Key Exponent will be a prefixed component.\
3\. Select the key profile from the dropdown menu.\
4\. Choose the Signature Algorithm from the dropdown list.

<figure><img src="/files/NrUMlZKlnjThVCFcv3rr" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/KPbMwjTImv4TOguYgOMD" alt="" width="323"><figcaption></figcaption></figure>

5. Select the Key Algorithm & Size for the respective signature algorithm from the dropdown list.

&#x20;

<figure><img src="/files/kwrMuJDMckm5lhvCW160" alt="" width="324"><figcaption></figcaption></figure>

6. Select the purpose, based on the requirement (live or test), from the dropdown.
7. After providing all the details, click on "Proceed."

<figure><img src="/files/UgDC0TClrwDhgClH7jG2" alt=""><figcaption></figcaption></figure>

8. You will need to authenticate the certificate generation using your Officer token, then press Authenticate to proceed.
9. Click on "Generate Key Pair" to complete the key pair generation.
10. Upon completion, the following UI will be shown:

<figure><img src="/files/g527vLVhpn9h8xqrQn5x" alt=""><figcaption></figcaption></figure>

11. Select "View All" to see the created key pair grid or click on "+New" to create a new key pair.

**Generate EMV scheme /Root Certificate:**

{% hint style="info" %}
Note: To initiate the creation of a Certificate request or Scheme Certificate, the user need to generate Key pair.
{% endhint %}

<figure><img src="/files/WFf9MdvrKUSyS9QG1MUA" alt=""><figcaption></figcaption></figure>

To generate an EMV certificate, click the "CA Public Key Certificate/Issuer Public Key Certificate Request" ![](/files/rePTkChqzlKPsXmsGBKt)icon in the Action column.

<figure><img src="/files/Ip7zN4vvStogqGlWN0K9" alt=""><figcaption></figcaption></figure>

Select the "Certificate" radio button to generate a Root or Scheme certificate. Choose the certificate profile from the dropdown.

<figure><img src="/files/yNd3ugSirXwqXB9qAoEx" alt=""><figcaption></figcaption></figure>

When you select a certificate profile , you will be prompted to enter its details. You need to enter the RID value, CA Public Key Index, and expiration date in the MMYY format. From the dropdown menu, select "MasterCard" as the type of certificate. Lastly, provide a description for the purpose of the certificate. Once you have provided all the details, click on the "Proceed" button.

<figure><img src="/files/HZa4uY3UjicxJCxs7sIs" alt=""><figcaption></figcaption></figure>

You will need to authenticate the certificate generation using your Officer token, then press "Authenticate" to proceed.

Click on "Create" to complete the Certificate Generation Process.

Upon successful completion, you will receive a success message on the screen for the creation of the EMV Certificate. The certificates are created in SEP and HEP files. Users can download the files, and the downloaded SEP file and HEP file are displayed with the name "MSI" followed by the index number.

Click "View all" to see the created scheme certificates. Click "+New" to create another certificate.

<figure><img src="/files/rgG50y7eNhSavN3jBR7A" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/3bRTms6ROHvMadfqpURU" alt=""><figcaption></figcaption></figure>

**Generate Certificate Request**

{% hint style="info" %}
**Note:** To initiate the creation of a Certificate request or Scheme Certificate, user need to generate EMV Key pair.
{% endhint %}

To generate a Certificate Request, click on the "CA Public Key Certificate/Issuer Public Key Certificate Request" icon in the Action column.

<figure><img src="/files/boCNuA4y9FkCt8JAKzNi" alt=""><figcaption></figcaption></figure>

After clicking on the Flag icon, the screen shown below will appear:

<figure><img src="/files/8jL3qsPPqCjsetxfzfoR" alt=""><figcaption></figcaption></figure>

To generate a certificate request, select the "Certificate Request" option. Enter the BIN (Bank Identification Number) provided by your bank, followed by the Issuer Public Key Index. Provide the Expiry Date in MMYY format. Once you have entered all the required information, click on the "Proceed" button to proceed with the request.

<figure><img src="/files/F0zPcz52dKSrWUkZEtwx" alt=""><figcaption></figcaption></figure>

After selecting "Proceed," you will need to authenticate the certificate generation using your officer token and press the "Authenticate" button.

<figure><img src="/files/tye1PQx3EV3ur0LuzIOo" alt=""><figcaption></figcaption></figure>

After successfully authenticating, click "Create" to generate the certificate request. Once complete, the following UI will be displayed:

<figure><img src="/files/Lvzju1zXqsmTVSJsGsrw" alt=""><figcaption></figcaption></figure>

After successfully creating a "Certificate Request", users will receive a success message on their screen. The certificates will be generated in SIP and HIP file formats. Users can download these files, and they will be displayed with the prefix of the BIN NO followed by the suffix of the Issuer Public Key Index. For clarity, this will be shown as follows: \[BIN NO]\_\[Issuer Public Key Index]. The downloaded SIP and HIP files can then be used as needed.

<figure><img src="/files/fkyKxKYkRloSa33BycJK" alt="" width="135"><figcaption></figcaption></figure>

Click "View" to see created certificate requests. Click "+New" to create another request.

{% hint style="info" %}
**Note:** To obtain the Issuer Public Key certificate, you must upload the generated SIP and HIP files for them to be signed with the Scheme certificate.
{% endhint %}

**Manage EMV Public keys**

In this section, you can find the "EMV Public Keys" for certificates that are linked to each RID in a JSON file. By selecting an RID from the dropdown menu, the user can view a list of CA Public Keys that correspond to the selected RID.

Please provide the name and a description.

Click on "Proceed." you will then be prompted to authenticate the certificate generation:

<figure><img src="/files/VYSEoygGR6QgbymQ4hbD" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/JT8e6wZUx7gTkPB0q5LK" alt=""><figcaption></figcaption></figure>

Press "Authenticate" after authenticating with your Officer token to proceed.

Upon successful authentication, click on the "Create" button.

<figure><img src="/files/dl1TwHtUWtkd1LML4U4S" alt=""><figcaption></figcaption></figure>

Upon clicking the "Create" button, EMV Public keys will be created in a JSON object as shown.

<figure><img src="/files/DtUuauwoC8AuCqXHUQGz" alt=""><figcaption></figcaption></figure>

**Generate Issuer Public Key Certificate**

When a user chooses the "Generate Issuer Public Key Certificate" option within the "Manage EMV Certificate" section, the following user interface (UI) will be presented. This UI will display a grid listing all previously created EMV certifications, including both Issuer public key certificates and CA public key certificates, as shown below.

<figure><img src="/files/CaT5MJJ7pe0oCEWvyhlL" alt=""><figcaption></figcaption></figure>

To generate an Issuer Public key certificate, the user needs to sign a "certificate request" by selecting the "+Sign EMV Certificate" option.

Upon selecting "+Sign EMV Certificate," the screen displayed will direct the user to perform the following actions shown in the below screen

<figure><img src="/files/kAIKyIYjqWjPLNr7mhLX" alt=""><figcaption></figcaption></figure>

Upload the SIP and HIP files and choose the Issuer Certificate from the dropdown menu.

<figure><img src="/files/T9SZJgtBZQ5G3bp0fVU7" alt="" width="328"><figcaption></figcaption></figure>

To continue, kindly click on the "Proceed" button.

<figure><img src="/files/Ilsuxk4iwnxaf6YXPDzm" alt=""><figcaption></figcaption></figure>

After selecting the "Proceed" button, you will be directed to the "Verify and Confirm" section. This section will display the SIP details for your review, as shown below. Here, you can confirm that the information is correct before proceeding by clicking the "Proceed" button again.

<figure><img src="/files/xWQLxs6M9eN3Hy5Uq5z1" alt=""><figcaption></figcaption></figure>

After clicking "Proceed," the authentication process will be initiated. The user will be required to provide their password for authentication purposes.

Additionally, the user has the option to edit SIP details, including the serial number, if necessary.

<figure><img src="/files/JLIuaEk7HoeaADgWIMQv" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/qEUv8dF8CoUuDNEQvMcL" alt=""><figcaption></figcaption></figure>

Clicking the "Sign" button after successful authentication will trigger a message confirming the successful signing of the EMV request.

The user can download the certificate in .C21 format by clicking "Download." The format number corresponds with the issuer index.

<figure><img src="/files/VwQzqRiWHa7GawawEVMP" alt=""><figcaption></figcaption></figure>

&#x20;


# Manage EMV CRL

To manage EMV CRLs, a user with an officer role can navigate to the "Manage EMV CRLs" page which displays a grid of available certificates.

<figure><img src="/files/vD2Kqs1trIahTcNml7YN" alt=""><figcaption></figcaption></figure>

If the user wants to revoke a certificate, they can do so by selecting the "Revoke" icon located in the action column. By selecting this icon, a popup screen will appear that prompts the user to fill in certain details such as the Revocation Date, the Revocation Effective Date, and remarks regarding the revocation. Once these details are entered, the user should click on the "Confirm" button to complete the revocation process.

<figure><img src="/files/4a7o1jFzLORJ9UnPjoe1" alt="" width="355"><figcaption></figcaption></figure>

After you click the "Confirm" button, the system will ask you to authenticate. To do this, you need to provide your username and token PIN. Once you have been successfully authenticated, you can click the "Revoke" button to complete the certificate revocation process.

Once the revocation process is completed successfully, you will receive a message displaying the following information.

<figure><img src="/files/9j5aegSneJMMgrBVyH0B" alt=""><figcaption></figcaption></figure>


# ePassport Certificates

ePassports, defined under ICAO Doc 9303, embed chips that store identity and biometric information. To secure this data, countries establish a **Public Key Infrastructure (PKI)** consisting of a Country Signing Certificate Authority (CSCA) and Document Signer Certificates.

emCA supports issuing these certificates, enabling Basic Access Control (BAC) and Extended Access Control (EAC) mechanisms. This ensures authenticity of travel documents, protects biometric data, and facilitates interoperability across borders.

How to configure, create, and issue ePassport Certificates in emCA will be published shortly.


# C-V2X Certificates

Cellular Vehicle-to-Everything (C-V2X) communication requires certificates to authenticate messages exchanged between vehicles, roadside units, and control centers. These certificates form the basis of trust in Cooperative Intelligent Transport Systems (C-ITS).&#x20;

emCA supports issuing certificates for C-ITS Enrollment Authorities (EA) and Authorization Authorities (AA), enabling secure message signing and validation in line with regional standards. This supports road safety applications, traffic efficiency services, and emerging intelligent transport infrastructures.

How to configure, create, and issue C-V2X Certificates in emCA will be published shortly.


# Integrating emCA

Simplified Integrations for Powerful PKI Solution

emCA exposes REST endpoints for CA and certificate lifecycle operations.

This emCA Dev section equips you with everything you need to seamlessly integrate CA management and certificate lifecycle management functionalities into your applications. Endpoints mirror functions available in the emCA Certificate Manager UI and are consumed over HTTPS with JSON payloads.

emCA services ensure you to take complete control of your Public Key Infrastructure (PKI) with our user-friendly APIs. Use our APIs to integrate eSignatures into your applications. Additionally:&#x20;

* #### Highly Cost Effective

  Our API's come as standard features and part of all plans and cost a fraction of other options in the market.
* #### Secure and Scalable

  Our API's meet stringent security standards such as ISO 27001 and SOC2 Type 2 and are highly available through geographically redundant cloud setup.
* #### Open API Specifications

  The REST API specifications are built on Swagger making the APIs easy to understand and deploy.
* #### Free Sandbox Accounts

  Get started quickly by signing up for developer sandbox and migrate your API's and Workflow definitions easily to production.


# Connecting External Applications

External applications are client systems that must be registered in emCA to access emCA Services (APIs).

The onboarding process of External Applications can be triggered from the following interface:

<figure><img src="/files/Vhp8rzPEhUWY2bMFIFkh" alt=""><figcaption></figcaption></figure>

Click + New to register a new External Application.

<figure><img src="/files/eK2cNq7kq35yWTJm5c41" alt=""><figcaption></figcaption></figure>

* Enter the Username for the new External Application.
* Enter a password for the new External Application. The password must comply with the password policy of emCA.
* Enter the IP Address of the new External Application. This address is used to whitelist the new External Application.

All of the above parameters will have to be provided during access to the emCA API.

<figure><img src="/files/WFL0AnX2HyEIuZLyA4Hj" alt=""><figcaption></figcaption></figure>

After providing the required fields click on proceed to continue.

You will be prompted to authenticate the registration:

<figure><img src="/files/IxJGy9vJtTeSmUiLT3xv" alt=""><figcaption></figcaption></figure>

Authenticate using your Administrator token and proceed by pressing Authenticate.

Click Sign and Save to generate a certificate for the new External Application.

<figure><img src="/files/NdSUIsy7HMpNpOSxiTkd" alt=""><figcaption></figcaption></figure>

Click on "View all" to see the created application links and click on "New" to create a new certificate.


# REST API Support

The emCA application provides REST APIs that enable integration with external systems for certificate and signing operations. It offers three categories of APIs: CA Management, Certificate Management, and eSign. These APIs support secure interactions, allow automation of key processes, and adhere to industry standards.

Detailed specifications and usage examples for each API type are available in the Postman documentation, accessible through the provided links.

**Authentication** for the emCA REST API v5.0.0 is handled via **JWT (JSON Web Token)**. A token must be obtained once and then included in every subsequent API request as the **`X-Emca-Api-Key`** header.

[Postman Link for Authentication API](https://documenter.getpostman.com/view/40123569/2sBXqDuPtp#b5fc84cf-1008-4137-98a7-a50fcf1549a2)

#### **CA Management API**

The CA Management APIs enable core functions of a Certifying Authority, including certificate issuance, renewal, revocation, and validation. They support RSA and ECC algorithms, follow industry standards for security and interoperability, and allow integration with existing systems for automated certificate lifecycle management

[Postman Link for CA Management APIs](https://documenter.getpostman.com/view/40123569/2sBXqDuPtp#bcc10c65-ac6c-4ec9-a2a2-9eb576f75e0d)

#### **Certificate Management API**

The Certificate Management APIs cover the complete lifecycle of digital certificates, from issuance and renewal to revocation and validation. They are designed to integrate with existing systems, support RSA and ECC algorithms, and comply with industry standards for secure and reliable PKI operations.

[Postman Link for Certificate Management APIs](https://documenter.getpostman.com/view/40123569/2sBXqDuPtp#261138d1-c52a-40d8-89b0-67a0ce078115)

#### **OCSP Management APIs**&#x20;

provide a programmatic interface for managing the Online Certificate Status Protocol (OCSP) infrastructure within the emCA platform. These APIs allow administrators to create OCSP responder certificates, map OCSP certificates to CAs, revoke OCSP certificates, and configure OCSP response caching.

[Postman Link for OCSP Certificate Management API](https://documenter.getpostman.com/view/40123569/2sBXqDuPtp#336dee9c-1347-4c51-9dc1-4a2df522db04)

#### **Backup Management APIs**&#x20;

Provide a secure and programmatic interface for managing the backup lifecycle of the application's critical components, including configuration files and databases. These APIs enable both automated and manual control over backup operations to support disaster recovery, compliance, and operational resilience.

They are designed for use by administrators or authorized external applications and can be easily integrated into enterprise backup workflows or third-party management systems.

[Postman Link for OCSP Certificate Management API](https://documenter.getpostman.com/view/40123569/2sBXqDuPtp#664f4b03-367d-48ee-90fa-0cedee2ea7b3)

#### **eSign APIs**

The eSign APIs allow signing of document hashes with user registration and authentication based on unique IDs. They provide secure, programmatic access and can be integrated into existing systems for electronic signing processes.

[Postman Link for eSign APIs](https://documenter.getpostman.com/view/28084851/2sA3e1CAqy)

For API release notes and Postman documentation related to older versions, please refer to the respective Previous Release Versions section.


# CA Management

## Prerequisites

Register your application with emCA and obtain credentials. Provide:

* **Username (appCode)**
* **Password**
* **Source IP address** for allowlisting

All API traffic must use HTTPS (TLS 1.2+).

## &#x20;Registration

1. Submit **appCode**, **password**, and **IP address**.
2. emCA issues a **ClientID** for your application.
3. Use the ClientID for all subsequent API requests.

## Authentication

CA Management REST APIs require an **AuthKey** on every request.

* Generate a unique **transaction ID (`txn`)** per request.
* Capture a **request timestamp (`ts`)** at call time.
* Compute:

  ```
  iniCopyEditAuthKey = SHA256( ClientID + ts + txn )
  ```

  (Concatenate the values as strings; encode the hash as lowercase hex.)
* Send the following with each request (headers or fields as specified by the API reference):
  * `ClientID`
  * `ts`
  * `txn`
  * `AuthKey`

Ensure `ts` represents the current request time and `txn` is not reused.

## CA Management APIs documentation

All APIs related to CA management functionalities:

* createCA
* createCSR
* createorupdateCRL
* createUpdateCRLProfile
* createUpdateProfile
* getCrl
* importCertificate
* generateCertificate

## emCA Version-Based Postman Links:

* [V5.0.0](https://documenter.getpostman.com/view/40123569/2sBXqDuPtp#bcc10c65-ac6c-4ec9-a2a2-9eb576f75e0d)

{% hint style="info" %}
Please refer in the respective version sections for older API Postman Collections.
{% endhint %}


# Certificate Management

## Prerequisites

Register your application with emCA and obtain credentials. Provide:

* **Username (appCode)**
* **Password**
* **Source IP address** for allowlisting

All API traffic must use HTTPS (TLS 1.2+).

## &#x20;Registration

1. Submit **appCode**, **password**, and **IP address**.
2. emCA issues a **ClientID** for your application.
3. Use the ClientID for all subsequent API requests.

## Authentication (JWT)

Certificate Management APIs use a short-lived **JWT** for authentication. To obtain a token, call the token endpoint with your **appCode**, **password**, and **ClientID**. The response returns a JWT and its expiry (`exp`). Include the token in each request header:

```
makefile

Authorization: Bearer <JWT>
```

Renew the token before expiry and discard expired tokens. Use one unique token per application context; do not share tokens across tenants or environments.

## Certificate Management APIs documentation

All APIs related to certificate issuance, management, and lifecycle operations:

* createCertificates
* createCustomCertificate
* createKeyStore
* getCAs
* getCertInfo
* getCertificate
* getCertificateChain
* getCertInfo
* getProfileInfo
* getProfiles
* reinstate
* rekey
* revoke
* suspend
* verifySignature

## emCA Version-Based Postman Links:

* [V5.0.0](https://documenter.getpostman.com/view/40123569/2sBXqDuPtp#261138d1-c52a-40d8-89b0-67a0ce078115)

{% hint style="info" %}
Please refer in the respective version sections for older API Postman Collections.
{% endhint %}


# eSign

## Prerequisites

Register once to obtain a unique ID used for all API authentications. The ID is derived from your system ID and email supplied at registration. All requests must use HTTPS (TLS 1.2+).

## Registration

Provide the following KYC details: full name, state, location, country, email, organisation, organisation unit, mobile, and system ID.\
**Mandatory:** full name, email, and system ID.

After approval, generate your **unique ID** as:\
`<systemID><email>`

{% hint style="info" %}
Example: system ID `LOREM-IPSUM`, email `abc@xyz.com` → unique ID `LOREM-IPSUMabc@xyz.com`.
{% endhint %}

This unique ID is required for all eSign API calls.

## Authentication

eSign APIs authenticate each request with the **unique ID** created during registration.\
Include the unique ID in every call (header or field as defined in the API reference).\
Use the exact value and casing; treat the ID as sensitive configuration, not client visible.

## eSign APIs Documentation

All APIs related to user registration, signing document hash, getting certificate chain and user KYC status:

* keygen/csr
* signing/sign
* getCertificateChain
* getKYCStatus

## eSign Postman Link:

* [eSign](https://documenter.getpostman.com/view/28084851/2sA3e1CAqy)


# Configuration Protocol Support

emCA supports standard protocols for automated certificate enrolment and lifecycle operations.

* **ACME (Automatic Certificate Management Environment)** Implements ACME APIs for automated enrolment and renewal. Integrates with ACME clients and enforces CA policy and auditing.
* **EST (Enrollment over Secure Transport)** Provides enrolment over HTTPS with proof-of-possession. Supports initial enrollment and re-enrolment with client authentication.
* **CMP (Certificate Management Protocol)**  &#x20;Supports issuance, renewal, revocation, and key update. Operates over standard transports and aligns with enterprise policy controls.
* **SCEP (Simple Certificate Enrollment Protocol)**  &#x20;Enables device enrollment in constrained or network-appliance environments. Supports request/renew flows suitable for MDMs, firewalls, and routers.


# ACME Protocol

emCA implements ACME per RFC 8555 (<https://datatracker.ietf.org/doc/html/rfc8555>). Requests are JWS-signed JSON over HTTPS. Directory, nonce, and error semantics follow the spec. Policy and audit controls apply to all ACME operations.

The client generates an asymmetric key pair. It retrieves the directory and a nonce. It submits a new Account request signed with the private key. Optional fields include contact URIs and ToS agreement. External Account Binding (EAB) is supported if required by policy. On success, the server issues an account with a stable kid (account URL).

## Prerequisites

#### Registration

In emCA, ACME clients must first **register through the emCA Portal**.

Steps to be followed by the emCA Team:

1. Once the emCA team receives the client's username, password, and IP address,
2. The emCA Administrator should log in to the emCA portal using an Admin account,
3. And proceed to register the client details.

emCA Administrator should log in to the emCA portal as Admin/CA Admin and navigate to “Application Settings‟ -> “External Applications‟ as shown in the figure.

![Figure 1](/files/CqqMqsvWXRu0SVgRwUqd)

Click on “New‟ The following screen will be displayed.

<figure><img src="/files/VcGy40jIX5wKoLbRZ7r9" alt=""><figcaption><p>Figure 2</p></figcaption></figure>

<figure><img src="/files/B7UT1fCajZGIP1bArXm8" alt=""><figcaption><p>Figure 3</p></figcaption></figure>

Once the details are entered, click on “Proceed‟.

The “Verify and Confirm‟ page will be displayed where the Admin/CA Admin should verify and enter details and authenticate by entering the Username and Password

<figure><img src="/files/FPfBEq47th3OQpZSUSZu" alt=""><figcaption><p>Figure 3</p></figcaption></figure>

Click on “Sign and Save‟.

<figure><img src="/files/79Lkb8ZnIPpDQlYunKwa" alt=""><figcaption><p>Figue 4</p></figcaption></figure>

Click on the “copy icon‟ button to save the client ID.

#### Create Certificate Template

Create the appropriate certificate template in emCA by following the steps outlined in **Section –** [Configuring Certificate Profile](/getting-started/configuring-certificate-profiles) -> *User Profile Creation*. Be sure to record important details such as the **Profile Name** or **Certificate Profile ID**, as these will be required during the certificate enrollment process.

#### Configure Properties

Configuration must be defined in the database. The required values must be updated in the **\`api\_properties\`** table to enable ACME server functionality.

| acme.ca.server.user.profile             | Cert profile name /ID | Active |
| --------------------------------------- | --------------------- | ------ |
| emca.acme.base.url                      | emCA API Base URL     | Active |
| emca.acme.extenal.application.username  | ACME Client           | Active |
| emca.acme.extenal.application.password  | Password              | Active |
| emca.acme.extenal.application.client-id | Client id             | Active |

Please find the following script to update the necessary values in the database:

```
-- Certificate template profile ID
UPDATE api_properties
SET prop_value = 'xxxx', prop_status = 1
WHERE prop_key = 'acme.ca.server.user.profile';
-- emCA Services Base URL
UPDATE api_properties
SET prop_value = 'https://www.example.com/emCAServices/acme', prop_status = 1
WHERE prop_key = ‘emca.acme.base.url;

-- External application details
UPDATE api_properties 
SET prop_value = 'xxxx', prop_status = 1 
WHERE prop_key = 'emca.acme.extenal.application.username';

UPDATE api_properties 
SET prop_value = 'xxxx', prop_status = 1 
WHERE prop_key = 'emca.acme.extenal.application.password';

UPDATE api_properties 
SET prop_value = 'xxxx', prop_status = 1 
WHERE prop_key = 'emca.acme.extenal.application.client-id';
```

{% hint style="info" %}
**Note**: To apply the configuration changes, it is necessary to restart the Tomcat services. Please follow the steps below to restart Tomcat
{% endhint %}

### ACME Endpoint

Base URL: <https://www.example.com/emCAServices/acme>

#### Supported Endpoints

| **Endpoint**              | **Type of Method** | **Description**                                          |
| ------------------------- | ------------------ | -------------------------------------------------------- |
| /directory                | GET                | Returns a list of available ACME endpoints and metadata. |
| /new-nonce                | HEAD               | Used to get a fresh anti-replay nonce.                   |
| /new-account              | POST               | Creates a new ACME account.                              |
| /account/{accountId}      | POST               | Retrieves or updates an existing ACME account.           |
| /new-order                | POST               | Creates a new order for a certificate.                   |
| /order/{orderId}          | POST               | Retrieves details of a specific order.                   |
| /order/{orderId}/finalize | POST               | Submits the CSR to finalize the certificate order.       |
| /new-authz                | POST               | Creates a new authorization object.                      |
| /authz/{authorizationId}  | POST               | Retrieves the status of a specific authorization.        |
| /chall/{challengeId}      | POST               | Responds to a challenge for domain validation.           |
| /revoke-cert              | POST               | Submits a certificate for revocation.                    |
| /key-change               | POST               | Requests a change of the account key pair.               |
| /cert/{certId}            | POST               | Downloads the issued certificate.                        |

### Authentication

* ACME uses **JSON Web Signature (JWS)**-signed requests to authenticate clients.
* Clients are required to generate an **account key pair** and use the private key to sign all requests sent to the server.
* The emCA ACME server verifies the **JWS signature** of each request to ensure the authenticity and integrity of the client’s identity and actions.

### HTTP Response Status Codes

| **HTTP Status Code** | **Meaning**           | **Description**                                                                                             |
| -------------------- | --------------------- | ----------------------------------------------------------------------------------------------------------- |
| 200                  | OK                    | The request was successful, and the response contains the requested data                                    |
| 201                  | Created               | A new resource (e.g., account or order) was successfully created.                                           |
| 202                  | Accepted              | The request has been accepted for processing, but the operation is not complete (e.g., pending validation). |
| 204                  | No Content            | The request was successful, but there is no content to return (e.g., successful revocation).                |
| 400                  | Bad Request           | The request was malformed or invalid.                                                                       |
| 401                  | Unauthorized          | The client failed to authenticate (e.g., missing or invalid JWS signature).                                 |
| 500                  | Internal Server Error | An unexpected server error occurred.                                                                        |


# EST Protocol

**Enrollment over Secure Transport** (EST) is a certificate enrollment protocol that operates over HTTPS, offering strong client authentication and enhanced security features. This implementation of EST (Enrollment over Secure Transport), as defined in RFC 7030 (<https://www.rfc-editor.org/rfc/rfc7030.html>), supports basic certificate enrollment and retrieval of CA certificates. Communication is secured using HTTPS (HTTP over TLS) over TCP, and client authentication is performed using HTTP Basic Authentication.

### Prerequisites

#### Registration

In emCA, EST (Enrollment over Secure Transport) requests are authenticated using **Basic Authentication**. Therefore, before utilizing the EST protocol, the client must first **register through the emCA Portal**.

Steps to be followed by the emCA Team:

1. Once the emCA team receives the client's username, password, and IP address,
2. The emCA Administrator should log in to the emCA portal using an Admin account,
3. And proceed to register the client details to authorize EST access.

emCA Administrator should login to the emCA portal as Admin/CA Admin and navigate to “Application Settings‟ -> “External Applications‟ as shown in the figure.

![Figure 1](/files/CqqMqsvWXRu0SVgRwUqd)

Click on “New‟ The following screen will be displayed.

![Figure 2](/files/VYWepnlbcqJh0yQHtOwm)

![Figure 3](/files/sm5nVaeP0bnlxQmx64SG)

Once the details are entered, click on “Proceed‟.

The “Verify and Confirm‟ page will be displayed where the Admin/CA Admin should verify and entered details and authenticate by entering the Username and Password

![Figure 4](/files/LqM1uuwGSk4STVYKD5WW)

Click on “Sign and Save‟.

![Figure 5](/files/lRNIRc9DqI8FrVIz5vIp)

#### Create Certificate Template

Create the appropriate certificate template in emCA by following the steps outlined in **Section – Manage Profiles** of the *emCA User Manual*. Be sure to record important details such as the **Profile Name** or **Certificate Profile ID**, as these will be required during the certificate enrollment process.

#### Configure Properties

EST configuration must be defined in the database. The required values must be updated in the \`api\_properties\` table to enable EST CA server functionality.

| est.ca.server.user.profile | EST Cert Profile name/ID | Active |
| -------------------------- | ------------------------ | ------ |
| est.ca.server.group.id     | Group Id                 | Active |

Please find the following script to update the necessary values in the database:

```
-- Certificate template profile ID
UPDATE api_properties
SET prop_value = 'xxxx', prop_status = 1
WHERE prop_key = 'est.ca.server.user.profile';
-- EST CA server group information
UPDATE api_properties
SET prop_value = '1', prop_status = 1
WHERE prop_key = ‘est.ca.server.group.id';
```

**Note**: To apply the configuration changes, it is necessary to restart the Tomcat services. Please follow the steps below to restart Tomcat:

### EST Endpoint

Base URL: <https://www.example.com/emCAServices>/est

### Supported Endpoints

| **Endpoint**  | **Type of Method** | **Description**                                            |
| ------------- | ------------------ | ---------------------------------------------------------- |
| /cacerts      | GET                | Retrieves the CA certificates (trust anchors).             |
| /simpleenroll | POST               | Accepts CSR and returns a signed certificate (enrollment). |

## API Specifications

### Get/est/cacerts

Purpose: Returns a response with the CA certificates (trust anchors)

#### Sample Request

GET /est/cacerts HTTP/1.1\
**Host:** emca.example.com\
**Authorization:** Basic \<Base64(username:password)>\
**Accept:** application/pkcs7-mime

#### Sample Response

**Status:** 200 OK\
**Content-Type:** application/pkcs7-mime\
**Body:** PKCS#7 SignedData containing the CA certificate chain.

### POST/est/simpleenroll

Purpose: Submits a certificate signing request (CSR) and returns a signed certificate.

#### Sample Request

POST /emCAServices/est/simpleenroll HTTP/1.1

**Host:** emca.example.com

**Authorization:** Basic \<Base64(username:password)>

**Content-Type:** application/pkcs10

**Content-Transfer-Encoding:** \<Base64-encoded PKCS#10 CSR>

#### Sample Response

**Status:** 200 OK if successful,

**Content-Type:** application/pkcs7-mime

**Body:** PKCS#7 SignedData with the signed certificate

#### Authentication

* EST (Enrollment over Secure Transport) uses **HTTP Basic Authentication** to verify client identity before processing requests.
* Clients must provide valid **username and password credentials** in the Authorization header of each request.
* Only authenticated clients are permitted to access endpoints.

#### HTTP Response Status Codes

<table data-header-hidden><thead><tr><th>HTTP Status Code Me</th><th valign="top">Meaning </th><th>Description</th></tr></thead><tbody><tr><td>200</td><td valign="top">OK</td><td>Returned when a request (e.g., CSR Attributes, CA Certs, and enrollment) completes successfully.</td></tr><tr><td>400</td><td valign="top">Bad Request</td><td>Returned when a CSR is malformed, missing required fields, or improperly encoded.</td></tr><tr><td>401</td><td valign="top">Unauthorized</td><td>Returned when the client fails to provide correct authentication (HTTP auth, TLS cert).</td></tr><tr><td>500</td><td valign="top">Internal Server Error</td><td>Unexpected error on the EST server</td></tr></tbody></table>


# CMP Protocol

Certificate Management Protocol (CMP) is a flexible and extensible protocol standardized. that enables secure and automated management of digital certificates throughout their lifecycle. Operating primarily over HTTPS, CMP facilitates a wide range of PKI operations, including initial certificate enrollment, key updates, certificate revocation requests, and retrieval of CA certificates and Certificate Revocation Lists (CRLs).

CMP supports robust client authentication methods, including Basic Authentication as implemented in emCA, and ensures message integrity and authenticity through cryptographic protections such as digital signatures and password-based message authentication codes (MACs). Its rich message structure (PKIMessage) allows for asynchronous communication patterns, including polling for certificate issuance in delayed processing scenarios. CMP is widely used in enterprise and governmental PKI deployments requiring strong security, traceability, and automation.

## Prerequisite

### Create Certificate Template

Create the appropriate certificate template in emCA by following the steps outlined in Section 6.3 – Manage Profiles of the *emCA User Manual*. Be sure to record important details such as the Certificate Profile ID, as these will be required during the certificate enrollment process

### Configure Properties

Properties configuration must be defined in the database. The required values must be updated in the `api_properties` table to enable CMP server functionality.

<table data-header-hidden><thead><tr><th valign="top">Key</th><th valign="top">Value</th><th valign="top">Status</th></tr></thead><tbody><tr><td valign="top">CMPCertificateProfileID</td><td valign="top">CMP Cert Profile ID</td><td valign="top">Active</td></tr><tr><td valign="top">CMPAuthenticationCode</td><td valign="top">Password or secret code</td><td valign="top">Active</td></tr></tbody></table>

Please find the following script to update the necessary values in the database:

```
-- Certificate template profile ID
UPDATE api_properties 
SET prop_value = 'xxxx', prop_status = 1 
WHERE prop_key = 'CMPCertificateProfileID’;

-- Client authentication code or password
UPDATE api_properties 
SET prop_value = 'XXXX', prop_status = 1 
WHERE prop_key =  ‘CMPAuthenticationCode’;

```

### Restart Tomcat Services

To apply the configuration changes, it is necessary to restart the Tomcat services. Please follow the steps below to restart Tomcat:

#### Stop the Tomcat services

```
Run the following command to stop the Tomcat service:
```

<table data-header-hidden><thead><tr><th valign="top"></th></tr></thead><tbody><tr><td valign="top">$CATALINA_HOME/bin/shutdown.sh </td></tr></tbody></table>

#### Start the Tomcat Service

Once the service is stopped, start it again using the following command:

<table data-header-hidden><thead><tr><th valign="top"></th></tr></thead><tbody><tr><td valign="top">$CATALINA_HOME/bin/startup.sh</td></tr></tbody></table>

## CMP EndPoint

URL: <https://www.example.com/emCAServices/cmp>

### Supported Endpoints

<table data-header-hidden><thead><tr><th>Endpoint</th><th valign="top">Type of Method</th><th>Descrrption</th></tr></thead><tbody><tr><td>/enrollment</td><td valign="top">POST</td><td>Main endpoint for CMP-based certificate enrollment. Clients send <code>PKIMessage</code> requests to this endpoint.</td></tr></tbody></table>

## Authentication

The emCA CMP Services application authenticates certificate management operations using a pre-configured shared secret.

* CMP messages must be encapsulated in a ProtectedPKIMessage, which ensures message integrity and authenticity.
* Clients are required to include a shared secret (authentication key), known in advance to both the client and the emCA server, to authenticate their requests.
* This secret is used by the client to generate a Password-Based MAC (PBM) or other cryptographic protection in the protection field of the ProtectedPKIMessage.
* The emCA CMP server validates the received message by verifying the PBM protection using the pre-configured shared secret associated with the client identity.
* Only clients with valid shared secrets are authorized to perform operations such as certificate enrollment, revocation, or confirmation.

## HTTP Response Status Code

<table data-header-hidden><thead><tr><th>HTTP Status Code</th><th valign="top">Meaning</th><th>Description</th></tr></thead><tbody><tr><td>200</td><td valign="top">OK</td><td>The CMP server processed the PKIMessage successfully and returned a valid response.</td></tr><tr><td>400</td><td valign="top">Bad Request</td><td>Sent when the client sends an improperly formatted <code>PKIMessage</code>, unsupported operation, or missing fields.</td></tr><tr><td>401</td><td valign="top">Unauthorized</td><td>Returned when the CMP client failed to authenticate using TLS client certificate, shared secret, or other methods.</td></tr><tr><td>415</td><td valign="top">Unsupported Media Type</td><td>Returned when the request is not sent with <code>application/pkixcmp</code> as the Content-Type.</td></tr></tbody></table>


# SCEP Protocol

The Simple Certificate Enrollment Protocol (SCEP) is defined in RFC 8894 (<https://datatracker.ietf.org/doc/html/rfc8894>) and is designed to simplify the secure issuance and management of X.509 certificates in large-scale networked environments. SCEP provides a standard mechanism for network devices and applications—such as routers, switches, VPN gateways, printers, and mobile devices—to securely request and obtain digital certificates from a Public Key Infrastructure (PKI).

SCEP uses a PKCS#10 certificate request encapsulated in a PKCS#7 message, enabling secure communication between the client (RA/EE) and the Registration Authority (RA) or Certificate Authority (CA). It supports automated certificate issuance and renewal, facilitating scalable certificate lifecycle management.

## Prerequisite

### Registeration

* Register your SCEP device in emCA before using protocol.
* The first step of the registration is to share the Device Manufacturer, type, and Model, Device id and Description of the to the emCA team.

Steps to be followed by emCA Team.

Once emCA team receives the Details of SCEP Device, emCA Administrator should login to the emCA portal as Admin/CA Admin and navigate to “Application Settings‟ -> “External Applications‟ as shown in the figure.

<figure><img src="/files/Sfv1aKF2IAJwqukwlLio" alt=""><figcaption></figcaption></figure>

Click on “New‟ The following screen will be displayed.

<figure><img src="/files/XZxMiZvrPCT4GceP1YbU" alt=""><figcaption></figcaption></figure>

Please select Registration type as SCEP and Please required details for registration.

<figure><img src="/files/SEPFmbU5CQBLmHbVCE25" alt=""><figcaption></figcaption></figure>

Once the details are entered, click on “Proceed‟.

The “Verify and Confirm‟ page will be displayed where the Admin/CA Admin should verify and entered details and authenticate by entering the Username and Password

<figure><img src="/files/XBykFY8OQwQs8uS66VhR" alt=""><figcaption></figcaption></figure>

Click on “Sign and Save‟.

The external application will be successfully registered and a challenge password will be generated.

<figure><img src="/files/DheuZuvL7Vbyh3niHjAa" alt=""><figcaption></figcaption></figure>

Click on “copy icon‟ button to save the challenge password.

### Create Certificate Template

Create the appropriate certificate template in emCA by following the steps outlined in Section 6.3 – Manage Profiles of the *emCA User Manual*. Be sure to record important details such as the Certificate Profile ID and Group ID as these will be required during the certificate enrollment process.

### Configure Properties

SCEP configuration must be defined in the database. The required values must be updated in the `api_properties` table to enable SCEP CA server functionality.

<table data-header-hidden><thead><tr><th valign="top">Key</th><th valign="top">Value</th><th valign="top">Status</th></tr></thead><tbody><tr><td valign="top">scep.ca.server.profile.id</td><td valign="top">SCEP-Cert-Profile Id</td><td valign="top">Active</td></tr><tr><td valign="top">scep.ca.server.group.id</td><td valign="top">Group Id</td><td valign="top">Active</td></tr><tr><td valign="top">scep.next.ca.serial.no</td><td valign="top">Next CA Cert Serial No</td><td valign="top">Active</td></tr></tbody></table>

Please find the following script to update the necessary values in the database:

```
-- Certificate template profile ID
UPDATE api_properties 
SET prop_value = 'xxxx', prop_status = 1 
WHERE prop_key = 'scep.ca.server.profile.id';

-- SCEP CA server group information
UPDATE api_properties 
SET prop_value = '1', prop_status = 1 
WHERE prop_key = 'scep.ca.server.group.id';

-- Next SCEP CA serial number (used when issuing a new CA before the current one expires)
UPDATE api_properties 
SET prop_value = 'xxxx', prop_status = 1
WHERE prop_key = 'scep.next.ca.serial.no';

```

### Restart Tomcat Services

To apply the configuration changes, it is necessary to restart the Tomcat services. Please follow the steps below to restart Tomcat:

#### Stop the Tomcat services

```
Run the following command to stop the Tomcat service:
```

<table data-header-hidden><thead><tr><th valign="top"></th></tr></thead><tbody><tr><td valign="top">$CATALINA_HOME/bin/shutdown.sh </td></tr></tbody></table>

#### Start the Tomcat Service

Once the service is stopped, start it again using the following command:

<table data-header-hidden><thead><tr><th valign="top"></th></tr></thead><tbody><tr><td valign="top">$CATALINA_HOME/bin/startup.sh</td></tr></tbody></table>

## SCEP EndPoint

URL:  <https://www.example.com/emCAServices/scep/pkiclient.exe>

### Supported Operations

* GET /scep?operation=GetCACert
* GET /scep?operation=GetCACaps
* POST /scep?operation=PKIOperation

## Authentication

The emCA SCEP server implements authentication mechanisms in accordance with RFC 8894 – Simple Certificate Enrolment Protocol (SCEP), which defines enhanced security requirements for SCEP.

**Supported Authentication Methods:**

* Clients may include a challenge password (using the PKCS#9 challengePassword attribute) in the certificate signing request (CSR).
* This password serves as a shared secret between the client and server to authenticate initial enrollment.
* The emCA server validates the challenge password against a pre-configured value associated with the certificate template or device identity.
* If the challenge password is not included, the request must be signed with a valid existing certificate (e.g., during certificate renewal).
* The signature is verified by the SCEP server to confirm that the request originates from an entity in possession of a previously issued and trusted private key.
* This signature-based method provides proof-of-possession and identity continuity for re-enrollment scenarios.

## HTTP Response Status Codes

<table data-header-hidden><thead><tr><th>HTTP Status Code</th><th valign="top">Meaning</th><th>Description</th></tr></thead><tbody><tr><td>200</td><td valign="top">OK</td><td>Used when a SCEP request is successfully processed and a response (e.g., PKCS#7 or CertRep) is returned.</td></tr><tr><td>400</td><td valign="top">Bad Request</td><td>Returned when a request has invalid parameters or unsupported operations.</td></tr><tr><td>401</td><td valign="top">Unauthorized</td><td>Returned when the client fails to provide correct authentication.</td></tr><tr><td>500</td><td valign="top">Internal Server Error</td><td>Unexpected error on the SCEP server</td></tr></tbody></table>


# Tutorials and Guides

This section provides tutorials and guides to help you get started with emCA.

It also includes task-specific instructions that demonstrate how to use emCA for common certificate management operations.


# Setting Up Root CA Issuance

This section covers the setting up Root CA in emCA.

## CA Certificate Profile Creation

1. Login as an Administrator
2. Click on Manage Profiles
   1. Certificate Profiles -> X509
3. Basic Information
   1. Profile Type: CA
   2. Profile Name: Your Root User Identifier
   3. Validity: as per your CA guidelines
   4. Issuing CA: Please select the corresponding issuing CA for "Self-Signed" in order to create root CA else select any existing CA in order to SUB CA.
   5. Choose algorithm: Select the preferred Algorithm type.
   6. Signature algorithm: Select as per your preferred algorithm type.

<figure><img src="/files/kcKKPeWDt01HUXUVCxFK" alt=""><figcaption></figcaption></figure>

4. Select the DN details: These are as per your regional CA controller.
   1. House Identifier
   2. Country
   3. Organization

<figure><img src="/files/cOKpVHOoWmMV7lIz9HT1" alt=""><figcaption></figcaption></figure>

5. X509 Certificate Extensions: Select the X509 certificate extension
   1. Basic constraint,
   2. Key Usage,
   3. Subject Key Identifier, etc.

<figure><img src="/files/Fm5x5jBtMxVoAPjskrpn" alt=""><figcaption></figcaption></figure>

6. Click on “Proceed” once the selection of DN details and X509 Certificate Extensions are completed.

<figure><img src="/files/yqw9shMbrtBquG7QQbNC" alt=""><figcaption></figcaption></figure>

7. Authenticate as an Administrator

<figure><img src="/files/dtCWCq4NxJAIDDwspbJO" alt=""><figcaption></figcaption></figure>

8. Issuing CA Certificate Profile will be created successfully.

<figure><img src="/files/NtT82ve8s26ZVnpbwgvq" alt=""><figcaption></figcaption></figure>

## Officer Generating Key Pair

1. Login as an Officer User
2. Click on Manage CA Certificates -> Enroll
3. Generate Key Pair:
   1. Select the Number of Keys
   2. Key Profile: Select where you want to store the Keys
   3. Chose algorithm: Select the Key pair algorithm
   4. Signature algorithm: Select the signature algorithm as per the chosen algorithm
   5. Key Algorithm & Size: Select the size of the Key Algorithm as per the chosen algorithm

<figure><img src="/files/UOWz7w15UndWKew12sJG" alt=""><figcaption></figcaption></figure>

4. Click on Proceed
5. Authenticate as an Officer
6. Click on “Generate Key Pair”

<figure><img src="/files/2J2H8AQZHUZGMzZkmpyt" alt=""><figcaption></figcaption></figure>

7. Key pair is generated successfully. Click on “View All” to view the crested key pair or “New” for creating a new Key Pair.

<figure><img src="/files/e27lHUD3v55Ln06RUKPv" alt=""><figcaption></figcaption></figure>

## CA Certificate Issuance

1. Click on “Action: icon” for creating the certificate using the newly generated or existing key pair.

<figure><img src="/files/Cer7FJiJ4vlVqXfjwo55" alt=""><figcaption></figcaption></figure>

2. Enter the Root/ sub-CA Certificate Profile DN information as Administrator configured.

<figure><img src="/files/V9vgkwqaQzQFUo2rqPAO" alt=""><figcaption></figcaption></figure>

3. Authenticate as an Officer and click on “Create”

<figure><img src="/files/6FFYuhPHNGy8T7xu9a9B" alt=""><figcaption></figcaption></figure>

4. Certificate is ready to download after successful authentication.

<figure><img src="/files/7TvruDPCtipIIOIT4Lfs" alt=""><figcaption></figcaption></figure>

5. Click on “View all” to see all the issued CA certificates or “New” to create a new certificate with the key pair and CA certificate Profile.

<figure><img src="/files/ZL10LbmbNPPYQAEUznUZ" alt=""><figcaption></figcaption></figure>


# Setting up TLS Issuance

For TLS Issuance, firstly Administrator needs to create a TLS Certificate Profile, using which an Officer can create and issue the TLA certificate.

## TLS Certificate Profile Creation

1. Login as an Administrator
2. Click on Manage Profiles
   1. Certificate Profiles -> X509

<figure><img src="/files/rKnEN0NqgAFjovalsJPw" alt=""><figcaption></figcaption></figure>

3. Click on “+New Profile” to create a new certificate profile

<figure><img src="/files/YVpqNlQcYD001IMIItbV" alt=""><figcaption></figcaption></figure>

4. Basic Information
   1. Profile Type: User for SSL/ TLS Certificates
   2. Sub Type: New
   3. Profile Name: anything for identification
   4. Validity: as per your Region Certifying Authority Guidelines
   5. Issuing CA: Select your Issuer CA
   6. Signature Algorithm: Select the preferred Algorithm type for SSL/TLS Certificate
5. Subject DN Details: Select as per your SSL Guidelines
   1. Common Name
   2. Email
   3. Country
   4. Organization
   5. Organization Unit

<figure><img src="/files/ShNftu0gYgTjpOBA7hyt" alt=""><figcaption></figcaption></figure>

6. Certificate Extensions: Select as per your SSL Guidelines
   1. Basic Constraint
   2. Key Usage
   3. Enhanced Key Usage
   4. Authority Key Identifier
   5. Subject Key Identifier
   6. Subject Alternative Name
   7. CRL Distribution Points
   8. Certificate Policy
   9. Authority Information Access

<figure><img src="/files/AEoGwEehnq3dVWdsnh5e" alt=""><figcaption></figcaption></figure>

Authentication: Administrator needs to authentication for Security Purpose

<figure><img src="/files/oDK8LiRcUCpoxSFqN5Q7" alt=""><figcaption></figcaption></figure>

X509 TLS Certificate Profile successful creation after successful authentication.

<figure><img src="/files/NGuSQ29g7ghOLbxQn1oX" alt=""><figcaption></figcaption></figure>

Same certificate with the profile basic information and status will be displayed under the menu. An Officer can issue the TLS using this Certificate Profile created by Administrator.

<figure><img src="/files/RO2myeFYMx0shY3yF4C7" alt=""><figcaption></figcaption></figure>

## TLS Certificate Issuance

Officer can use the TLS Certificate Profile created by Administrator to create and issue the TLS Certificates or Sign CSR for TLS Certificates as a CA. This section covers both.

### **Issue New TLS Certificate**

1. Login as an Officer
2. Click on Manage User Certificates -> Enroll
3. Select the Token (Soft/Hard) where the Certificate needs to be stored
4. Select the TLS Certificate Profile that Administrator has created
5. Enter Subject DN, SAN, and other details as per the Certificate Profile
6. Authentication as an Officer before requesting to create the certificate for security purposes

<figure><img src="/files/K3Hi7kdp7JV65B0O2Wtt" alt=""><figcaption></figcaption></figure>

7. After successful authentication, please proceed to “Create” the certificate.

<figure><img src="/files/mMOqRjak6t3sTtyac6Xj" alt=""><figcaption></figcaption></figure>

8. Certificate will be ready to “Download”

<figure><img src="/files/FAQfDyW9BMvGqO2JZILZ" alt=""><figcaption></figcaption></figure>

### **Sign CSR**

If the request is coming from Client/ externals in the form of CSR – follow this tutorial.

1. Login as an Officer
2. Click on Manage User Certificates -> Sign CSR
3. Select the Configuration Type, either file Upload or Text Area
4. Select the Certificate Profile crested by Administrator
5. Finally, the Certifying Authority (CA)

<figure><img src="/files/cqqkNFQUndWFsnnvLFbn" alt=""><figcaption></figcaption></figure>

6. Click on Proceed
7. Enter CSR details as per the Certificate Profile
   1. Common Name
   2. Email
   3. Country
   4. Organization
   5. Organization Unit
   6. SAN details

<figure><img src="/files/BWkgdjji134ZcU49jIiQ" alt=""><figcaption></figcaption></figure>

8. Check Other details
   1. Key Size
   2. Certificate Profile
   3. Certifying Authority
9. Click on Proceed

<figure><img src="/files/SBTZxqU91danvh6cNXaW" alt=""><figcaption></figcaption></figure>

10. Authenticate as an Officer
11. Finally, Sign CSR

<figure><img src="/files/bUXW4vabhrCJ5ExqtsjW" alt=""><figcaption></figcaption></figure>

Signed CSR as a CA will be ready to download for TLS issuance.


# Setting up Client Auth Certificates

For Client Auth Certificates, firstly Administrator needs to create a Client Authentication Certificate Profile, using which an Officer can create and issue the certificates.

## Client Auth Certificate Profile Creation

1. Login as an Administrator
2. Click on Manage Profiles
   1. Certificate Profiles -> X509

<figure><img src="/files/qVtON998kCdIttnxfSgV" alt=""><figcaption></figcaption></figure>

3. Click on “+New Profile” to create a new certificate profile

<figure><img src="/files/bwoU2xYMReDEefTNB1pR" alt=""><figcaption></figcaption></figure>

4. Basic Information
   1. Profile Type: User for Client Auth Certificates
   2. Sub Type: New
   3. Profile Name: anything for identification
   4. Validity: as per your Region Certifying Authority Guidelines
   5. Issuing CA: Select your Issuer CA
   6. Signature Algorithm: Select the preferred Algorithm type for Client Auth Certificates
5. Subject DN Details: Select as per your SSL Guidelines
   1. Common Name
   2. Email
   3. Country
   4. Organization
   5. Organization Unit

<figure><img src="/files/38OXXOPLYoPpbipB6L09" alt=""><figcaption></figcaption></figure>

6. Certificate Extensions: Select as per your SSL Guidelines
   1. Basic Constraint
   2. Key Usage
   3. Enhanced Key Usage
   4. Authority Key Identifier
   5. Subject Key Identifier
   6. Subject Alternative Name
   7. CRL Distribution Points
   8. Certificate Policy
   9. Authority Information Access

<figure><img src="/files/Wan4L9gn6FPDSltWWwWO" alt=""><figcaption></figcaption></figure>

7. Authentication: Administrator needs to authentication for Security Purpose
8. X509 Client Auth Certificate Profile creates successfully.

<figure><img src="/files/Sl4tPTbYj7g531JI4IJO" alt=""><figcaption></figcaption></figure>

9. Same certificate with the profile basic information and status will be displayed under the menu. An Officer can issue the TLS using this Certificate Profile created by Administrator.

<figure><img src="/files/SK70PUOrXeUCrod6vQVu" alt=""><figcaption></figcaption></figure>

## Client Auth Certificate Issuance

Officer can use the Client Auth Certificate Profile created by Administrator to create and issue the Client Auth Certificates or Sign CSR for Client Auth Certificates as a CA. This section covers both.

### Enroll New Client Auth Certificate

1. Login as an Officer
2. Click on Manage User Certificates -> Enroll
3. Select the Token (Soft/Hard) where the Certificate needs to be stored
4. Select the Client Auth Certificate Profile that Administrator has created
5. Enter Subject DN, SAN, and other details as per the Certificate Profile
6. Authentication as an Officer before requesting to create the certificate for security purposes

<figure><img src="/files/CkoyMatO4PeFr9syN3LL" alt=""><figcaption></figcaption></figure>

7. After successful authentication, please proceed to “Create” the certificate.

<figure><img src="/files/ewvl2spUj8A88wFHgNND" alt=""><figcaption></figcaption></figure>

8. Certificate will be ready to “Download”.

### Sign CSR

If the request is coming from Client/ externals in the form of CSR – follow this tutorial.

1. Login as an Officer
2. Click on Manage User Certificates -> Sign CSR
3. Select the Configuration Type, either file Upload or Text Area
4. Select the Certificate Profile crested by Administrator
5. Finally, the Certifying Authority (CA)

<figure><img src="/files/wbbE4Z2hYyZBDgItyQw9" alt=""><figcaption></figcaption></figure>

6. Click on Proceed
7. Enter CSR details as per the Certificate Profile
   1. Common Name
   2. Email
   3. Country
   4. Organization
   5. Organization Unit
   6. SAN details

<figure><img src="/files/kZ8yQ6gUCuXk3g9Tnbhu" alt=""><figcaption></figcaption></figure>

8. Check Other details
   1. Key Size
   2. Certificate Profile
   3. Certifying Authority
9. Click on Proceed
10. Authenticate as an Officer
11. Finally, Sign CSR

<figure><img src="/files/kbpBAEuGMoCoG2oQFNpJ" alt=""><figcaption></figcaption></figure>

Signed CSR as a CA will be ready to download for TLS issuance.


# Setting Up PQC Issuance

In this section, set-by-step flow of PQC Certificate issuance in emCA is explained.

## PQC Certificate Profile Creation

1. Login as an Administrator
2. Click on Manage Profiles
   1. Certificate Profiles -> X509

<figure><img src="/files/0m0rA7S8TdYe5oX8OY3S" alt=""><figcaption></figcaption></figure>

3. Click on “+New Profile” to create a new PQC certificate profile
4. Fill in Basic Information
   1. Profile Type: User
   2. Sub Type: New
   3. Profile name: anything for identification
   4. Validity: as per your Region Certifying Authority Guidelines
   5. Issuing CA: Select your Issuer CA
   6. Signature Algorithm: Select the PQC Algorithm

<figure><img src="/files/In8XXQXsjl5uDBBUTkjg" alt=""><figcaption></figcaption></figure>

5. Subject DN Details:
   1. Common Name
   2. Email
   3. Country
   4. Organization
   5. Organization Unit

<figure><img src="/files/rjQRnFzmxQHCFGG5b5xa" alt=""><figcaption></figcaption></figure>

6. X509 Certificate Extensions
   1. Basic Constraint
   2. Key Usage
   3. Enhanced Key Usage
   4. Authority Key Identifier

<figure><img src="/files/jtqUON06UPZrc6YKNyTH" alt=""><figcaption></figcaption></figure>

7. Click on “Proceed” and authenticate.

<figure><img src="/files/VWyxyIByaIY9P9R6I8l9" alt=""><figcaption></figcaption></figure>

8. Confirm after successful authentication. Profile will be successfully created

<figure><img src="/files/E94rALdfpzdkPa2nOK3F" alt=""><figcaption></figcaption></figure>

## PQC Certificate Issuance

1. Login as an Officer User
2. Click on Manage User Certificates -> Enroll
3. Select the Token (Soft/Hard) where the Certificate needs to be stored
4. Select the PQC Certificate Profile that Administrator has created
5. Enter Subject DN and other details as per the Certificate Profile
6. Authentication as an Officer before requesting to create the certificate for security purposes

<figure><img src="/files/RniwWxKdM1zfR5bvjorU" alt=""><figcaption></figcaption></figure>

7. After successful authentication, please proceed to “Create” the certificate.

<figure><img src="/files/BXRqdLipc6fXCgRucjQ3" alt=""><figcaption></figcaption></figure>

8. PQC certificate will be ready to Download.


# Setting Up OCSP

The Manage OCSP Certificate feature in emCA allows users to configure the created OCSP certificate at the specified URL. This is useful for deploying the OCSP certificate to a public-facing web server or other device where it can be accessed by clients.

## Create OCSP Certificate Profile

As step 1, Officer needs to use the OCSP profile created by CA Administrator. CA Administrator OCSP Profile creation steps are covered under [Configuring Certificate Profiles - OCSP Certificate Profile](/getting-started/configuring-certificate-profiles#ocsp-certificate-profile).

## Generate Key Pair

As step 2, Officer need to Generate a new Key Pair

Click on "Generate Key Pair " to open the following dialog:

<figure><img src="/files/1rgZc0r31LtV6hPUlFda" alt=""><figcaption></figcaption></figure>

Enter the number of keys that you want to generate. In general, you will need 1 key for 1 CA and 1 more key, if that CA will receive an OCSP certificate.

Select the "Key Profile" you want to use from the first dropdown list.

<figure><img src="/files/8TXSFUlBukZqmvZNmdbK" alt=""><figcaption></figcaption></figure>

Choose the "Algorithm" from the drop-down

Select the "Signature algorithm". This will filter the element for the third dropdown list accordingly.

<figure><img src="/files/osl92YduDKdczZAYMOC3" alt=""><figcaption></figcaption></figure>

Select the "Key Algorithm" and "Key Size"

<figure><img src="/files/wvSPi55cAHsfU9XoDgNb" alt=""><figcaption></figcaption></figure>

Press "Proceed" to continue and authenticate the action via Username & Password or Hard/ Soft token basis.

<figure><img src="/files/8q2hwLKJ7KepqLqKO1u6" alt=""><figcaption></figcaption></figure>

Click on "Generate Key Pair(s)" to generate the keys

<figure><img src="/files/GRpmkpyCvgZ9TEqqbhRa" alt=""><figcaption></figcaption></figure>

After the successful generation of the key pair, click on "View all" or "+ New" to continue with the new Key Pair creation.

## Generate CA Certificate

After creating a key pair, select the "Generate Certificate" option available in the "Action" column of the created key pair.

<figure><img src="/files/Coyhvq00jqM5S0WmiF9R" alt=""><figcaption></figcaption></figure>

Click on  !\[A black flag on a white background

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAA0ADgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1yLzpYwwcDNP8uf8A56Ci0/491ovLuOxtJLiX7kYyaTdtwSuHlz/89B+VHlz/APPQVi6F4ysNemeO33Iy/wB7vW+rq/3WB+hqrCIvLn/56Cjy5/8AnoKnpAwJ4IOKQytL50UZYuDiin3f/Hu1FABaf8e61HqkSTabOkgypQ8VJaf8e60l/wD8eM3+4amfwsqO6PCZZ5dP1GYWkhiwxAxU8PiPVoGzHeyCquo/8hKf/eqvketEG+VCkveZ0M3jjV5YdgnZTj7wrqPhxqN3etN9qnaX615tXoPwv+9NWsFuZz6HoN3/AMe7UUXf/Hu1FQWFp/x7rSX/APx4zf7hpbT/AI91qSSMSxsjdGGDSkrpoadnc8u8M+F7PxDe3kl5uwj4AWujm+GmjtERGJFbsc1u6RoVvo7zNASfNbcc1qU7KySFrds80Pwun+0cXKeVnp3rsvD/AIatPD8BS3yWb7xNbNFNNpWE1cgu/wDj3aii7/492opDC0/491qeiigAooooAKKKKAILv/j3aiiigD//2Q==) to start generating a CA certificate.

<figure><img src="/files/WN5LjY1knXZeEFXqaIEa" alt=""><figcaption></figcaption></figure>

The above window opens after clicking on “Action”.

There are two different options available for generation:

* Certificate – use the key to generate a new CA certificate directly.
* CSR – use the key to generate a Certificate Signing Request (CSR).

Choose "Certificate" if you want to directly generate a new CA certificate. This option is applicable if the CA is "self-signed" or the "issuing CA" is in the same instance

Choose "CSR" if the issuing CA is not on the same instance. This is the case if ROOT and SUB CAs are not operated on the same system.

{% hint style="info" %}
Note: You can operate CAs using the appliance functionalities that have their trust anchored outside the Appliance using the option CSR.
{% endhint %}

<figure><img src="/files/kgFAIy15qc9JjHEM6XmJ" alt=""><figcaption></figcaption></figure>

CA Administrator created certificate profiles will be available under “Certificate profile” dropdown.

<figure><img src="/files/KtuQ4n7oriIjIFUrHBe1" alt=""><figcaption></figcaption></figure>

For "Subject DN Details", enter all Subject Distinguished Name (Subject DN) information for the CA as per the certificate profile selection.

Press "Proceed" to continue. You will be prompted to authenticate the action using your officer token/ username & password. Press "Authenticate" to proceed.

<figure><img src="/files/xykoqgDniW5jtE8bKhkc" alt=""><figcaption></figcaption></figure>

Officer is required to successfully authenticate and continue with “Create”.

<figure><img src="/files/8qCRgB6T881XxxEgdzAI" alt=""><figcaption></figcaption></figure>

The "Certificate" will be created and downloadable.

## **Configure OCSP Certificates**

An Officer can manage the Online Certificate Status Protocol (OCSP) certificates of CAs in his/her own group using the following UI.

<figure><img src="/files/UVlHIxL2RIzdcSqpkRnr" alt=""><figcaption></figcaption></figure>

After generation, OCSP certificates must be manually mapped to the corresponding CA.

To map the OCSP certificate to an existing CA, simply click on "OCSP Config".

<figure><img src="/files/xScF2DdAUA7OtT5dbAD0" alt=""><figcaption></figcaption></figure>

Select the CA to which the OCSP certificate should be mapped.

Enter the URL to your OCSP Core Responder in the OCSP URL.

For the emCA application with an internal OCSP Core Responder, this URL will be

```
https://<application_net_address>/ocsprespondercore/
```

where `<application_net_address>` is the Application Network address of your emCA application.

An example of a user interface can be seen in the image below.

<figure><img src="/files/SdxKmcaHGIupcOjichWd" alt="" width="351"><figcaption></figcaption></figure>

Inspect the CA's certificate by clicking "View" next to the registered CA. The OCSP certificate can also be inspected by clicking "View" next to the desired certificate.

To view the details of the OCSP certificate, please click on<img src="/files/JXgG1JsHb5jLkBNz9rXJ" alt="" data-size="line"> icon.

<figure><img src="/files/Ce0i7WaXDVffFAQgcbeW" alt=""><figcaption></figcaption></figure>

Please click on the download <img src="/files/9peWeIbip83orgoc9p7X" alt="" data-size="line"> Icon to obtain the OCSP certificate.

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

&#x20;![](/files/Qh5hl2az8X8i3G9PIWGq)

Select the export format of your choice and click "Download" to start the download of the user certificate. The user certificate will be downloaded to the standard download location of your OS.


# Setting Up Time Stamping

Time Stamping in emCA allows administrators to configure and manage a Time Stamping Authority (TSA) for providing trusted timestamp services. The setup involves creating key profiles, generating key pairs and CSRs, issuing TSA certificates, and registering clients. This section provides a step-by-step guide to complete the configuration and enable timestamping in emCA.

## Manage Key Profile

To begin configuring Time Stamping, log in to the **eMudhra TSA portal** with your credentials.

<figure><img src="/files/AxPBYXadkWeYRNLdHK5h" alt=""><figcaption></figcaption></figure>

Navigate to **Manage Timestamping Signer → Manage Key Profile → New Profile**.

<figure><img src="/files/XARZbax4j4wflAhBqCxu" alt=""><figcaption></figcaption></figure>

Enter the following details:

* **Profile Name**: Identifier for the key profile
* **Profile Type**: Location where the key profile is generated
* **Configuration Type**: Select the configuration type (e.g., PKCS11)
* **HSM Password**: Provide the hardware security module password

<figure><img src="/files/crNNmiPoovAdWAfXctMW" alt=""><figcaption></figcaption></figure>

Click **Confirm** to complete the key profile creation.

![](/files/ptIeISfUt53suDTwzqu2)

<figure><img src="/files/u4eVVop76Nqe49O0bwGd" alt=""><figcaption></figcaption></figure>

The new profile will be listed under **Manage Key Profiles → View All**.

<figure><img src="/files/wjHN3cOfvnOfTSs8dtdd" alt=""><figcaption></figcaption></figure>

## Manage Key Pair

Next, generate a key pair using the key profile created in the previous step.

<figure><img src="/files/zK6j3vZ0RDkRtOMuOxHF" alt=""><figcaption></figcaption></figure>

Go to **Manage Timestamping Signer → Manage Key Pair → Generate Key Pair** and provide:

* **Number of Keys**
* **Key Profile** (select the one you just created)
* **Signature Algorithm**
* **Key Algorithm & Size**

<figure><img src="/files/beGBVkCkuTQ60lNH92hA" alt=""><figcaption></figcaption></figure>

Click **Generate Key Pair** to create the key pair.

![](/files/rpJSdWfKHRtg0aysVdfp)\
The generated key pair will appear under **View All**.

<figure><img src="/files/fokDJG3pn9tC8fBkACGa" alt=""><figcaption></figcaption></figure>

To generate a CSR (Certificate Signing Request), click on the **Action** icon of the created key pair. Enter the required **Subject DN details**:

* Common Name
* Organization
* Organization Unit
* Country

<figure><img src="/files/q87cScJPEN70I3aDSd9D" alt=""><figcaption></figcaption></figure>

Click **Save and Proceed**, then **Create** to generate the CSR.

![](/files/Ux12zODAFDPEv3Dreaxt)

![](/files/4vlYkGhyi0rHVhGsMePG)\
Download the CSR for signing by the CA.

<figure><img src="/files/QK0cOX9iyEWyRGZeG2wS" alt=""><figcaption></figcaption></figure>

## TSA Certificate Profile Creation

Log in as an **Administrator** and navigate to **Manage Profiles → Certificate Profiles → X.509**.

Provide the following basic information:

* **Profile Type**: User
* **Sub Type**: New
* **Profile Name**: Identifier for the TSA profile
* **Validity**: Certificate validity period
* **Issuing CA**: Select the appropriate issuing CA
* **Signature Algorithm**: Select the preferred algorithm

<figure><img src="/files/MiYoH2cRRbU3JrM1xlxJ" alt=""><figcaption></figcaption></figure>

Add the required **Subject DN details**:

* Common Name
* Country
* Organization
* Organization Unit

<figure><img src="/files/bRDimug0Zm6B9MvaCwzb" alt=""><figcaption></figcaption></figure>

Configure **X.509 Certificate Extensions**, such as:

* Basic Constraints
* Key Usage
* Enhanced Key Usage
* Authority Key Identifier
* Subject Key Identifier
* Authority Information Access
* CRL Distribution Points
* Certificate Policy

<figure><img src="/files/Cg424iRTK0PQXWux0fwA" alt=""><figcaption></figcaption></figure>

Click **Proceed** and authenticate to complete the creation.

<figure><img src="/files/u1nWTPPnHRvo1zKjAycj" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/SRw2zqzNnHezqBTCxKKr" alt=""><figcaption></figcaption></figure>

The profile will be available under **View All**.

<figure><img src="/files/ecAbKbD1zdiSScXFT3Ul" alt=""><figcaption></figcaption></figure>

## Sign CSR – TSA Certificate

Log in as an **Officer** and navigate to **Manage User Certificate → Sign CSR**.

* Upload the CSR generated earlier
* Select the **TSA Certificate Profile** created by the Administrator
* Choose the **Certifying Authority** (Root CA or relevant issuer)

Click **Proceed** to view CSR details, then authenticate as an Officer.

![](/files/68CnHnHOlWP2e2NGheJb)\
Once authenticated, click **Sign CSR** to generate the signed certificate.

![](/files/A9C7BywBRJ8vO2qEJxkF)\
The signed certificate will be ready for download.

<figure><img src="/files/Sza2hPFzeJO76fKmiL6I" alt=""><figcaption></figcaption></figure>

Signed Certificate

<figure><img src="/files/LkMC6P0dfOc2xqJJF1du" alt=""><figcaption></figcaption></figure>

## Manage TSA Certificate

Log in as **TSA Admin** and navigate to **Manage Timestamping Signer → Manage TSA Certificates**.

<figure><img src="/files/EN32N2D4keQ6bnypUGzr" alt=""><figcaption></figcaption></figure>

Click **Import Issuer Certificate** and upload the Root/Issuer CA certificate. A success message will confirm the import.

<figure><img src="/files/1Hn7Vk40eCiFvh9R1VPH" alt=""><figcaption></figcaption></figure>

Click the **Import** action for the TSA Auth Certificate and upload the signed TSA certificate.\
A success response will be displayed upon successful import.

<figure><img src="/files/GXAJniQG7QUYfEmsaTwB" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/nOMwFtzqckeLX9yLN9Gi" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/CWcIweKk0YJWR9Q5nwqz" alt=""><figcaption></figcaption></figure>

The signed TSA certificate will now be visible under the TSA Certificates list.

<figure><img src="/files/hPXQoOk0yXG9w8AwNplP" alt=""><figcaption></figcaption></figure>

## Client Registration – TSA Services

To register clients for TSA services, log in as **TSA Admin**.

Go to **Client Registration → New Registration** and provide:

* Client Name
* Username
* Password
* Confirm Password

Click **Save and Proceed**, then **Submit**.

![](/files/64dnNSlJfdqNq4kLRUKz)

![](/files/2SLLuEAJi4MY3hpqWP17)\
A confirmation message will confirm successful client registration.

![](/files/S5OLJbP9Say6K929kygi)\
Registered clients will be listed under **View All**.

<figure><img src="/files/kLfvdm9abJxjEats9Goz" alt=""><figcaption></figcaption></figure>

## Manage NTP Devices

To configure NTP devices, go to **Manage NTP Devices → New NTP Device**.

<figure><img src="/files/EGfEmUfi2Otb88fAD08M" alt=""><figcaption></figcaption></figure>

Provide the following:

* NTP Device Name
* NTP Device URL

<figure><img src="/files/gaQm4M9WtkKxtW6ptfnK" alt=""><figcaption></figcaption></figure>

Click **Proceed** to add the device.\
A confirmation message will confirm successful addition.

<figure><img src="/files/UxE3iMSVJFtDR6gGNiPT" alt=""><figcaption></figcaption></figure>

## Manage Policy

To define TSA policies, go to **Manage Policies → New Policy**.

<figure><img src="/files/YcdDAsYRmMa7zvFbP87M" alt=""><figcaption></figcaption></figure>

Provide the following details:

* **Policy ID**
* Select the **Signed TSA Certificate** from the dropdown
* **NTP Server Name**

If you select **Mark as Default**, the policy will be applied to all clients by default.

![](/files/FMPv9cxZVwyPCrwvwhR6)\
Click **Proceed** to save the policy.\
A success message will confirm policy creation.

<figure><img src="/files/joufyZudkVSKmDw4KqVP" alt=""><figcaption></figcaption></figure>

## Time Stamping endpoint for TSA requests

<figure><img src="/files/LKiXGRMMCcT9o649g0qU" alt=""><figcaption></figcaption></figure>


# Previous Release Versions

This section serves as a reference for all previous emCA versions. It includes release notes, release dates, key enhancements, user manuals, and version-specific API upgrades, enabling users to easily track changes, improvements, and documentation across different releases.


# V4.3.1

## Release Notes for emCA  v4.3.1

**Release Date: 10th Jul'25**


# Manage emCA

This section explains daily operations after installation. It covers creating root and issuing CAs, configuring OCSP and timestamping, and defining certificate profiles and lifecycles. It includes user and role management, keystore/HSM administration, external integrations and APIs, and protocol setup (ACME, EST, SCEP, CMP).

You will also find mail/notification setup, reporting, and key-recovery procedures. All actions are role-based, can require M-of-N approvals, and are fully audited.


# Creating a Root Certificate

## **Enroll**

Users with the Officer role can enroll a Root CA from the CA Certificates UI.

The workflow generates an HSM-backed CA key pair and either issues a self-signed root certificate or produces a CSR for external signing, as defined by policy (with M-of-N approvals if enabled

{% hint style="info" %}
Note: CA certificates and OCSP certificates are both generated using this UI.
{% endhint %}

<figure><img src="/files/rdmkvohTxYXcj876Nr16" alt=""><figcaption></figcaption></figure>

## Generate Key Pair

Click on "Generate Key Pair " to open the following dialog:

<figure><img src="/files/1rgZc0r31LtV6hPUlFda" alt=""><figcaption></figcaption></figure>

Enter the number of keys that you want to generate. In general, you will need 1 key for 1 CA and 1 more key, if that CA will receive an OCSP certificate.

Select the "Key Profile" you want to use from the first dropdown list.

<figure><img src="/files/8TXSFUlBukZqmvZNmdbK" alt=""><figcaption></figcaption></figure>

Choose the "Algorithm" from the drop-down

Select the "Signature algorithm". This will filter the element for the third dropdown list accordingly.

<figure><img src="/files/osl92YduDKdczZAYMOC3" alt=""><figcaption></figcaption></figure>

Select the "Key Algorithm" and "Key Size"

<figure><img src="/files/wvSPi55cAHsfU9XoDgNb" alt=""><figcaption></figcaption></figure>

Press "Proceed" to continue and authenticate the action via Username & Password or Hard/ Soft token basis.

<figure><img src="/files/8q2hwLKJ7KepqLqKO1u6" alt=""><figcaption></figcaption></figure>

Click on "Generate Key Pair(s)" to generate the keys

<figure><img src="/files/GRpmkpyCvgZ9TEqqbhRa" alt=""><figcaption></figcaption></figure>

After the successful generation of the key pair, click on "View all" or "+ New" to continue with the new Key Pair creation.

## Generate CA Certificate

After creating a key pair, select the "Generate Certificate" or "CSR" option available in the "Action" column of the created key pair.

<figure><img src="/files/Coyhvq00jqM5S0WmiF9R" alt=""><figcaption></figcaption></figure>

Click on  !\[A black flag on a white background

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAA0ADgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1yLzpYwwcDNP8uf8A56Ci0/491ovLuOxtJLiX7kYyaTdtwSuHlz/89B+VHlz/APPQVi6F4ysNemeO33Iy/wB7vW+rq/3WB+hqrCIvLn/56Cjy5/8AnoKnpAwJ4IOKQytL50UZYuDiin3f/Hu1FABaf8e61HqkSTabOkgypQ8VJaf8e60l/wD8eM3+4amfwsqO6PCZZ5dP1GYWkhiwxAxU8PiPVoGzHeyCquo/8hKf/eqvketEG+VCkveZ0M3jjV5YdgnZTj7wrqPhxqN3etN9qnaX615tXoPwv+9NWsFuZz6HoN3/AMe7UUXf/Hu1FQWFp/x7rSX/APx4zf7hpbT/AI91qSSMSxsjdGGDSkrpoadnc8u8M+F7PxDe3kl5uwj4AWujm+GmjtERGJFbsc1u6RoVvo7zNASfNbcc1qU7KySFrds80Pwun+0cXKeVnp3rsvD/AIatPD8BS3yWb7xNbNFNNpWE1cgu/wDj3aii7/492opDC0/491qeiigAooooAKKKKAILv/j3aiiigD//2Q==) to start generating a CA certificate.

<figure><img src="/files/WN5LjY1knXZeEFXqaIEa" alt=""><figcaption></figcaption></figure>

The above window opens after clicking on “Action”.

There are two different options available for generation:

* Certificate – use the key to generate a new CA certificate directly.
* CSR – use the key to generate a Certificate Signing Request (CSR).

Choose "Certificate" if you want to directly generate a new CA certificate. This option is applicable if the CA is "self-signed" or the "issuing CA" is in the same instance

Choose "CSR" if the issuing CA is not on the same instance. This is the case if ROOT and SUB CAs are not operated on the same system.

{% hint style="info" %}
Note: You can operate CAs using the appliance functionalities that have their trust anchored outside the Appliance using the option CSR.
{% endhint %}

<figure><img src="/files/kgFAIy15qc9JjHEM6XmJ" alt=""><figcaption></figcaption></figure>

CA Administrator created certificate profiles will be available under “Certificate profile” dropdown.

<figure><img src="/files/KtuQ4n7oriIjIFUrHBe1" alt=""><figcaption></figcaption></figure>

For "Subject DN Details", enter all Subject Distinguished Name (Subject DN) information for the CA as per the certificate profile selection.

Press "Proceed" to continue. You will be prompted to authenticate the action using your officer token/ username & password. Press "Authenticate" to proceed.

<figure><img src="/files/xykoqgDniW5jtE8bKhkc" alt=""><figcaption></figcaption></figure>

Officer is required to successfully authenticate and continue with “Create”.

<figure><img src="/files/8qCRgB6T881XxxEgdzAI" alt=""><figcaption></figcaption></figure>

The "Certificate" will be created and downloadable.


# Creating an Issuer CA Certificate

Issuing CA can happen in two flows in emCA. One is through external root, and the other is directly through existing internal root.


# Internal CA Certificate Issuer

Administrator shall crate a Profile under Issuing CA. These steps are covered under [Configure CA Certificate Profile](/getting-started/configuring-certificate-profiles).

## **Officer Login**

Officer can use this profile to Sing the CSR as displayed in the following interface.

## **Generate Key Pair**

Click on "Generate Key Pair " to open the following dialog:

<figure><img src="/files/gPakfBkN3J4Zk2wPBR1T" alt=""><figcaption></figcaption></figure>

Enter the number of keys that you want to generate. In general, you will need 1 key for 1 CA and 1 more key, if that CA will receive an OCSP certificate.

Select the "Key Profile" you want to use from the first dropdown list.

<figure><img src="/files/WfzvAKUlQcxClG5OT2fD" alt=""><figcaption></figcaption></figure>

Choose the "Algorithm" from the drop-down

Select the "Signature algorithm" from the third dropdown list. This will filter the element for the third dropdown list accordingly.

<figure><img src="/files/skECpiGVhzIwKIUOuK3S" alt=""><figcaption></figcaption></figure>

Select the "Key Algorithm" and "Key Size" from the fourth dropdown list.

<figure><img src="/files/DJ6Sasmd0tpydZ5Tjbjm" alt=""><figcaption></figcaption></figure>

Press "Proceed" to continue and authenticate the action.

<figure><img src="/files/wqNuVWFFjkYwK1JnP01x" alt=""><figcaption></figcaption></figure>

Click on "Generate Key Pair(s)" to generate the keys.

<figure><img src="/files/bPEdfrIhdfm7EAzuLTXP" alt=""><figcaption></figcaption></figure>

After the successful generation of the key pair, the success message as shown below.

Click on "View all" or "+ New" to continue with this new Key Pair creation.

## Generate CA Certificate

After creating a key pair, the user needs to select the "Generate Certificate" or "CSR" option available in the "Action" column of the created key pair.

<figure><img src="/files/rwsM6GJM74rADnzUvqUi" alt=""><figcaption></figcaption></figure>

Click on  !\[A black flag on a white background

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAA0ADgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1yLzpYwwcDNP8uf8A56Ci0/491ovLuOxtJLiX7kYyaTdtwSuHlz/89B+VHlz/APPQVi6F4ysNemeO33Iy/wB7vW+rq/3WB+hqrCIvLn/56Cjy5/8AnoKnpAwJ4IOKQytL50UZYuDiin3f/Hu1FABaf8e61HqkSTabOkgypQ8VJaf8e60l/wD8eM3+4amfwsqO6PCZZ5dP1GYWkhiwxAxU8PiPVoGzHeyCquo/8hKf/eqvketEG+VCkveZ0M3jjV5YdgnZTj7wrqPhxqN3etN9qnaX615tXoPwv+9NWsFuZz6HoN3/AMe7UUXf/Hu1FQWFp/x7rSX/APx4zf7hpbT/AI91qSSMSxsjdGGDSkrpoadnc8u8M+F7PxDe3kl5uwj4AWujm+GmjtERGJFbsc1u6RoVvo7zNASfNbcc1qU7KySFrds80Pwun+0cXKeVnp3rsvD/AIatPD8BS3yWb7xNbNFNNpWE1cgu/wDj3aii7/492opDC0/491qeiigAooooAKKKKAILv/j3aiiigD//2Q==) to start generating a CA certificate.

<figure><img src="/files/FxtManpbhdTS9vX85jup" alt=""><figcaption></figcaption></figure>

The above window opens after clicking on “Action”.

Certificate – use the key to generate a new CA certificate directly.

Choose "Certificate" if you want to directly generate a new CA certificate. This option is applicable if the CA is "self-signed", or the "issuing CA" is in the same instance.

<figure><img src="/files/JK7POhMIdW41VIyXnv4s" alt=""><figcaption></figcaption></figure>

CA Administrator created certificate profiles will be available under “Certificate profile” dropdown.

<figure><img src="/files/kxUwXAlv9f55IMS0WX9j" alt=""><figcaption></figcaption></figure>

For "Subject DN Details", enter all Subject Distinguished Name (Subject DN) information for the CA as per the certificate profile selection.

Press "Proceed" to continue. You will be prompted to authenticate the action using your officer token. Press "Authenticate" to proceed.

<figure><img src="/files/ppVSpLwAhYruUMVvkCP5" alt=""><figcaption></figcaption></figure>

Officer is required to successfully authenticate and continue with “Create”.

<figure><img src="/files/HJODe8DMi4Z45IRQyKl7" alt=""><figcaption></figcaption></figure>

The "Certificate" will be created, and the user is able to download the certificate.


# External CA Certificate Issuer

## Officer Login

Once the ‘Key Profile’ is created by the CA Administrator, login as ‘Officer’ to create Key Pairs and generate CSR.

## Generate Key Pair

Click on "Generate Key Pair " to open the following dialog:

<figure><img src="/files/qW52A3LeaWmc7cwMh95b" alt=""><figcaption></figcaption></figure>

Enter the number of keys that you want to generate. In general, you will need 1 key for 1 CA and 1 more key, if that CA will receive an OCSP certificate.

Select the "Key Profile" you want to use from the first dropdown list.

<figure><img src="/files/uvbD9IhzXwDcy4lb6T3H" alt=""><figcaption></figcaption></figure>

Choose the "Algorithm" from the drop-down

Select the "Signature algorithm" from the third dropdown list. This will filter the element for the third dropdown list accordingly

<figure><img src="/files/bJNk8MuAs19Sx9OFNiBq" alt=""><figcaption></figcaption></figure>

Select the "Key Algorithm" and "Key Size" from the fourth dropdown list.

<figure><img src="/files/oa6adlVx3z4J0G9xLSnM" alt=""><figcaption></figcaption></figure>

Press "Proceed" to continue and authenticate the action.

<figure><img src="/files/iiqBFvxJ1VY3BSUG9N7C" alt=""><figcaption></figcaption></figure>

Click on "Generate Key Pair(s)" to generate the keys.

<figure><img src="/files/ok2d9p7iIVaIT4Bz2Hpk" alt=""><figcaption></figcaption></figure>

After the successful generation of the key pair, the success message as shown below.

Click on "View all" or "+ New" to continue with this new Key Pair creation.

## Generate CSR

Click on Manage CA Certificate -> Enroll. The following screen will be displayed.

<figure><img src="/files/ujgB6IFF0q2oNTA2q2yw" alt=""><figcaption></figcaption></figure>

Click on Action icon![](data:image/png;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAeACsDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2J3IYBaPn9RQf9aK4Tx7rF7ompQXFrIQMDK54pN2C1zu/npGZ1GTXl4+KV8sR3woW7cV32g6jJquhxXUwAd+uKdhGsDkA0tIv3RS0ARn/AForjfGGhPr+rQWx3LGACWFdhK2xwab5wJzsGfWixVzzy7+FZ3qLe5JXvmu50nTBpGkRWitu2DrVv7R7UjTbhjFAidfuilpF+6KWgR//2Q==)in ‘Action’ column as shown in the above Figure.

The following page will be displayed.

<figure><img src="/files/y7lW9h8NQIlBeLa835Jn" alt=""><figcaption></figcaption></figure>

By default, ‘Certificate’ radio button will be selected. Please change the option to ‘CSR’.

The following options will be displayed.

<figure><img src="/files/2mHDIoSAsK7si6UYfK1T" alt=""><figcaption></figcaption></figure>

Select the ‘Subject DN’ from the drop-down. The following options will be displayed.

<figure><img src="/files/6a3bOrUcwLLPASdLSpHD" alt=""><figcaption></figcaption></figure>

Select ‘Subject DN’ - ‘Common Name’ from the drop-down.

<figure><img src="/files/Qegke3cLGexwqjTpfUTX" alt=""><figcaption></figcaption></figure>

Once the Common Name is selected under Subject DN, click on ‘+’ icon next to the ‘Common Name’ from the drop-down.

A new field will be displayed based on the selection made.

Enter the relevant details in the new field (‘Common Name’ in the current example) as viewed below.

<figure><img src="/files/QjGbLgunv82fcfpctG6J" alt=""><figcaption></figcaption></figure>

Follow the same process to add individual Subject DN details and their relevant values.

Once the details are added, click on ‘Proceed’ button. The following ‘Verify and Confirm’ page will be displayed.

The following ‘Verify & Confirm’ page will be displayed.

<figure><img src="/files/8jhqvk5pce7DEBKo8WFa" alt=""><figcaption></figcaption></figure>

Officer should enter the Username and Token pin and click on ‘Authenticate’.

On successful authentication, click on ‘Create’ button.

CSR will be successfully created as displayed below.

<figure><img src="/files/mo0uWZV7LrZcUCOqq7PO" alt=""><figcaption></figcaption></figure>

Clicking on “Download CSR” will download .csr in the system.

<details>

<summary>Submit the same CSR to the ‘Root Authority’ to get the X509 certificate.</summary>

</details>

To view the CSR created, click on ‘View All’.

Once the CSR is signed by the Root Authority, login as ‘Officer’ to Import the Signed Certificate.

## Import Issuer Certificate

To import ‘Issuer Certificate’, login as ‘Officer’ and click on Manage CA Certificate -> CA Certificates. The following page will be displayed.

<figure><img src="/files/ZTX3tFcV7XazLZ0rUm7r" alt=""><figcaption></figcaption></figure>

Click on ‘Import Issuer Certificate’ on the top right corner of the page.

The following pop-up will be displayed.

<figure><img src="/files/AmeAXvVCx9z2PEbpHZgj" alt=""><figcaption></figcaption></figure>

Click on ‘Choose File’ and upload.

Once the file is uploaded, enter the username and Token Pin of the respective officer and click ‘Authenticate’.

<figure><img src="/files/DxdcD26j6KqPJoVagYdw" alt=""><figcaption></figcaption></figure>

On successful authentication, click on ‘Import X509’ to import the certificate.

<figure><img src="/files/tMLJ8VA7RcXHahzgUaRN" alt=""><figcaption></figcaption></figure>

The Certificate will be imported successfully and the following success message will be displayed.

<figure><img src="/files/OTkzvvJtorjeB4cISQrb" alt=""><figcaption></figcaption></figure>

## Import CA Certificate

Click on Manage CA Certificate -> CA Certificates. The following page will be displayed.

<figure><img src="/files/LOYpvu20FnJMhZS0koxA" alt=""><figcaption></figcaption></figure>

To import CA Certificate signed by CCA, click on ‘Import  ![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABsAAAAcCAIAAAAfs1O6AAAAAXNSR0IArs4c6QAAAAlwSFlzAAAOxgAADsMBl6I51wAAAd1JREFUSEtj/Pf/PwNVARNVTQMZxvj///+PHz9Sbi4/Pz/Es0xA437+/EmhiUAT4M5i/PDhA9A4oA2UGAoxjg9sCPXDcSiYiC8cvz6+cuvVb8zwZRVT05HlRhZHDkecJr7aXlO4hdvWRIwV3cjfr84c/urT3+IpBpdBNpEBGNdAAEyVqODynKiJJ75DxX49uXnuzLlzt558+QUW+X5iYtScy0gaIIYAsx8QseBMNL+5uTkYPlzdPHfaipOvYX5nFTNPryu24+bGEhhQk/DH9dev3EYZHbP6W/OSnRVB3v/96uSUmsW3dWy92XA5Bb+J3NIK0ty83NKqNu7pnV3h0mBTPuw4eEUtJlYHh5EkpEdpaydFsCm/b91/xYwztEgwkUFCUQ1izoNXr3DnWVJMJC7n4zHx9++/cDO+Pr16/vzZW0+hAk9vnT1//urTr9jswJXCf1+Znz3prW+coww3A6u0ttiVnsIZl1CSDKtGcn+TOySVE5VnGP5+vX9o874HIHeImUX4anzd2V44F2YoyLh6dzFY/BCTZzAyEVDgz8sdzVGhoaFRtTte/kFRgJxncOVCbCaCDT2x7gSacUBhZBNHy3DiUjAhVaBwBNaN7OzshFTik4eYAKkLqd8CAAC3AI/6rCnHFAAAAABJRU5ErkJggg==)’ icon available in the ‘Action’ column corresponding to the respective CA Certificate as shown in the above figure.

The following pop-up will be displayed.

<figure><img src="/files/cYFegU4rXpAQRMh4kgsj" alt=""><figcaption></figcaption></figure>

Click on ‘Choose File’ and upload.

Once the file is uploaded, enter the username and Token Pin of the respective officer and click ‘Authenticate’.

<figure><img src="/files/k43K1fcbL2M4J1NV14Dh" alt=""><figcaption></figcaption></figure>

On successful authentication, click on ‘Import X509’ to import the certificate.

<figure><img src="/files/1Mkzpa7WlGJDSme8AfY8" alt=""><figcaption></figcaption></figure>

The Certificate will be imported successfully, and the following success message will be displayed.

<figure><img src="/files/p6V3wI8phlTwSVzimIDi" alt=""><figcaption></figcaption></figure>


# Creating a User Certificate

**Enroll**

Users with the Officer role enroll an Issuing CA under an existing Root or Intermediate CA.

The result of this UI is always both private and public key for a new user.

<figure><img src="/files/YMQ9IbVj2Lev4uFAXScS" alt=""><figcaption></figcaption></figure>

Officers can generate two types of user certificates:

* Soft token – storable in PFX, JKS or JCEKS keystores.
* Hard token – storable in ePass or eToken hard tokens.

**Soft Tokens** are software-based authentication tokens (e.g., keystore files).

This means that they do not have any additional requirements and can be stored and used directly on the user’s system.

Note:

It is highly recommended to enable enhanced security when importing Soft Token.

Enhanced security enforces the entry of the Soft Token password on use. If Soft Token certificates are imported without enhanced security, anyone with access to your browser also has access to your certificates.

**Hard Tokens** are generated onto some hardware token (e.g., secure USB device or smart card).

This means that 2-factor authentication is enforced as a token, and the system can be separated at any time.

emCA supports Hard Token which supports either ePass configuration or eToken configuration.

The following image is an example of a Soft Token UI:

<figure><img src="/files/DOvrA6beV7lwJXlgn5se" alt=""><figcaption></figcaption></figure>

An Officer can choose from all certificate profiles available in his/her group. Depending on the certificate profile additional insert fields will be loaded in.

<figure><img src="/files/46pbUIq7IOFnbrGoijCt" alt=""><figcaption></figcaption></figure>

**Viewing Certificate Profile Details**

To view the details of a certificate profile, click the "View" button next to it. This will open the profile in a read-only view as displayed above.

The fields displayed will depend on the selected certificate profile.

**Subject DN Details**

<figure><img src="/files/MavSlefuDKJ6ISUEdtE4" alt=""><figcaption></figcaption></figure>

For the Subject DN Details section, you must fill in all of the required fields. Optional fields can be left empty and will be ignored during certificate creation.

The information provided in this section will be used to generate the Subject Distinguished Name (Subject DN) of the certificate owner.

**Other Details**

<figure><img src="/files/r4RYbDWogyNNjsSxvBBM" alt=""><figcaption></figcaption></figure>

For the Other Details section, you can leave the subscriber ID field empty, or enter your subscriber ID if you have one.

Select the Key Algorithm and Key Size for the user certificate.

<figure><img src="/files/xHN08BXb2jeLwxiTaZJo" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Note: The Key Algorithm of the issuing CA does not limit the Key Algorithm of the user.

It is however recommended to avoid mixed-cryptography hierarchies because they require additional maintenance effort without real benefits.
{% endhint %}

For Soft Token, select the Keystore Type from the following options:

<figure><img src="/files/FtP6eFZnYn7kzIstVeDQ" alt=""><figcaption></figcaption></figure>

For Hard Token, select the Keystore Config from the following options:

<figure><img src="/files/hHHbUhrmwGfuklGtA6IE" alt=""><figcaption></figcaption></figure>

For Soft Token, insert the password for the Soft Token into Password and confirm it in Confirm Password.

You can inspect the given password policy by hovering above

{% hint style="info" %}
Note: Soft Token Password is only intended as a One-Time-Password (OTP). It is recommended to change the token password after receiving it.
{% endhint %}

For Hard Token, insert the PIN for the Hard Token into Token PIN.

{% hint style="info" %}
Note: The Token PIN is the already established PIN on the Hard Token of your choice.
{% endhint %}

Click "Proceed" to Authenticate.

<figure><img src="/files/OGMCYCBESBfvukk7836I" alt=""><figcaption></figcaption></figure>

You will be prompted to authenticate using Username & Password or Token.

Authenticate using your Officer token and proceed by pressing Authenticate.

Click on "Create" to create the new user certificate.

Depending on the Key Algorithm and Key Size this may take several seconds.

Upon completion, a summary will be displayed. For Soft Tokens, this summary includes the following element:

<figure><img src="/files/dEZ1xycFko7FgzVgIWfh" alt=""><figcaption></figcaption></figure>

Click on "Download Certificate" in order to retrieve the Soft Token of your choice.


# Managing CA Certificates

Officer can create and manage CA Certificates in this section

## Generate CSR

For CSR, the following dialog will be shown:

<figure><img src="/files/SCPWv3hge2LKBm2Kafqz" alt=""><figcaption></figcaption></figure>

Select the DN attribute type from the first dropdown and add it to Subject DN.

The following "DN attributes" are available:

<figure><img src="/files/DbdZu5EbUtaJAZylfLaQ" alt=""><figcaption></figcaption></figure>

Every added DN attribute is marked as required. Remove DN attributes by clicking !\[A white square with black lines

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAdAB0DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD02YebM7PydxAz2pnlL/dFTEfO/wDvn+dVb65ktI1aK0muiTgrFjI9+aAH+Uv90flQZ5LXiI7Q3UU63dpoEkeJ4mYZKP1X2NR3Y5T8aALYXLP/AL5/nS7abdS/ZJim3cGO70xmoft//TMfnQBY21UvRgpn3p/2/wD6Zj86nht11BN7krt4AFAH/9k=)next to them. Click !\[A white square with a black and blue plus symbol

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAmACUDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1eSR5ZX+dlVW2gKcU3af+e0v/AH1TQf3kv/XQ0uaAF2n/AJ7S/wDfVG0/89pf++qqx6jBLfyWalvOjXcwI4x9as5oAa989mQpJkDdM9RRVXUD80f0NFAFknEsv++aqaiuoSRoNNmhicH5jKuQRVlz++l/3zSZoA5S2j1o+IbpY7q2F2Ixvcp8pHsK6ezFylqgvZEknH3mQYBpqWsEd09ysYEzjaz+oqbNHQOpXvjkp9DRSXZyU+lFAFq+X7NMzHlXORVX7Uv900UUAH2pf7po+1L/AHTRRQBbgsheR+YzYHYCiiigD//Z)next to Subject OID’s to add custom DN attributes.

<figure><img src="/files/0FQC3Noo1IwPrVCecFEq" alt=""><figcaption></figcaption></figure>

Enter the OID and value of the custom DN attribute. Remove attributes by clicking the !\[A white square with black lines

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAiACIDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1NgJpJGlG7DFRnsKPJh/55J+VJnDy/wC+aM0AHkw/880/Kl8mLtGoPqKOR1FIGoArNqU6MVDjCnHNFVpP9Y31NFAF8n97L/vmmTx+fbvEHZN4xvXqPcUrnE8o77zSZoAp6dpp093Y3tzcbhjErZA+laG6o80bqAKTn9431NFOaJyxIUkE0UAXdX+WZCOCRzjvWfub+8fzoooANzf3j+dOjJMqgkkEiiigDpFUBQABjFFFFAH/2Q==)icon.

Click !\[A white square with a black and blue plus symbol

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAApACcDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1eSR5ZXAdkVTtAWm7W/57y/8AfVNB/ezf9dDTs0AG1v8AnvL/AN9UbW/57y/99VC13Alytu0qidxlU7kVNmgBGne1G8uzr0Iaiob0/wCjN9RRQA8nE03++arajdXFrbeZaWpupM42A449anY/v5v980ZoA5CfU9QbxFb3DaUy3CoQsO7lh65rpdMvbq8idryyNowbAUnOR60yXThLrEN+ZSGiUrsx1/Gru7NC2B7kd2c25+oopLo/uD9RRQBJMDHcyhuMtkUzcPUVPrPRKyaAL+4eoo3D1FUKKALro0w8uMZY80VPo3V6KAP/2Q==)next to SAN Details to add Subject Alternative Name (SAN) attributes.

<figure><img src="/files/1wSqZGMqY3EPaMN5ifkH" alt=""><figcaption></figcaption></figure>

Select the type of SAN attribute from the dropdown list.

A new text field will appear next to the list. You can insert the value for the SAN attribute into the text field. If you want to remove SAN attributes, just click the !\[A white square with black lines

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAsACwDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1SX/SJ5BJyqHaF7U37PB/zzWlzief/fpc0AN+zwf88xR9nh/55rTs0Z5oAb9nh/55io2vpLRvKHzAdM9qmzWfe83J+goAuk/6RP8A79LmmOcXM/8Av0ZoAp32uafpkqxXk/luwyBjtU9lfW+oW4ntZPMiJxuxiia1trh908EUrDgF1zTooo4E2QxrGn91RgUICbNUbvmc/Sreap3R/fH6CgC3IcXM/wDv03NTaqgixKnDNwazvtD+tAFvNLmqf2h/UUCd/UUAW81VuATKSBmk89/UVt2ttEIFyoJPJJoA/9k=)icon next to them.

Press "Proceed" to continue. You will need to authenticate the action using your Officer token and then press Authenticate.

Click on Create to generate the CSR.

Upon completion, the following view will be displayed:

<figure><img src="/files/ucfStY85Gxo80JpT0f9u" alt=""><figcaption></figcaption></figure>

Click "Download CSR" to download the CSR.

## CA Certificates

An Officer can manage the CA certificates in his/her own group from this interface.

<figure><img src="/files/trddt1xGU5HBx2wNnOuw" alt=""><figcaption></figcaption></figure>

To import an External CA certificate into the emCA Application, click on "Import Issuer Certificate".

Please note that only the CA certificate will be imported, not the CA key.

<figure><img src="/files/SrUGlgnrnZkKfDtDRzBC" alt=""><figcaption></figcaption></figure>

If you want to export the entire table to an XLSX file, click on "Export to Excel". The file will be automatically downloaded to the standard download location of your operating system.

Import Issuer Certificate

To import a CA certificate !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAfABsDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19V3AszMOT3pvmW//AD8L/wB/BVLXGK+HL8qSCI3wRXEX2nWWnadDPH4anuolhV5rgzsASRzgZpXHY9HQRyDKSlh7Nmq8rukrKrtge9YXgm3tWimv9MBjsrkDEBYkxuOD1rbuP9e1Nom4ajavfaNd20RAklRlUnpk1h6jNq9h4OeN9Oikkjj8p1STPyYxuH+FdRD9w/U04gEEEZB4pNFJnnnwwvL0wy2iWwNkrFmnJxg+gHeu1uP9e1Wra1gs4vKtokijyTtUYGTVW4/17U2yUj//2Q==) in response to a CSR, follow these steps:

1\. Click on "Choose File" to select the CA certificate that needs to be imported.

2\. Click on "Import X509" to upload the certificate.

3\. You will be prompted to authenticate the action.

4\. Use your Officer token to authenticate and proceed by pressing "Authenticate".

5\. Click on "Import X509" again to complete the upload process.

<figure><img src="/files/slxIilLEO85wIabTfV45" alt=""><figcaption></figcaption></figure>

View Certificate Details

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAZAB0DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2FEDLk5zk96iuLmztMfabiOHd03ybc/nT3MotJDAAZcNsDdCe2a8qs726U6nPfWb3mslvL2v96BccMintn0pAeqQS211H5lvKkqf3kfcP0pl18m3aSM5715nosuqQeJdPWxQC6kjBvok4TGerAcA4/WvTL3+D8adhXJ4/ufif51VvtG0/UmDXlrFK4GA5GGH4jmon/wBY31NJQMtWWnWmnRlLO3ihU8nYuM/U96S9/g/GqopG6CgD/9k=)to view the CA certificate details:

<figure><img src="/files/8lN4blXaQRnX3TKwamKt" alt=""><figcaption></figcaption></figure>

Download Certificate Details

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAgACMDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BEDgklup70rIiKWZmAAyTu6UsP3D/vH+dZPiXXbTRLEm8WbbMrIrIm4A47+lJuwLUn07VtN1aSRLG7EzRffCseKv+Svq3/fVeS+BNdtNF1O5N0JSbjCRiNNxJzXrincoOCMjoaYupQnZ0mZVdgB70Ul1/wAfD/57UUDL0X3D/vH+deaa38QJHurvTrrTrea2WQxsCxyQO/1r0iOVFBDOoO48E1VfTdJkdne1tGZjkkoMmlYDy7S9S0/Rrzz9EtzqF0csPP8AlEC+g9T716F4S1+5161uHu4Ehlhk2FVOavf2XpA6WloPogqxbx2dopW3WGJSckIAMmmIr3X/AB8P/ntRSXDBp2IIIooGf//Z)to download the user certificate as

<figure><img src="/files/sdfuRZdmYbO7FduqK3l7" alt=""><figcaption></figcaption></figure>

Select the export format of your choice and click Download to start the download of the user certificate.

The user certificate will be downloaded to the standard download location of your OS.

**CSR Creation Using Existing Keypair**

Click on !\[A black arrow in a circle

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAfACEDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19E3liXb7xHBpXRI1LPKyqOpLYApYujf7xrmL3TLzxJ4glhvvOh0m2ACoDt89j7+lIDoYprafPlXSyY5O2QHFPTy5Y98UxdexVsiuA8Q6GulT+X4d0m9inAyJ4XyjZ6giun8G209p4Ygiu4mimG4srDByTTWonoW/Pl/56N+dFMooGacXR/8AeNeY3NzqJ1m9nuJ79tOScx7rdsmM/T0r0pbiOMurEg7j2pqSWkW7y0Vd5y2Fxk+9LrcOljmbrxUb2zXT9AjuLi7kXYJmQqE9ST610unWstnpcME8zTSomHkY5LGnJNbRAiNQueu1cU43kRBG4/lTEZ9FFFAz/9k=)to create a new CSR based on the same key. This option is only available for CA keys with pending CA certificate requests.

You will be forwarded to the following CSR creation UI:

<figure><img src="/files/Myp0Z0lcuKbFYSEwUFpX" alt=""><figcaption></figcaption></figure>

You will have the option to edit the new CSR before creating it.

Click "Proceed" to continue.

You will be prompted to authenticate the action.

Authenticate using your Officer token and proceed by pressing "Authenticate".

Click on "Create" to generate the new CSR.

## Revoke/ Suspend

An Officer can revoke CA certificates in his/her own group manually, if necessary, using this UI.

Revocations of CA certificates may become necessary if keys have been compromised.

<figure><img src="/files/j3XjHtjqGTk790TTxx28" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left. The following search criteria are available:

* Serial Number – the serial number of the CA certificate
* Common Name – the common name (CN) of the CA certificate
* Issuer Name – the CN of the issuer (= CA) of the CA certificate

To search for certificate information, you can enter search criteria in the appropriate fields. For all search criteria except the Issuer Name, you can enter the desired search value in the right field. However, when you search using the Issuer Name, the right field changes to a dropdown box. From this dropdown, you can select the name of any existing Certificate Authority (CA).

The image below illustrates an example of how to filter search results using a specific Issuer Name.

<figure><img src="/files/Y9giYeyPq3hFi7b3Ahuo" alt=""><figcaption></figcaption></figure>

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAoAC4DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19EMhcl2HzEcGneT/ALb/AJ0Q/wAf+8aS6uobK2ee5kWOJBlmY9KAF8n/AG3/ADo8n/bf865KPxxdardOmg6b58MX+snmbao96bJ44u9MkR9W09PsjnAntpN4z70Adf5P+2/51DdboUBR3yT3NOsNQttTtEubSVZYnHBFJf8A+rX60ASw/wAf+8a4b4oxXz2ds8ZY2Sn96F/vdifau5h6P/vGnTQxzxNFMiujDDKwyDSauNOx5bpeuXOjeD4ZNMto50cslyCMlG7E4rL0pZU8O6tLdAraSgbA3QyZ4213kngSK1uZLjRr2WyeTrHjdGfwNIPAv22SN9a1CW7EZyIlARPyFN63FsYnwtivxLcSDIsCMYPQv7V39/8A6tfrUltaw2dukFvGscSDCqo4FR3/APq1+tNu4krD45UQuGYA7j1p/wBoi/56L+dFFIYfaIv+ei/nR9oi/wCei/nRRQAfaIv+ei/nVa8kR41CsCc9qKKAP//Z)to view the CA certificate details:

<figure><img src="/files/sH168qqw2JxT7Sple7qH" alt=""><figcaption></figcaption></figure>

**Revoke Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAiACkDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19UMjOS7jDY4NO8n/AKaP+dEPWT/eNct4w8VXelN9m0y3LTLhnkZflUHoPxpXCx1Pk/8ATR/zo8n/AKaP+dc1b+INY1PT4pdN05fPQ7bhJm27T7eopIde1u31iztNUsYIo7liAyPu6U7a2C+lzpvJ/wCmj/nR5P8A00f86looAih6yf7xrD8bQyS+HZfIheWQOh2ouWIBrch6yf7xqWgaOUt/GSxxxodI1AcAMfJNYev6zq0XiCw87T98iOWtigOJARwD6EV6PTWjRmVmRSy9CRyKOtxdLFfTmu3sYmv1RbgjLqnQH0q1RRQCMudmW4cBiOexpnmP/eb86KKADzH/ALzfnR5j/wB5vzoooAPMf+8350eY/wDeb86KKAP/2Q==)in order to start the revocation process for the selected CA certificate.

<figure><img src="/files/gVdFPOLyDK1OzToF3Sd9" alt=""><figcaption></figcaption></figure>

Select one of the following revocation reasons from the dropdown list:

<figure><img src="/files/r30rVYwgwleyiMP8RaGY" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Note: CA certificates cannot be suspended.
{% endhint %}

Provide an explanation for the revocation/suspension of the certificate in the Remarks section.

Select "Confirm" to proceed. You'll then need to authenticate the revocation by using your Officer token and pressing "Authenticate."

{% hint style="info" %}
Warning: Revocations are permanent! Revoked CA certificates cannot be recovered by any means.
{% endhint %}

Click on "Revoke" to proceed with the revocation process.

## Reinstate

<figure><img src="/files/34wpCMdUOOiptZ4rrNwQ" alt=""><figcaption></figcaption></figure>

## Search

The user can search for CA certificates in his/her own group. The user cannot inspect the certificates of other groups.

<figure><img src="/files/NHb2s1HmXrnXMO3JOlmn" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left.

The following search criteria are available:

* Serial Number – the serial number of the CA certificate
* Common Name – the common name (CN) of the CA certificate
* Issuer Name – the CN of the issuer (= CA) of the CA certificate
* Status – the state of the certificate

“Search for” changes according to “Search by” criteria.

For sample, inserting the “Search by” Status filter, click "Search" to filter for all matching user certificates.

The following image shows an example of a CA-specific filter:

<figure><img src="/files/t0YVfll2cuig3NzT9WRO" alt=""><figcaption></figcaption></figure>

User can view and download the certificates in the available formats.

## Sign CSR

An Officer can use the following UI in order to sign CA CSR from External CAs using existing CAs and certificate profiles from the emCA Application.

<figure><img src="/files/lCQQdNdwymuz27LUXtl2" alt=""><figcaption></figcaption></figure>

**Steps to Generate a Certificate**

1. Select the configuration type, either Upload or Text Area.
2. Click "Choose file" to select the CSR for signing.
3. Pick the desired certificate profile from the dropdown list.
4. Make sure that the certificate profile is of type CA, not Root.
5. Upon selecting a certificate profile, the Certifying Authority field will be filled with the correct CA.

<figure><img src="/files/LuByUzj9MknpjqczzCOR" alt=""><figcaption></figcaption></figure>

Click "View" next to the certificate profile to view it read-only.

Click on "View" next to the issuing CA in order to inspect the CA’s certificate.

To move on to the next stage, simply click on the "Proceed" button.

The following summary of the certificate request will be displayed:

<figure><img src="/files/Qpw2xlMC90mGlQ8ZGfSm" alt=""><figcaption></figcaption></figure>

The CSR Details section displays the data that can be obtained from the CSR (Certificate Signing Request) that has been submitted.

To download the CSR once again, please click on the !\[A blue arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAvACkDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2akpaZL/qXx/dNAFaXVLSF9jzKG+tWY5ElQMjAg9xXhviO5uV1uQCZwN/rXq3g53fRYy7Fjjqa7a+EVKmp33OSjifaTcbG/RRRXEdYlcnr/jNNIuGgdOSMZxXUyTRxffcL9a57xJoWn67aNhkEwHBBrfD8nP+8WhjW5uX3HqeRareC+1Bpx0LZrtfDvjdLK1jtCuTwK4vUNJudOvTbOhJJwpA613Hg7whBBtvNS2huqqTXtYn2XslzaroeTh/a+0909Cs5/tNqkuMbhmp6rxT24AjidcDoAanyPWvn2tT209Dzz4j39zaSKIJSgx2rgk13UVYMLl+K9l17w1DrZBlIGKxB8N7TH3hXrYbFUYU1GS1PNr4erKbcTlbXxpb+QDe2olmUcMRVGbVNY1Z2mtGcQg8Adq7j/hW9p/eFWrbwX9jjMdvMFQ9RVfWsPHWK1J+r13pI4TRLrVrfXrdLuRwrHoe9eoec/8AeNUIfCI+2x3E8gcp0re+xpXLiK8KjTR00KM4Jpn/2Q==)icon provided.

To make changes to the loaded CSR information, simply click 'Edit'.

If the CSR is missing any required data (indicated by \*), fill it in manually.

The Other Details section displays the key size generated by the CSR and the certificate options selected.

You will need to authenticate the generation of the certificate. Use your Officer token to authenticate and press "Authenticate" to proceed.

To finish generating the certificate, simply click on the "Sign CSR" button.

The following UI will be shown upon completion:

<figure><img src="/files/4UQu2UUb9VSG4IxA4zlQ" alt=""><figcaption></figcaption></figure>

To get the latest CA certificate, all you need to do is click on the "Download Certificate" button.

## Import PKCS12

An Officer can import existing PKCS12 keystores into the emCA Application HSM using the following UI.

The PKCS12 keystore must include a CA certificate; user certificates are ignored.

<figure><img src="/files/k6HA1Xd52FVg7dT282lv" alt=""><figcaption></figcaption></figure>

To choose the PKCS12 keystore from your system, simply click on the "Choose file" button.

Please enter the password for the PKCS12 keystore in the "Enter Password" field.

To select the key profile, you must choose an option from the drop-down menu.

To continue, please click on the "Proceed" button.

You will need to authenticate the upload using your Officer token. Press "Authenticate" to proceed.

Click on "Import" to upload the PKCS12 to the EmCA Application HSM.


# Manage User Certificate

Officer can create and manage User Certificates in this section

## **Revoke/Suspend**

An Officer can revoke or suspend user certificates of his/her group manually, if necessary, using this UI.

Revocations or suspensions of certificates may become necessary if keys have been compromised or access must be suspended temporarily for validation purposes.

<figure><img src="/files/KRmbILoUdyPsgk3BdMzU" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left.

The following search criteria are available:

* Serial Number – the serial number of the user certificate.
* Common Name – the common name (CN) of the user certificate.
* Issuer Name – the CN of the issuer (= CA) of the user certificate.
* Subscriber Id – the subscriber ID used to create the user certificate.

<figure><img src="/files/YExGRZTLP7vnhJW0pzA0" alt=""><figcaption></figcaption></figure>

For all search criteria except Issuer Name, the search value can be inserted in the right field.

For Issuer Name, the right field changes to a dropdown box from which you can select any existing CA name.

The following image displays and example for filtering for a specific issuer:

<figure><img src="/files/OSgKtQoPbiHWa2xpPuBa" alt=""><figcaption></figcaption></figure>

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAbAB8DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2FEDLkk5ye5ocRRrudto9WbFCsVhYqNxGSB615dDrP9p6pqF74hinmjs+Es06R84yV74/rSuB6gnlSjMbhx/svmm3ChIWZSwP1NeRJrF3ZW9rqtkPs1w87R+WgwlwvYlfXtkV6yssk+lxyyxmKR0VmQ/wk44p2EWIvufif51l6j4ZsNQuxd7XguwMedC21j9ex/GrBnkRmCtgAntSfaZf7/6CgZVsvClha3aXcvmXVygwkk7Z2fQdBWrdf8e7fh/Oqv2mX+/+gprzyOhDNkfSgD//2Q==)to view the user certificate details:

<figure><img src="/files/Y5utpadDgw4eilKPNzbP" alt=""><figcaption></figcaption></figure>

**Revoke the certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAhACcDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19EMhcl3GGI4NO8n/AKaP+dEP8f8AvGuQ8WeJtVsr2O30q2IVHUPI44cnooovrYDr/J/6aP8AnR5P/TR/zrnRqXiDUreK4020giQjEiXBIZWHX8Kfo2ras+uy6dq0durLEJFMRz3o62DzN/yf+mj/AJ0VLRQBFD/H/vGsHxlbXc9hatZWz3EkNwshROpAreiIG/JH3jT9y+o/OgDnIvEOqzSCI6DdQh/l8w4IQ+prn4pfEp8YPF9njFyYwjXG393sznd9a9D3L6j86Ny56ijrcOlgQEIoY5bHJ9aKXcvqPzooAy5/+Ph/rTKKKACiiigAooooA//Z)to open the following revocation dialog:

<figure><img src="/files/yhwhVNG1kcYfGCAenMUd" alt=""><figcaption></figcaption></figure>

Select one of the following revocation reasons from the dropdown list.

{% hint style="info" %}
Note:&#x20;

Suspension (=Certificate hold) is a special revocation reason.

Certificates which are suspended can be reinstated at a later point in time.

Suspended certificates will be automatically revoked after 15 days of suspension.
{% endhint %}

Please add a comment in the "Remarks" section explaining the reason for revoking or suspending the certificate.

Click on "Confirm" to continue.

You will need to authenticate the revocation using your Officer token and proceed by pressing the Authenticate button.

Click on "Revoke" to proceed with the revocation process.

## **Reinstate**

An officer can manually reinstate suspended user certificates for their group using this UI. Reinstated certificates will be removed from the next corresponding CRL.

<figure><img src="/files/gUzmQKPTNXmIiu3J3ovD" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left. The following search criteria are available:

* Serial Number – the serial number of the user certificate.
* Common Name – the common name (CN) of the user certificate.
* Issuer Name – the CN of the issuer (= CA) of the user certificate.
* Subscriber Id – the subscriber ID used to create the user certificate.

<figure><img src="/files/Dmi1BbcWsJPgC180mCGS" alt=""><figcaption></figcaption></figure>

For all search criteria, except Issuer Name, enter the search value in the right field. However, when searching for Issuer Name, the right field becomes a dropdown box containing all existing CA names.

The following image displays an example for filtering for a specific issuer:

<figure><img src="/files/laXGhFtQH0NBEreL6L5Z" alt=""><figcaption></figcaption></figure>

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAbAB8DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2FEDLkk5ye5ocRRrudto9WbFCsVhYqNxGSB615dDrP9p6pqF74hinmjs+Es06R84yV74/rSuB6gnlSjMbhx/svmm3ChIWZSwP1NeRJrF3ZW9rqtkv2a4edo/LjGEuF7Er69sivWVlefS45ZYzFI6KzIf4SccU7CLEX3PxP86y9R8M2GoXYu9rwXYGPOhbax+vY/jVgzyIzBWwAT2pPtMv9/8AQUDKtl4UsLW7S7l8y6uYxhJJ2zs+g6CtW6/492/D+dVftMv9/wDQU155HQhmyPpQB//Z)to view the user certificate details:

<figure><img src="/files/gh5tJWkCLmzcTGlzFvC7" alt=""><figcaption></figcaption></figure>

**Reinstate the certificate**

Click on !\[A black arrow pointing to the left

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAkACYDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD16JGkiVjK+SKf5J/56vRb/wDHun0ry+PxLqcWs6jp0F4kZlnOJrh/liX0FHWw7aXPUPJP/PV6PJP/AD1euIi8M62sAvtP8SyXT43Ip5RjW74V8QSaxBLBex+VfWzbJk9T6igk07kvAqlZG5Peilv/APVp9aKBk1v/AMe6fSsa48F6HczPLNZIzyHLEk8mtm2/490+lZ2v6Tc6rZqlneyWkyNuR16Z96TGi9ZWVvp1oltaxiOGMYVR2rlNDZbrx/qdxanMCIEcjoWpJNI8XXcf2SbU4Yohw0yD5mFdDoWh22g2It7fLMTl5G6ufWqW9yXtYsX/APq0+tFF/wD6tPrRSGTW3/Hun0qWiigAooooAqX/APq0+tFFFAH/2Q==)to open the following reinstation dialog:

<figure><img src="/files/VSQuGQy0Rdr3GcaKHCnb" alt=""><figcaption></figcaption></figure>

Please provide an explanation as to why the certificate was reinstated into the Remarks section.

Click "Confirm", authenticate with the Officer token, then press "Authenticate"..

To proceed with the reinstatement process, please click on the "Reinstate" button.

## Search

The user can search for their own group's certificates only. Certificates of other groups are not accessible. User certificates refer to non-CA and non-role owner certificates within the EmCA Application database.

<figure><img src="/files/hvJm4wCDgQJLMHkILARF" alt=""><figcaption></figcaption></figure>

Select a search criterion from the dropdown box on the left. The following search criteria are available:

* Serial Number – the serial number of the user certificate.
* Common Name – the common name (CN) of the user certificate.
* Issuer Name – the CN of the issuer (= CA) of the user certificate
* Status – the state of the certificate
* Subscriber Id – the subscriber ID used to create the user certificate

<figure><img src="/files/v6rYhMRa7Liblx7dzcal" alt=""><figcaption></figcaption></figure>

For all search criteria except Issuer Name and Status, insert the search value in the right field. For Issuer Name, select an existing CA name from a dropdown box.

For Status, the right field changes to the following dropdown box:

<figure><img src="/files/wDsxVI9g6ue7156pDJOS" alt=""><figcaption></figcaption></figure>

After inserting the search value or selecting the status filter, click Search to filter for all matching user certificates.

The following image shows an example of a CA-specific filter:

<figure><img src="/files/TBewfQ9JlAqmIf2Iajik" alt=""><figcaption></figcaption></figure>

Each entry in the table “Certificate Details” represents one user certificate.

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAmAC0DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19E8wsS7/AHiODT/JH99/++qSHo/+8ag1TVbXR7J7q9kCRr+ZPoKG7AWPJH99/wDvqjyR/ff/AL6rjbXxZrOuCW50uzgt9PizumuCST9AKiPjm+00xzajDbXVhKdq3Fo2cH3B7+1AHb+SP77/APfVVrotCVCO/PvT9P1G21SzS6s5BJE44Ipl/wDeT6GgCxD0f/eNcN8TdIvruGC8t98sEIIeNf4f9qu5h6P/ALxqQgMCCAQeoNJq407HlNpqept4Wgj0FlcKhiuoAoLj/aA96zTbS6P4Vuor8eXLdyL5MB+8MdWI7V6XeeDNJup2njie2nbrJbuUJ/KlsfB+k2U63Bha4nXpLOxc/rT3FsY3w20i+sNPmuLotHFcEGOFu3+1+NdTf/eT6GrgGBgdKp3/AN5PoabdxJWHfalhd1KkncelL9vT+61FFIYfb0/utR9vT+61FFAB9vT+61V7mZZypUEY9aKKAP/Z)to view the user certificate details:

<figure><img src="/files/9IiwXEbuBKaHmeMt4x8K" alt=""><figcaption></figcaption></figure>

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAuADMDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19VaR3/eMMHAAp3kn/nq/50Q/ek/3qloAi8k/89X/ADo8k/8APV/zqprs8ltot1LC22RYyQfSvOfA2ualdeJUhuLuWWNwcqxyKI6uwPRXPUfJP/PV/wA6PJP/AD1f86looAzpZpY5WUSHANFMuP8Aj4f60UAX4fvSf71S1FD96T/erI8VeIT4c05blYPNLNtxnFJuwJXOb8a+JtV02SaxksYvsk67UmycmuF0XV5dD1JLyCJZJFyArdDmuquvH9prUf2PVNO/0eQ4Lg8p7iqUVnpPhqQ3888eotuzbQof1anHR3Y5aqyPRvDl/qGpaYtzqVsls78qik9PWtevObb4oyTXMUX9n4DsF69K9EjbfGrYxuGab7krsZtx/wAfD/Wii4/4+H+tFIZfh+9J/vVl+JfDqeI7FbaSdoQG3blGaum5EEsilSfmpft6/wBw0mrgnY4n/hVEH/QSm/74FPg+FkNtOkseoyblORlARXZ/b1/uGj7ev9w0wOak8BGdo/NvztSTzMLEASa66NNkar12jFVvt6/3DR9vX+4aA8ytcf8AHw/1opsreZIzAYzRQB//2Q==)to download the user certificate as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/fxCokHF8dxy5cyvRaCxQ" alt=""><figcaption></figcaption></figure>

Select the export format of your choice and click "Download" to start the download of the user certificate.

The user certificate will be downloaded to the standard download location of your OS.

## Sign CSR

Officers can generate user certificates based on a Certificate Signing Request (CSR) manually using the following UI.

User certificates are any non-CA and non-role owner certificates in the emCA Application database.

The result of this UI is always just the public key for a new user.

The private key can be stored independently from the PKI.

<figure><img src="/files/zPklwvWKSrZ2umpuTE45" alt=""><figcaption></figcaption></figure>

To begin, choose the configuration type as "Upload". Next, click on "Choose file" to select the CSR.

Once you have done that, select a certificate profile from the dropdown list. This will automatically fill in the correct issuing CA in the "Certifying Authority" field.

<figure><img src="/files/vd6wVfFtdiAEXDjDRXVl" alt=""><figcaption></figcaption></figure>

Click on "View" next to the chosen certificate profile to inspect the profile in a read-only view.

Click on "View" next to the issuing CA in order to inspect the CA’s certificate.

Click "Proceed" to continue to the next stage. The summary of the certificate request will be displayed.

<figure><img src="/files/M7JOLwRimdAVLVehRnu6" alt=""><figcaption></figcaption></figure>

The "CSR Details" section displays information that can be obtained from the given CSR.

Click on !\[A blue arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAmACEDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2aqt/fwadbma5cKg7mrOcVynxAkjfw86h1Jz0BrSjDnmoszqz5IORsaX4hsdXdktZQzDtWnXlHwxZE1GUswX6mvVlZXGVII9q1xVFUanKiMPVdWHMx1FFFcxuMkXfGyg4yMZryHxppWqabdO0srS2shyD6V0HjnxTfaNqKxWpAUiubi8cz3hMGrIsluwweORXq4OhVhaotUzzcVVpz9x6MxtEt767vVh08sHY8kdq9s0Kwm07TkhuJfMk6kmvMU8Q2mljyvDcDNK/JLDmp9P8Y64dTt47pCscj4JIrXFU6lfZWX4meGnCjvqz1jNFZn22T1oryfZSPS9rEp654StNcuBLOSGFZn/CttO/vH8qKK0hiKkVZSIlRpyd2iW3+H9naSiWCQq474q0PCETTRSTTFxG24DHeiih16j3YlRgtkbX2KOiiisueXc15Uf/2Q==)in order to download the CSR again.

Click on "Edit" in order to change the information loaded from the CSR.

If not all required data (marked by \*) is loaded from the CSR, you will need to fill it in manually.

"Other Details" shows the key size that was determined from the CSR as well as the chosen options for the certificate.

You will need to authenticate the generation of the certificate. Use your Officer token to authenticate and press "Authenticate" to proceed.

Click "Sign CSR" to complete certificate generation. After successful signing, the following message will appear.

<figure><img src="/files/zwYcVKCIojXO3S7I4NAH" alt=""><figcaption></figcaption></figure>

Click "Download Certificate" in order to retrieve the new user certificate.

## Bulk Sign CSR

<figure><img src="/files/Qx69c4AWTnFQlKRSlIkV" alt=""><figcaption></figcaption></figure>

## **Manually Authorize Certificate**

If a certificate profile has "Manual Authorization Enabled," an officer can review and approve or reject any certificate requests using this UI.

<figure><img src="/files/5bnmyV6q4autFzAvaXpM" alt=""><figcaption></figcaption></figure>

Click "Export to Excel" to export the entire table to an XLSX file. The file will be downloaded to the standard download location of your OS.

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAkACoDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BE37iWb7xHBp3kj+8/8A31RD0b/eNZHiTxPaeG7QPPmSd/8AVxL1b/61DdgNfyR/ef8A76o8kf3n/wC+q4ka14gk0k6xe3Vvp1k/3EEPmMAehPtTbXx1c6ZexW+uCGa2nG6K8txhWB74o8gO48kf3n/76qg8siuwDtgHHWtCORJolkjYMjDKkdCKzZP9a/1NAGjD0b/eNcD8RPC93eTrqlkrTbU2yRDkgDuBXfQ9G/3jUlJoaZ5FfyXev2kYsNQRICqrPZzSCPy3HfnqKrXGnyaobDRtKzdtbA+bMo+RWPUZ9BXq11oOl3zh7mwt5GHcoKtW9pBaR7LeGOJfRFApiK2h6b/ZGj29l5hkMS4LHuahk/1r/U1q1lSf61/qabd9QSsTNcvFI6rjG49RSfbZf9n8qKKQB9tl/wBn8qPtsv8As/lRRQAfbZfRfyqBjuYk9Sc0UUAf/9k=)to view the user certificate details:

<figure><img src="/files/9IZYsr7DWmZHvrAfbBA8" alt=""><figcaption></figcaption></figure>

**Download Certificate**

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAhACQDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BE3gks3U96d5Sj+Jv++qIvun/eP86oa3rdlolqJL+Ro0kyqkIW5x7UmwQtnqum6hcSW9perNLH99Fc5FXvKH95v++q8h8G61Y6N4hubu9lMcMisFIUnJJ44FevQyrPCkiZ2uAwyMHFPomHWxVuWaOUKjsBj1opL3/Xj/AHaKALcX3T/vGvP/ABB49gNzeaXd6UJ4FcxtmTr7j0NegREbT/vH+dZVx4S0O6uHnn06B5ZDuZjnJNK2oHmlg2jaRere2wfVZCd0FsBgxD1f1Ir0Hwt4ofxDJcxy2TWrQY4Y8nNWE8H6DE26PToUbplSQf51dsdJsdNeR7OBYmkxvYEktjp1qriEvf8AXj/doovP9cP92ikMim/1z/7xqOiigApaKKAENFFFAH//2Q==)to download the user certificate as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/17sbRIfv8Q1TclFxd9bw" alt=""><figcaption></figcaption></figure>

Select your desired "export format" and click Download to obtain your user certificate. The certificate will be automatically saved to the standard download location of your operating system.

**Approve**

Click on !\[A checklist in a box

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAApAC0DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD12JZJIlYysM0/yX/57NRa/wDHun0rN1nxLZ6KwS48zzXHyKFzuPpSuFjS8l/+erUeS/8Az2asG78Uz6dpUF3d6fIGmPEackD3rP8A+FiL/wBAy5/75NMDrvJf/ns1V7mSWBgBITkd6g0HWxrloZhBJDg42uMVNqH+sX6UWC5Ztf8Aj3T6Vi+JNZtNMeEXVi1xIx/ckLn5q2rX/j3T6VieJ9VvtOktBZaat4JHw5IzsHrSe6Givf8AiO50nSILnUtOaaWZv9XGudg96y/+Fhwf9AK5/wC+P/rVveIdW1HT7KCSw037XI/3kx92sD/hK/EX/QtfpR1YuiOm8Oa0ut2TTpZyWoBxtcYzVnUP9Yv0qr4b1G91KyaTULD7HIDgJ61a1D/WL9KpiRZtf+PdPpUtRWv/AB7p9KmpDCiiigAqhqH+sX6VfqhqH+sX6UAf/9k=)icon to open the following approval dialog:

<figure><img src="/files/DTBqDo8TzIZMmxI3eUfB" alt=""><figcaption></figcaption></figure>

Before approval, click "Edit" to correct CSR details if needed.

To validate the CSR, click on the "Approve" button. If you want to reject the CSR instead, click on the "Reject" button.

After approving, you will need to authenticate the action using your Officer token, then proceed by pressing "Authenticate".

To finish the approval action, simply click on the "Confirm" button.

## **STC Requests**

If a certificate request with CT Logs Enabled and Manual Process Type is created, an Officer can import a response, view certificate, and download certificate using this UI.

{% hint style="info" %}
Note: Signing Certificate Timestamps (SCT) is only relevant for public CAs with abide the Certificate Transparency rule defined in RFC 6962.
{% endhint %}

<figure><img src="/files/ynzOTzYuMlJ2geQFWZRn" alt=""><figcaption></figcaption></figure>

Click "Export to Excel" to download the entire table as an XLSX file.

**View Certificate**

Click on ![](data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAfACQDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BEDgkls5PeneUvq3/fRoi+6f94/zrhNd8W3d/r40XSZvs0asVmucZYY64+lHkB3flL6t/wB9Gjyl9W/76Nea3d7HFqy6fpmr3sk3l74roXO9WfGdrL0roPBXi99eElneqFvYRkso4cdM+xoWobHQXLNHKArMBj1opL3/AFw/3aKALcX3T/vH+dctr/gw3epLqukypb3ynLK4+ST610qXEablZsEMe1O+1Rf3v0NAHn8Hg/UIrmR7PS4LS4cEee9xvRM9Si4z+ddR4Y8K23hu2YK3nXMn+smI6+w9BWx9qi/vfoaPtUX979DQBWvf9cP92im3UiySgqcjFFAH/9k=)to view the user certificate details:

<figure><img src="/files/2A7kZ2WgHpoajKCLUFMk" alt=""><figcaption></figcaption></figure>

**Download Certificate**

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAkACgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2BE37iWb7xHBp3kj+8/8A31RD0b/eNJcXMNrEZbiVIox1Z2wB+NAFeS8sorkW8l4izHpGZMMfwqz5I/vP/wB9V5D4iuYJvHwnjmR4vNQ+YrZXHHevWrW9tr1SbW4imC8ExsGx+VC1jcHo7Cyx7ImYO+QP71FPn/1D/SigAh6N/vGue8QeJNAiM2las+7cvzpsJ610MPRv941yHiD4fDXdXkvv7QaHeANgjBxikxo4mTwss1wJtOuo30lssbljjylHUMPX+ddp4b8Q+F9Kgh07TZzukYAsUOXb1NUR8K2CFBrEoQnJUR8H6jNX4vh6kd1BKLiFDFIJP3cGCcds5ql2Jfc7Cf8A1D/Siif/AFD/AEopDKj3TxSuq4xuPUUn26X0X8qKKAD7dL6L+VH26X0X8qKKAEa7kdSp24PHSiiigD//2Q==)to download the user certificate as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/TRQGkSdGAaP79S7YwHdY" alt=""><figcaption></figcaption></figure>

Select your preferred export format and click 'Download' to obtain your user certificate. The certificate will be saved to the default download location on your OS.


# Manage Key Stores

The manage keystore feature in emCA allows you to check the status of connected HSMs when creating key profiles, view HSM device information, and see where the HSM is used while creating key profiles. This information can be helpful for troubleshooting HSM-related issues and for ensuring that you are using the correct HSM for your needs.

An officer can inspect the application's connections to various HSMs, as well as the details of the key pairs available in each HSM.

<figure><img src="/files/Ys2f2qEGk7vh3lC21pyY" alt=""><figcaption></figcaption></figure>

Click on !\[A black circle with white text

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAfACEDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD19E37iXb7xHBpXRI1LPKyqOpLYApYej/7xryvx5r91f66+nRSOttCwQqpxvJ60r62Gu56fDLb3BIguhIR12SA4/KpTFgH536eteLajH/wi+qwnSprqJwgdhKNpz6Y7ivXdD1IavolveYwZY8ke/eq3VyepH58v/PRvzoplFIZpw9G/wB415h478NXVrrTanBC81tKwZ9g5U16WtxHGXVic7j2pTdwkYJJ/ClbW4/I8g1J7rxjqluLLT5o5FQRMWJIwO5Ner6Npy6To1vZKc+UmCfU96mSe2iBEahc8nauKcbuLB5P5VV9LE9TPooopDP/2Q==)to display the details for the corresponding HSM. The following view will open:

<figure><img src="/files/5x3EX7MEVKEhDoD2nU33" alt=""><figcaption></figcaption></figure>

In order to facilitate the identification of the HSM, the top section displays basic information.

In the lower section, all keys located in the HSM Slot described by the corresponding PKCS11 configuration are listed.

If there are more keys that cannot fit on one page, use the navigation at the bottom of the table to switch pages.

{% hint style="info" %}
Note: Unused keys can be identified by their Alias Name and CN being equal.
{% endhint %}

**Download**

Click on !\[A black arrow pointing down

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAAzADgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD14B5JH/eMADgAU7yX/wCerUQ/6yX/AHqmoAh8l/8Anq1Hkv8A89WqWvK9c8b6xa69NDBMEijfATFK+qQW0uen+S//AD1ajyX/AOerUzTp2utOt5n+9IgY1ZqmrOwk7q5XlR44mYStkCin3P8Ax7v9KKQxIf8AWS/71TVDD/rJf96nTzxW0TSzOEReSxPSgDI1zxXp/h+WOO+80GQZUqmRXj+r3cV9rE9zDny3fcM9cV6rrV14f12xa3ubuHn7r55U15nfeGr601NLOOMzCU/upF5Vh65qVfmKfwnonh7xrpd0lpp0JmNxsC42cZA9a62uK8MWOi+GYj9pu4Gvz/rGJ+77Cuts9QtdQQtazJKBwdp6VpLUzWhJc/8AHu/0oouf+Pd/pRUlCQ/6yX/erH8ZRvL4aulRGdivRRk1sQ/6yX/eqXrSkrqw07O58+Lp13tH+hXHT/nma2bTWvEFjYfZIYJjHghWaIllB9DXtO1fQflS7V9B+VMR4hBoSXEcclzNcJLISZAYSStdr8NLWS2t7tXjkVd/yl1IzXc7V/uj8qUADoKadhNXI7n/AI93+lFFz/x7v9KKQylcSvHO4RiBmmfaJf75oooAPtEv980faJf75oooAPtEv980faJf75oooAQzyMMM5INFFFAH/9k=)to download the certificate assigned to the key as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/jD6lClgw9byE0jqjYzNB" alt=""><figcaption></figcaption></figure>

Select the desired export format and click "Download" to save the user certificate to your OS's default download location.


# Configure Mail Server

## Mail Settings

An Administrator can view and edit the Email bodies of the different E-Mail Notification Service messages using the following dialog:

<figure><img src="/files/xIFtlsEOCx3GdiOLEbt9" alt=""><figcaption></figcaption></figure>

Click on  to open the editor dialog for the respective mail type.The following is an example from Mail Type Officer:

<figure><img src="/files/ItcnPRO7Y3VFKH3596uL" alt=""><figcaption></figcaption></figure>

Click into the text area to start editing.

Click on Proceed to continue.

You will be prompted to authenticate the registration:

<figure><img src="/files/O6vAGR1orKRogJn6kFnd" alt=""><figcaption></figcaption></figure>

Authenticate using your Administrator token and proceed by pressing Authenticate.

Click Sign and Save to save the changes.


# Reports

**The auditor provides detailed reports of application logs, showing all actions performed by users in a table format.**

**Application Logs**

All user actions are logged in a report table, with the latest appearing first.

<figure><img src="/files/UrTTNcUUldUg4oQvH5F3" alt=""><figcaption></figcaption></figure>

&#x20;The log events can be filtered by the following criteria:

<figure><img src="/files/yZ2gpmC83Ez3PoC8TivI" alt=""><figcaption></figcaption></figure>

Click "Search" to apply the filter of your choice. Click "Reset" to remove the filter again.

Click "Export to Excel" to export the entire Application Log to an XLSX file. The file will be downloaded to the standard download location of your OS.

Click to <img src="/files/dLbCqJuwSeT7C7MGtwPp" alt="" data-size="line">view logs for a detailed report.

<figure><img src="/files/4Qt4X5BQBz2INFAl1XCf" alt="" width="375"><figcaption></figcaption></figure>

Click on the<img src="/files/zIgD3v91IefQnYjj3vkr" alt="" data-size="line"> button to view the signed data. A pop-up window will appear displaying the signed data as shown below.

<figure><img src="/files/X9RO0fUM2bDXbqOehhxg" alt="" width="328"><figcaption></figcaption></figure>

Click to <img src="/files/5ZxgKYVHaDDHr4casw04" alt="" data-size="line">trigger signature verification check on the application log entry.

If tempered, then it will give the failure message given below

<figure><img src="/files/OmrH8mtKG42GuklgvEWB" alt="" width="344"><figcaption></figcaption></figure>

If the data is correct, then give the success message given below:

<figure><img src="/files/iTiYGcv12pTK4uiNyPmp" alt="" width="344"><figcaption></figcaption></figure>

&#x20;


# Recover User key Pair

Enabling KRS (Key Recovery Service) while creating a certificate profile allows users to recover the keypair for the certificates. This is a useful feature for organizations that need to be able to recover the keypair for their certificates in the event of a disaster or other incident.

**Recover**

When Is KRS Enabled is selected in the certificate profile, officers can recover keys using two different modes for user certificates.

* PFX with New Password
* PFX with Old Password.

<figure><img src="/files/HH7Dza6g9VJ122gcRwO8" alt=""><figcaption></figcaption></figure>

Select a search criteria from the dropdown box on the left. The following search criteria are available:

* Serial Number                    – the serial number of the user certificate
* Common Name                  – the common name (CN) of the user certificate
* Issuer Name                       – the CN of the issuer (= CA) of the user certificate
* Status                                 – the state of the certificate
* Subscriber Id                      – the subscriber ID used to create the user certificate

<figure><img src="/files/iAdDo4J3qZffElDzHKX6" alt=""><figcaption></figcaption></figure>

For all search criteria, except Issuer Name and Status, enter the search value in the right field. For Issuer Name, a dropdown box with existing CA names is provided.

For Status, the right field changes to the following dropdown box:

<figure><img src="/files/N05E0uNBUsVrGcxmzZCu" alt=""><figcaption></figcaption></figure>

After inserting the search value or selecting the status filter, click Search to filter for all matching user certificates.

Here's an example of a filter that specifically applies to the "Active" status:

<figure><img src="/files/I48PEUy2B6UCFRI4CcDM" alt=""><figcaption></figcaption></figure>

&#x20;**View**

Click on <img src="/files/MGUxSMmcwAXY6UKAob49" alt="" data-size="line"> to view the user certificate details:

&#x20;

<figure><img src="/files/vIIaN1mg1nXrKC6mIDGq" alt="" width="305"><figcaption></figcaption></figure>

**Download**

&#x20;Click on  <img src="/files/p0B4u0fXIOukVCzhFohP" alt="" data-size="line">to download the user certificate as

* DER-encoded X.509 certificate (.cer)
* Base64-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/hXocYHViyHiYEn7tDyy3" alt="" width="257"><figcaption></figcaption></figure>

Select the export format of your choice and click Download to start the download of the user certificate. The user certificate will be downloaded to the standard download location of your OS.

**Recover**

Click on  <img src="/files/vefewAheRIFodYkWWfR1" alt="" data-size="line"> icon to start the recovery dialog:

<figure><img src="/files/8sEkuRdVNHSD8pOe1U1M" alt="" width="356"><figcaption></figcaption></figure>

By default, "Keystore with new password" will be selected and you will be prompted to insert a new password.

Enter the new user certificate password in the New Password field. You can view the password policy by hovering over it<img src="/files/Yn5GTm62lAPipY5lXtQL" alt="" data-size="line">.

While "Keystore with old password" will not prompt for a new password but will generate the new user certificate with the old password again.

Press "Authenticate" after confirming and using your Officer token.

To generate a new user certificate key, simply click on the "Recover key" button.

###


# V4.2.7

## Release Notes for emCA v4.2.7

**Release Date: 30/05/2025**

**Password Change at First Login**

Enforces a security policy requiring users to change their default or temporary password upon first login. This ensures account integrity and prevents unauthorized access using known default credentials.

* **Enabled Backup & Restore**

Provides a mechanism to back up system configurations, certificates, and critical data, allowing for complete or partial restoration. This feature supports disaster recovery and simplifies migration between environments.

* **Connectivity with SMTPS & LDAPS**

Supports secure communication with external services over SMTPS (SMTP over SSL/TLS) for email notifications and LDAPS (LDAP over SSL/TLS) for directory services. Ensures encrypted data transmission and compliance with secure networking standards.

**emCA REST API and Protocol Support - Enhancements in this version**

* **Replay Attack Protection Using Nonce**

Implements anti-replay mechanisms using a unique nonce (number used once) in cryptographic protocols. Ensures each request is unique, preventing attackers from reusing intercepted messages to gain unauthorized access or manipulate operations.

* **Basic Authentication for EST Protocols**

Supports HTTP Basic Authentication for Enrollment over Secure Transport (EST) operations, such as certificate enrollment and renewal. Ensures compatibility with clients that authenticate using simple credentials, while recommending transport-layer security (e.g., HTTPS) to protect credentials in transit.

**REST API Postman Link**

* **CA Management -** [V4.2.7](https://documenter.getpostman.com/view/40123569/2sB34imfqi)
* **Certificate Management -** [V4.2.7](https://documenter.getpostman.com/view/40123569/2sB34imfqi)


# User Manual

Each version of emCA includes user manuals covering four key roles:&#x20;

CA Administrator,&#x20;

Administrator,&#x20;

Officer, and&#x20;

Auditor.&#x20;

These manuals provide details such as login, application setup, screenshots, features, functionalities, and the roles and responsibilities associated with each user. They serve as a reference to help users understand and perform their tasks within the application.

{% hint style="info" %}
Until version V4.2.3, emCA included a separate role called *Operator*. This role was responsible for managing the CA hierarchy (including viewing and exporting Root and Sub-root CA certificate details) and performing secure data backups using manual (local) or automatic (local/remote) modes. From version V4.2.4 onwards, these responsibilities have been merged into the *CA Administrator* role.
{% endhint %}


# CA Administrator

In this part, we will provide a detailed explanation of all the features available in the emCA application for users with the CA Administrator role. We will also include helpful screenshots of the application to make things clearer.


# CA Admin Login

Enter emCA URL in any of the browser displays login page as shown below.

To start using the application, CA Administrators need to install the .pfx file in the system before and enter their unique Username and After entering this information, they can click the "Login" button.

<figure><img src="/files/6fMwL6xodxaBwheDWIFt" alt=""><figcaption></figcaption></figure>


# Dashboard Page

Upon successful login, if the minimum required users have not been created for a group, the following message will be displayed.

<figure><img src="/files/nYReec5HJ7VyxY1GJbVP" alt=""><figcaption></figcaption></figure>

The Create User button will be available for the administrator to click and proceed with creating the required user(s) for the group.

If the login is successful, the application will show them the main dashboard page, which looks like the example below section.

<figure><img src="/files/gGWwlvKvy6pKlM0HSQPm" alt=""><figcaption></figcaption></figure>

1. On the left-hand side of the dashboard page, there is a “Navigation panel” displaying various options that the CA Administrator can choose from.
2. Located at the top of every user interface (UI), there is a “Home” button. Clicking on this button will take you back to the emCA Dashboard, where you can access statistical information related to your Public Key Infrastructure (PKI).
3. On the top-right corner of each UI, you will find a “language” option. Here, users can select their preferred language from the drop-down menu, with choices between English and German.
4. Also situated on the top-right corner of each UI, you'll find the “User information” section. This menu contains two additional subsections: Profile and Logout.

* Profile: This section allows users to view their own user information. However, editing user information is not possible from this view.
* Logout: By selecting this option, users can manually log out from the emCA system.


# View CA Hierarchy

CA Hierarchy deals with the display of hierarchical view of Certificates (Root, CA, and Sub CA certificates). CA Hierarchy defines the certificate chain and clicking on particular certificate; certificate details can be viewed and exported. The user can also know by looking at the hierarchical view whether for a given CA Certificate the private key is available or not.

* In the dashboard page, click on CA Hierarchy menu on the left panel.
* You will be redirected to the CA Hierarchy page. Refer below figure.
* By clicking on a particular CA certificate, the CA Administrator can view certificate details and export certificates.

<figure><img src="/files/jdsizAVoY8ZmKaPjLPr6" alt=""><figcaption></figcaption></figure>

* For larger sets of CAs, there is also a Search field located above the CA hierarchy. The Search field filters for matching CA names depending on the user input.
* By clicking Export on the right side of the detail view, the user can export the CA certificate as
  * DER-encoded X.509 certificate (.cer)
  * Base64-encoded X.509 certificate (.cer)
  * PEM encoded X.509 certificate (.pem)
* The following pop-up dialog will be displayed to select the export format:

<figure><img src="/files/lb624i9PRki4HefrUjp1" alt=""><figcaption></figcaption></figure>

Select the export format of your choice and click Download to start the download of the CA certificate. The CA certificate will be downloaded to the standard download location of your OS.


# Manage User & Roles

With the **"Manage User & Roles"** feature, the CA Administrator can create an administrator account.

The CA Administrator can supervise all other Administrators through the **"Manage User"** interface.&#x20;

<figure><img src="/files/xLkkTrK2412J4LgPIcXQ" alt=""><figcaption></figcaption></figure>


# Manage User

CA Admin can manage User accounts through various functions available on this page.

* Create New User
* View user details
* Regenerate
* Renew
* Deactivate
* Activate
* Delete
* Export to Excel


# Create New User

Click on the "+ New User" button to create a new user. The following dialog box will appear:

<figure><img src="/files/LBbd8BQC0kKq5uiAgxGu" alt=""><figcaption></figcaption></figure>

When creating a new user, the CA Administrator requires the user's information to be provided in three sections:\
\
**1. Map to group** - assigns the user to a specific group.\
**2. Basic Information** - contains basic details about the user.\
**3. Other Details**         - contains details such as the login type, signature algorithm, key algorithm and size, and validity.

### Map a Group&#x20;

{% hint style="info" %}
Please note that fields marked with an asterisk (\*) are mandatory.
{% endhint %}

CA Admin users can select a group and access type from a dropdown, or choose an existing group with a predefined access type.

![](/files/8RcOrYM3yZQz67Z3L6NR)

When selecting a group, please choose from the available options.

* New (to create a new mandate group)
* or an existing group (default group is GRP\_001)

If the user selects "New" as the group and "ALL" as the access type from the dropdown, the screen will prompt with certificate features as shown below:

![](/files/Mq9zypCsLA6mWLLqjlU0)

The user can then select the certificate features based on their requirements.

* X509 Certificate
* EMV Certificate&#x20;
* CVC Certificate&#x20;

By default, the system selects at least one certificate feature. Users can select multiple features by checking the respective boxes.

### Basic Information

In the "Basic Information" section, CA Admin users must provide mandatory information.

<figure><img src="/files/SuojFcbvL1XgwIfT8P8k" alt=""><figcaption></figcaption></figure>

**Common Name (CN):** Provide a unique "Common Name" (CN) for the Administrator certificate, serving as the alias of the new role owner.

**Email:** Enter the **"Email"** for the new Administrator, used as the username and contact for the E-Mail Notification Service.

**Organization Name (O):** Enter the legal **"Organization Name"** (O) of your company to associate the certificate with the correct organization.

**Country Code:** Enter the **"Country code"** using either the 2- or 3-letter Country Code, specifying the country code for proper identification.

**Role Selection:** Select **"Administrator"** from the dropdown box as the only available role for CA Administrators.

**Optional Parameters:** Optionally fill in any additional parameters as required for customization based on specific needs or preferences.

### Other Details

The image below which illustrates the **"Other Details"** section for user login preferences.

<figure><img src="/files/q3eBu8dQtCbkrMQmbk7v" alt=""><figcaption></figcaption></figure>

Users can choose from three login types based on their needs.

* Hard token
* Soft token&#x20;
* Password

#### Hard token

If a user selects the **"Hard token"** option, they need to insert the crypto token into their system. Once the token is plugged in, they can select it from the dropdown menu. In addition, they must enter the token password. Following this process, a pfx file will be created and saved in the crypto token. This pfx file enables the user to use the token while logging in.

<figure><img src="/files/SM4V5lDMd2W1KvTeeDE5" alt=""><figcaption></figcaption></figure>

**Soft token**

When a user chooses the **"Soft token"** login type, they have two options to choose from: **"Manual"** and **"Automatic"**.&#x20;

If the user must select **"Manual"** and click **"Browse"** to save the Administrator's soft token in the preferred location.

<figure><img src="/files/Fuj6ES1LEfpiMbCrbeUB" alt=""><figcaption></figcaption></figure>

If the user selects the **"Automatic"** option, the user must click **"Browse"** to specify where the Administrator's soft token should be generated.

<figure><img src="/files/LXxiosE63AreIKJUDusu" alt=""><figcaption></figcaption></figure>

#### Password

When the user selects the Password-based login type, they are given the same two options **"Manual"** and **"Automatic"**:

Choosing the **"Manual"** option prompts the user to enter and confirm their password.&#x20;

<figure><img src="/files/I2wHhMfccgQrwJ2ENZVv" alt=""><figcaption></figcaption></figure>

The **"Automatic"** option does not require a password.

After selecting the login type, choose a recommended "signature algorithm" for either soft or hard token login, and then select a recommended key algorithm and size.

&#x20;Finally, specify the new period of validity in the designated fields next to **"Validity"**.

{% hint style="info" %}
Note that the period of validity cannot exceed the period of validity of any of the CA Administrators.
{% endhint %}

After providing all necessary information, click "Proceed" and authenticate the action by verifying user identity with CA Administrator tokens and clicking "Authenticate."

<figure><img src="/files/2GHIum9PMiSMjRWRLcBX" alt=""><figcaption></figcaption></figure>

Once authentication is successful, click on the **"Create User"** button to generate the new Administrator user.&#x20;

After successfully creating the Administrator user, various options will become accessible such as **"Create New"** and **"View All"**

**Create New:**

Selecting **"Create New"** allows users to initiate the process of generating another new Administrator User. This involves following the same process as before.

<figure><img src="/files/8H9WU09lgoptA1euQXtP" alt=""><figcaption></figcaption></figure>

**View All**

By selecting the **"View All"** option, users can access a grid that showcases all the Administrator users that have been created. This grid provides a clear overview of the existing Administrator accounts.

<figure><img src="/files/4ck7SxDQVEEyfQ86RSyL" alt=""><figcaption></figcaption></figure>

In the following screen, click on ![](/files/oGR8GemkkTzUeEhWoIB6) to view the Administrator certificate details:

![](/files/PFtMwkww4cIPdERTFP0q)&#x20;

**Renew:**

* Click on ![](/files/akXYABBTJkvNsy506K74)to renew an Administrator that is about to expire.
* This icon is only available for soon-to-expire Administrators. The default threshold for expiring Administrators is 31 days but may vary depending on the customer specific configuration.

**Deactivate:**

* Click on ![](/files/gEwcd7vSTCygRXCxe0yO) to deactivate an Administrator.
* Deactivating an Administrator blocks them from logging into emCA. It does not revoke their access but merely suspends it.
* After clicking on ![](/files/daBbX1KvQZOFvrJOF13j), the following warning message is shown:

<figure><img src="/files/bwIvG79rqlah1PexcTzh" alt=""><figcaption></figcaption></figure>

* Click **Yes** to proceed. You will be prompted to authenticate the deactivation action:

<figure><img src="/files/0fJij9YKGmip4nxdC0JD" alt=""><figcaption></figcaption></figure>

* Authenticate using all CA Administrator Credentials and proceed by pressing Authenticate.
* Click on Deactivate to proceed. The following message is displayed upon completion:

<figure><img src="/files/7yxinOmfahuJt4Tyf51R" alt=""><figcaption></figcaption></figure>

* Click on ![](/files/Ew0dYv1TsXsmqmD8K7tJ) to activate an Administrator.
* Activating an Administrator reenables their access to emCA.
* After clicking on ![](/files/LFXFp71by5bGcJpCry8Q) , the following warning message is shown:

<figure><img src="/files/PSozTeNHWG1fFSvjPl87" alt=""><figcaption></figcaption></figure>

Click Yes to proceed. You will be prompted to authenticate the activation action:

<figure><img src="/files/Up9RxkTk30YGjjHIeB6d" alt=""><figcaption></figcaption></figure>

Authenticate using **all CA Administrator Credentials** and proceed by pressing Authenticate.

Click on **Activate** to proceed. The following message is displayed upon completion:

<figure><img src="/files/fks5LpthWVkkOqYg5joK" alt=""><figcaption></figcaption></figure>

* Click on ![](/files/DRP3R8mBtCpodyILLjz1) to delete an Administrator.&#x20;
* An Administrator that has been deleted, cannot be recovered! Consider deactivating an Administrator before deleting it.
* After clicking on ![](/files/MRhMxR3nkANYNSCVYEuU) , the following warning message is shown:

<figure><img src="/files/ODb0o8xgpVrWzAYfkR9I" alt=""><figcaption></figcaption></figure>

Click Yes to proceed. You will be prompted to authenticate the deletion action:

<figure><img src="/files/6MnVVtvoBXpGHeRAPfTE" alt=""><figcaption></figcaption></figure>

Authenticate using **all CA Administrator Credentials** and proceed by pressing **Authenticate.**

Click on **Delete** to proceed. The following message is displayed upon completion:

<figure><img src="/files/9d7bUu7UCs1e9n5g1XBe" alt=""><figcaption></figcaption></figure>

* Clicking on **Export to Excel** will trigger an automatic download of an XLSX file to the standard download location of your OS.
* The generated XLSX file will have the name **ManageUsers\_Report.xlsx.**
* This XLSX file contains the displayed table of Administrators in a tabular format.


# View Groups

CA Administrator users have the ability to view all role owners for every group and check how many certificates have been created for each group.&#x20;

Simply access the **"View Groups"** UI and emCA will load the current set of role owners.

<figure><img src="/files/0Drz3Xid1i4TZsATgT1d" alt=""><figcaption></figcaption></figure>

Users can filter their search by selecting "Role" or "Group".

Select "Search for" from the second dropdown and click "Search".

To remove any existing filter from the display, simply click on the "Reset" button.

Click on the hyperlink in the field **Access Type** in order to check the number of certificates created in the particular group and access type:

<figure><img src="/files/Ny99twGvQc12xqTCMuvy" alt=""><figcaption></figcaption></figure>


# Reports

emCA offers a variety of reports including application logs, certificate revocation lists (CRLs), certificate statistics, all certificates, active certificates, revoked certificates, suspended certificates, and expired certificates.


# Application Logs

All the actions performed by the users in the emCA application will be displayed in the Logs report table with the latest on the top list.

<figure><img src="/files/spNxw7kJFFEAAoOMz7MD" alt=""><figcaption></figcaption></figure>

The log events can be filtered by the following criteria:

<figure><img src="/files/qnxYMp3e6AXyjF69D8t2" alt="" width="119"><figcaption></figcaption></figure>

Click "Search" to apply a filter or "Reset" to remove it.

Export the entire Application Log to an XLSX file by clicking "Export to Excel". The file will be downloaded to your computer's standard download location.

Click the 'verify'<img src="/files/x2p9BMPom47OFfjUYRNF" alt="" data-size="line"> icon to trigger signature verification for the application log.

If the data is correct, a success message will be displayed. Otherwise, a failure message will appear if tempered.

<figure><img src="/files/C82PeUBGzehlfYwVWQ50" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/QM12nEeSm5qsRL9yvl7Y" alt=""><figcaption></figcaption></figure>


# CRL Report

The CRL Report displays the available Certificate Revocation Lists (CRLs) for each group, allowing users to view the current lists.

<figure><img src="/files/6sVaDRqxHK1Ch2un8YWk" alt=""><figcaption></figcaption></figure>

As a CA admin, users can easily search the CRL from a large number of lists using a search filter.&#x20;

To access the filter pop-up, simply click on the Search icon at the bottom of the grid. You can filter any column except for CRL No. using either the equal or contains comparator. This means that you can quickly and easily find the information you need without having to manually search through a long list of data.

![](/files/BEH1994zixF5wCDv3Nng)

After selecting your desired filter, simply click on the "Search" button to apply it. In case you want to remove the filter, click on "Reset".&#x20;

If you wish to export the entire table to an XLSX file, click on "Export to Excel". The downloaded file will automatically be saved to your local system's standard download location.


# Certificate Statistics

The Certificate Statistics report displays the total number of certificates created or generated through emCA, including Issued, Active, Revoked, Expired, Suspended, and Reinstated certificates for all groups.

Additionally, this shows the total number of CSRs, Key Profiles, and Certificate Profiles, CRLs created.

<figure><img src="/files/az78C55xlS82pbroQeMp" alt=""><figcaption></figcaption></figure>

Export the entire table to an XLSX file by clicking **"Export to Excel"**. The downloaded file will be saved to your OS's standard download location.


# All Certificates

The **"All Certificates"** reports section allows users to view a table of all the certificates generated by emCA.&#x20;

The table displays the Issued Date, Expiry Date, Certificate Serial No., Common Name, issuer Name, and the Status of each certificate (active, expired, revoked, suspended, or reinstated).

<figure><img src="/files/LD0ANsItjG3Hn5eeCE1S" alt=""><figcaption></figcaption></figure>

emCA provides a range of filtering options to simplify certificate searches.

**Search Filters:**

![](/files/O6VrUamYZ2gTsT93kX2Z)

**Serial Number and Common Name:** Users must enter relevant information in the designated field for "Serial Number" or "Common Name" selections.

**Issuer Name:** When the user selects "Issuer Name," they must choose the correct issuer from the dropdown.

**Status:** If the user chooses the "Status" option, they must select the specific status from the dropdown list, which represents the current state of the certificate.

**Subscriber ID:** When searching for a certificate using "Subscriber ID", the user must provide the specific Subscriber ID associated with it.

**Created Date and Expiry Date:** If the user selects "Created Date" or "Expiry Date," they must enter the certificate's creation and expiry dates in "yyyy-mm-dd" format, including the time if needed. This enables accurate date-based searching.

emCA is a user-friendly interface that allows users to filter and locate certificates based on their unique requirements easily.

#### Download

To download the certificate, users should click the "Download" icon under the action column.

#### View

Users should click the "View" icon under the Action column to view the certificate.


# Application Settings

CA Administrators can use "Application Settings" to manage licenses, authentication matrix, and certificate features.


# Manage License

CA Administrator can manage the emCA license using this UI.

<figure><img src="/files/j33DXIzFnaCbMEuRaGKa" alt=""><figcaption></figcaption></figure>

CA Administrators can renew their emCA license up to 30 days prior to expiration by generating a new ID, as indicated in the "Important Note" section of the user interface.

In the upcoming pages, you will find detailed instructions on how to renew your emCA license. Clicking on the "Generate ID" button will trigger a dialog box.

<figure><img src="/files/mjwkeI4Cgi1T7KSA9dKk" alt="" width="357"><figcaption></figcaption></figure>

<figure><img src="/files/Ol509ZSaXwKQMsqtmveO" alt="" width="353"><figcaption></figcaption></figure>

To store the generated ID on your device, simply click the "Download" button.

Please send the ID file that has been generated to the email address <emca.support@emudhra.com>.

After receiving the new emCA license file, click "Choose file" and select the license.

<figure><img src="/files/5XrNWI5o1Bl6ah3jVvmE" alt=""><figcaption></figcaption></figure>

To complete the registration process, upload your license and click 'Register'. This will prompt the screen below.

<figure><img src="/files/KdrRwg01uyaAOy7HueXF" alt=""><figcaption></figcaption></figure>

Enter the CA administrator's email and token PIN to sign and authenticate. Once authenticated, click "Register" to renew emCA.

By following the steps mentioned above, you can easily renew your emCA.


# Manage Authentication Matrix

The Authorization Matrix specifies the minimum and maximum number of users assigned to each role. CA Administrators can adjust this range as needed, particularly after initial setup.

<figure><img src="/files/MsV6Xj9ES0qAWRCdmrJ3" alt=""><figcaption></figcaption></figure>

Select **"Edit Matrix"** to activate the entry fields in the table above for editing purposes. It is important that each role has a minimum value of 1 and a maximum value of 9.


# Certificate Features

Different certificate types, such as x509, EMV, and CVC, are available on the emCA platform.

When you first set up emCA, you have the option to choose the certificate features that suit your needs. You can add more features later by selecting "Manage certificate features" and using the edit option if you only selected one feature during the initial setup. If you have already selected all three characteristics, you won't be able to modify them after the initial setup.

<figure><img src="/files/68NDLMPnHQL8vJ6vVxnh" alt=""><figcaption></figcaption></figure>


# Administrator

CA Administrators can assign the Administrator role to each group. Administrators and their roles are limited to viewing content only within the group they have been assigned to; they cannot view content from other groups. Administrators are primarily responsible for configuring certificate creation.

Administrators can perform various tasks, including:

* Creating and managing certificate profiles
* Creating and managing key profiles
* Creating and managing Officer, Auditor, and Operator users

####


# Dashboard

The Dashboard is the primary interface displayed after a successful login. It provides a comprehensive overview of the emCA's key metrics and actionable items for administrators.

<figure><img src="/files/6cdnJkC2urVfTScCIcnJ" alt=""><figcaption></figcaption></figure>

Key Components of the Dashboard

1. Welcome Message and Last Login
   * Displays a personalized welcome message along with the Last Login Date and Time.
2. Quick Statistics
   * Active Certificates: Displays the total count of certificates currently active.
   * evoked Certificates: Displays the number of certificates that have been revoked.
   * Certificates Expiring Soon: Indicates the count of certificates nearing their expiration date.
   * CRL (Certificate Revocation List): Displays the count of CRLs available in the system.
3. Active Certificates Table
   * Lists all CA and User certificates with the following columns:
     * Created Date: Displays the creation timestamp of each certificate.
     * Certificate S.I.No.: The unique serial number of the certificate.
     * Common Name: The name associated with the certificate.
     * Issuer Name: The authority that issued the certificate.
     * Status: Indicates whether the certificate is active, revoked, or expired.
     * Action: Provides options for viewing or downloading the certificate.
       * Eye Icon: Click to view certificate details.
       * Download Icon: Click to download the certificate.
4. emCA  Admin has the following features:
   * CA Hierarchy: Manage Certificate Authority (CA) structure.
   * Manage Profiles: Configure user and application profiles.
   * Manage User Certificates: Handle individual user certificates.
   * Manage CA Certificates: Oversee CA-issued certificates.
   * Manage Keystores: Manage keystores for secure storage.
   * Manage Users & Roles: Configure and control user access roles.
   * Reports: Generate and view system reports.
   * Application Settings: Adjust application configurations.

* Administrators can use the Search and Reset buttons under the certificate table to filter or refresh the list.
* Use the Pagination Controls at the bottom of the table to navigate through multiple pages of certificates if available.


# View CA Hierarchy

As an administrator, the user can access the CA Hierarchy user interface, which presents a hierarchical view of CA Certificates, including both Root and Sub CA certificates. This interface outlines the certificate chain for each sub-hierarchy in a tree structure, with the Root level on the left-most side.

By clicking on a particular CA certificate, the Administrator can

* View certificate details
* Delete certificates&#x20;
* Export certificates

<figure><img src="/files/772fiUor14En9c3xopsP" alt=""><figcaption></figcaption></figure>

Users can easily filter for matching CA names using the "Search" field above the CA hierarchy.

Users can delete CA certificates by clicking "Delete" in the detail view, followed by a confirmation dialog.

<figure><img src="/files/Rq9UfciEtZni3uH3NSQD" alt=""><figcaption></figcaption></figure>

To finalize the deletion, please click on the "Delete" button and confirm your action.

User will be prompted to authenticate the delete action. Authenticate using your Administrator token and proceed by pressing Authenticate.

{% hint style="info" %}
Warning :&#x20;

* Deleting CA certificates is highly discouraged!
* CA certificates – even if expired – can be used to validate signatures later on.
* Deleting CA certificates will render underlying CA certificates inaccessible as well.
  {% endhint %}

Clicking the Export button on the right side of the detail view allows the user to export the CA certificate.

* Base64-encoded X.509 certificate (.cer)
* DER-encoded X.509 certificate (.cer)
* Cryptographic Message Syntax Standard PKCS#7 certificate (.p7b)

<figure><img src="/files/7MtLun3jELmB3FaNOZKi" alt=""><figcaption></figcaption></figure>


# Manage Profiles

In the "Manage Profiles" feature, the Administrator has the ability to oversee and control different profiles, including certificate profiles, key profiles, and CRL profiles.


# Manage Certificate Profiles

Certificate profiles determine the features and limitations of certificates that are issued by a Certificate Authority (CA). These profiles provide specific details and characteristics, such as the key usage, extended key usage, validity term, and other important aspects, that a certificate needs to have.&#x20;

Certificate profiles are essentially blueprints that are used to generate certificates with predetermined parameters. They support the organization's security policies and needs by ensuring that the certificates issued by a CA are consistent and secure. Certificate profiles are defined by emCA through the functions located in the Certificates Profiles sub-menu.

The below shows the user interface of the certificate profiles.

<figure><img src="/files/JURibboPHNel5CC5A9so" alt=""><figcaption></figcaption></figure>

An Administrator can perform the following actions for certificate profiles by accessing sub-menu:

**Create New Profile:** Click on the "+ New Profile" button to create a new certificate profile. This action will open the Certificate Profile Edit Dialog.

The features available in the emCA or the CA Administrator interface will depend on the certificate features selected during configuration. X.509, CVC (Card Verifiable Certificate), and EMV are the available certificate types based on the choices made during the setup process.

To create an "X509 certificate" profile, the user must choose "X509" as the certificate type.

<figure><img src="/files/6vdFpVS768hgWmi0Yv59" alt=""><figcaption></figcaption></figure>

Once a certificate type is selected, the corresponding certificate profile options are activated and can be accessed. This helps users by providing relevant and context-specific choices, making the process of generating certificates easier and more efficient based on their specific needs.

**View Certificate profile:** Click on the <img src="/files/BU0yjKmG6qkMlLQRqVr2" alt="" data-size="line">icon to open a read-only mode of the Certificate Profile Edit Dialog.

**Edit Certificate profile:** Click on<img src="/files/QyivbuGstucimwaKmswt" alt="" data-size="line"> the icon to open the Certificate Profile Edit Dialog for already existing certificate profiles.

**Clone Certificate profile:** Click on <img src="/files/dYVaYcESFvV4fL8oh5GZ" alt="" data-size="line">  icon to clone a certificate profile. This will copy all information except the Profile name to a new profile

**Delete Certificate profile:** To delete a certificate profile, click the "Delete" <img src="/files/tzWqro6jMENKqeC4jAsn" alt="" data-size="line">icon and then confirm your action. You'll need to authenticate this action using your Administrator token by pressing "Authenticate." Once authenticated, click "Confirm" to complete the deletion of the certificate profile.

**Deactivate Certificate profile:** To make a certificate profile inaccessible for use, click on the "deactivate" <img src="/files/DyST9ILWMeKIrnzN8xKJ" alt="" data-size="line"> icon. Confirm by clicking "Yes". You will need to authenticate the deactivation action by using your Administrator token and pressing "Authenticate". Finally, click on "Confirm" to complete the deactivation of the certificate profile.

**Activate Certificate profile:** Click on the "activate" <img src="/files/TNkpPdgV35rQmMRQa6WF" alt="" data-size="line"> icon to enable certificate profile. Same process as deactivation.

**Search**: The user can filter the list of certificate profiles by clicking on Search and using the pop-up.

<figure><img src="/files/yeG2K0hp6Pb5m2ix8JNh" alt=""><figcaption></figcaption></figure>

Users can filter using each criterion with an equal or contain comparator.


# X509 certificate profile

Certificate profiles define the technical parameters that can be part of a given certificate such as X.509 Certificate extensions, Subject DN, Key usages, Extended key usages, etc. Certificate profiles are extendable and upgradeable.

## CA Certificate Profile

The user must select the X.509 certificate type to generate a CA certificate profile. The default certificate type is "X509".

There are three types of X.509 certificate profiles, each explained in the following section:

* CA Certificate Profiles.&#x20;
* User Certificate Profiles.
* OCSP Certificate Profiles.

In order to create a root CA OR Sub CA certificate profile, the admin must select the CA Certificate Profile and fill in all mandatory fields in the Certificate Profile Edit Dialog, which contains three sections:&#x20;

* Basic Information.
* Subject DN Details.
* X.509 Extensions.

### Basic Information

The following image displays the Basic Information section of the Certificate Profile Edit Dialog.

<figure><img src="/files/eG0NX8zSSeRPUSvLKb82" alt=""><figcaption></figcaption></figure>

**Profile Type Selection:** Choose "User" as the profile type.

**Profile Name Entry:** Enter a unique "Profile Name" in the corresponding field, using any printable characters.

**Validity Fields:** When filling in the "validity" fields, ensure it is less than the remaining validity of the issuing CA. Be mindful of leap days, especially when exceeding leap years.

**Issuing CA Selection:** Select the corresponding issuing CA for "Self Signed"  in order to create root CA else select any existing CA in order to SUB CA.

**Choose Algorithm:** Choose an algorithm from the list that is supported by emCA and select the corresponding signature algorithm.

Users have choices when it comes to "Signature Algorithms." Here are the options explained:

![](/files/6IdDCnOjnYvsFmp34C0t)

**DSA Algorithm:** If you choose "DSA," the corresponding signature algorithm is "SHA1WithDSA."

![](/files/MoR5iPR6BrIJtal9uIox)

**RSA Algorithm:** Opting for "RSA" gives you signature algorithms like "SHA1WithRSA," "SHA256WithRSA," "SHA384WithRSA," and "SHA512WithRSA."

![](/files/mXeJ314Woj6a9bA0RSPM)

**ECDSA Algorithm:** Going with "ECDSA" means signature algorithms such as "SHA1WithECDSA," "SHA256WithECDSA," "SHA384WithECDSA," and "SH512WithECDSA."

![](/files/n5VKdlq2tu1PfdjAR9fn)

**EDDSA Algorithm:** If you go for "EDDSA," the associated signature algorithm is "Ed25512."

&#x20;![](/files/5uOMMaH3y9ABfkynlS8Z)

**PQC Algorithm:** Choosing "PQC" Algorithm opens up signature algorithms like "DILITHIUM2," "DILITHIUM3," "DILITHIUM5," "FALCON-512," "FALCON 1024," and "SPHINCSPlus."

![](/files/3sLNxYU4MXN4kC6xDdRt)

## Edit Subject DN Details

The following image displays the Subject DN Details section of the Certificate Profile Edit Dialog.

<figure><img src="/files/CQ8kW2k6mAQMMFgAxDV7" alt=""><figcaption></figcaption></figure>

The Subject Distinguished Name (Subject DN) is the unique name that is attributed to the certificate owner.

In order to create a Subject DN, you need to choose from a list of Subject DN attributes. The image above shows a pre-defined subset of the available attributes. To choose the attributes that you want to include in your certificate, simply select the corresponding checkbox. Any unselected attributes will be ignored.

Users can rearrange the order of certificate elements by dragging and dropping the Subject DN attribute.

The first element in the Subject DN is the top element in the UI.

By clicking + Subject OID, you may add additional Subject DN attributes to your list.

<figure><img src="/files/Lev4wPLoIYAENcVkysim" alt=""><figcaption></figcaption></figure>

Object Identifiers (OIDs) identify Subject DN attributes. For instance, the "Locality" attribute is identified by 2.5.4.7. Customize your OID in the field above.

To choose an attribute encoding, simply use the dropdown list located in the middle of each row.

&#x20;<img src="/files/uD24bS3o3q6pDdwVl5l3" alt="" data-size="original">

In most cases, PrintableString or UTF8String are used. For more information, refer to RFC 5280.

Please choose either "Mandatory" or "Optional" from the last dropdown menu.

&#x20;![](/files/XmmkxRxMzXthAku6t4zK)

Mandatory fields are required for certificate generation. Failure results from missing data.

During certificate generation, optional attributes may be provided. Empty fields are not added to the certificate.

**X.509 Certificate Extensions**

The following is the list of extensions available for selection as part of the ‘X.509' Certificate Extensions’ section. To select a specific extension, select the ‘Use’ checkbox attached to the respective extension. In addition, for selected extensions, an option to mark a specific section as ‘Critical’ is also provided.

<figure><img src="/files/GCZjWG4qM3CLrZ1Ei7MI" alt=""><figcaption></figcaption></figure>

* Select the checkbox 'Use' in order to include specific extensions in the certificate. Note that some extensions must be filled with content if selected in accordance with RFC 5280.
* Select the checkbox 'Critical' in order to set the critical flag in the certificate for this extension. If a critical extension fails validation, the certificate is not valid.
* Users can reorder X.509 Extensions via drag and drop.
* Basic Constraint (mandatory) - By default, the Basic Constraint "None" is selected. The administrator can choose to maintain up to 6 sub-CAs or a certificate hierarchy. This option is only available for CAs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       &#x20;
* Key Usage (mandatory) - Please select the 'Usage' option from the dropdown menu. Make sure to select at least one key.

<figure><img src="/files/o4DHBCRSQmoLoSkZCzN0" alt="" width="125"><figcaption></figcaption></figure>

* The authority key identifier extension is an optional feature that helps identify the corresponding public key used to sign a certificate.
* The Issuer Alt Name Extension allows additional identities to be associated with the issuer of a CRL.
* The Subject Key Identifier extension is mandatory and provides information on how to access information and services related to the certificate's subject.
* Authority Information Access extension (optional) indicates how to access CA information and services for the issuer of the certificate in which the extension appears.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   &#x20;
* The subject alternative names extension (optional) allows additional identities to be bound to the subject of the certificate. It may include an email address, a DNS name, an IP address, and a uniform resource identifier (URI).
* The CRL distribution points extension (optional) identifies how CRL information is obtained.
* The Certificate policy extension is mandatory and defines the roles and duties of different entities in a PKI. Clicking the (+) button allows optional entry of the Certificate policy.
* The Policy Mapping extension (optional) contains pairs of OIDs: each pair includes an ‘issuerDomainPolicy’ and a ‘subjectDomainPolicy’. The pairing indicates that the issuing CA considers its ‘issuerDomainPolicy’ equivalent to the subject CA’s ‘subjectDomainPolicy’.
* The Policy Constraints extension, which is optional, can be used to prohibit policy mapping or require that each certificate in a path contains an acceptable policy identifier.
* The Inhibit any policy extension (optional) indicates that the special ‘anyPolicy’ OID with the value is not considered an explicit match for other certificate policies.
* The Freshest URL extension (optional) identifies the CRL to which a certificate user should refer to obtain the freshest revocation information.
* The Subject information access extension (optional) indicates how to access information and services for the subject of the certificate in which the extension appears.
* The Subject Directory Attributes extension (optional) is used to convey identification attributes of the subject

**Save Certificate profile**

Click "Proceed" to confirm saving the profile will redirect to the next page you will then be prompted to authenticate the action using your Administrator Username, and Token Pin and click on the ‘Authenticate’ button. The admin credentials will be validated

Click "Confirm" to finalize the certificate profile and view the success message as shown below.

<figure><img src="/files/Ymw2qsRx3t4oGGoBmgZm" alt=""><figcaption></figcaption></figure>

You can create new profiles by clicking on "+New" or return to the Certificate Profile overview by clicking "View All".

This way, you can easily set up an X509  CA profile with the necessary details for your specific use.

## User Certificate Profile

emCA allows users to generate various X509 certificate types within the certificate framework, as subtypes including New, DS, MLS, and DLS certificates.

Click on + New Profile to create a new certificate profile. This will open the Certificate Profile Edit Dialog.&#x20;

**Basic Information**

The Basic Information section of the Certificate Profile Edit Dialog is displayed in the following image:

The administrator provides the basic information

<figure><img src="/files/O5jqvAZcxwKsC2N2J485" alt=""><figcaption></figcaption></figure>

**Profile Type Selection:** Choose "User" as the profile type.

**Profile Name Entry:** Enter a unique "Profile Name" in the corresponding field, using any printable characters.

**Validity Fields:** When filling in the "validity" fields, ensure it is less than the remaining validity of the issuing CA. Be mindful of leap days, especially when exceeding leap years.

**Issuing CA Selection:** Select the corresponding issuing CA for "Issuing CA" to filter Signature Algorithm values to those supported by the issuing CA.

**Signature Algorithm:** Choose a "signature algorithm" that is supported by the options available under the Signature Algorithm.

**Certificate Recovery Option:** If you wish to enable the recovery of user certificates, select "Is KRS Enabled."

**Certificate Transparency Logs:** Select "Is CT Logs Enabled" to create Certificate Transparency (CT) Logs for user certificates. This enables selection between Manual or Automatic Process Types for SCT Requests.

**Manual Authorization:** Choose "Is Manual Authorization Enabled" to ensure that an officer must authorize during creation.

**Customize Validity Support:** Select "Support Customize Validity" to allow different validity values from CSR.

**Link Check:** To include link checks for user certificates, check 'Is Link Check Enabled'.

**Subject DN Details:**

The following image displays the Subject DN Details section of the Certificate Profile Edit Dialog.

<figure><img src="/files/Gbp7lZgMoOtF1wZbr9Bo" alt=""><figcaption></figcaption></figure>

Subject DN (Common name, Country, Email, organization etc.) attributes can be added by selecting the checkbox of the respective attribute. Once the attribute is selected, use the dropdown menu to define the relevant string from the options: Printable String, BitString, IA5String, BMPString, and UTF8String.

The option to make an attribute Mandatory (or) Optional is also provided.

In addition to these options, the order of attributes can also be rearranged using the option next to Mandatory/optional.

Optional: The option to customize OID is also offered. To add a custom Subject DN, click on ‘+ Subject OID’ option.

Enter a valid OID and select the corresponding values to include this OID to the Certificate creation process.

**X.509 Certificate Extensions:**&#x20;

The following are the list of extensions available for selection as part of the ‘X.509 Certificate Extensions’ section. To select a specific extension, select the ‘Use’ checkbox attached to the respective extension. In addition to it, for selected extensions, an option to mark a specific section as ‘Critical’ is also provided.

<figure><img src="/files/Vl8TbSUZaOz01qWO7HCX" alt=""><figcaption></figcaption></figure>

**Basic Constraints:** To use the Basic Constraints extension, select the **Use Basic Constraints** checkbox.

**Key Usage:** From the **Key Usage** dropdown menu, select the appropriate key usage options.

**Enhanced Key Usage (optional):** From the **Enhanced Key Usage** dropdown menu, select the appropriate key usage options.

**Authority Key Identifier (optional):** To use the Authority Key Identifier extension, select the **Use Authority Key Identifier** checkbox.

**Issuer Alternate Name (optional):** To use the Issuer Alternate Name extension, select the **Use Issuer Alternate Name** checkbox.

**Subject Key Identifier (mandatory):** The Subject Key Identifier extension is mandatory.

**Authority Information Access (optional):** To use the Authority Information Access extension, select the **Use Authority Information Access** checkbox.

**Subject Alternative Names (optional):** To use the Subject Alternative Names extension, select the **Use Subject Alternative Names** checkbox.

**CRL Distribution Points (optional):** To use the CRL Distribution Points extension, select the **Use CRL Distribution Points** checkbox.

**Certificate Policy (mandatory):** The Certificate Policy extension is mandatory. To enter the Certificate Policy, click the **(+)** button.

**Freshest CRL URL (optional):** To use the Freshest CRL URL extension, select the **Use Freshest CRL URL** checkbox.

**Subject Information Access (optional):**&#x54;o use the Subject Information Access extension, select the **Use Subject Information Access** checkbox.

**Subject Directory Attributes (optional):**&#x54;o use the Subject Directory Attributes extension, select the **Use Subject Directory Attributes** checkbox.

**Private Key Usage Period:**&#x54;o Configure the private key lifetime by providing the validity

<figure><img src="/files/D0oHOqNwNwSMYqjC8bVB" alt=""><figcaption></figcaption></figure>

**Save Certificate profile**

Click "Proceed" to confirm saving the profile will redirect to the next page you will then be prompted to authenticate the action using your Administrator Username, and Token Pin and click on the ‘Authenticate’ button. The admin credentials will be validated

Click "Confirm" to finalize the certificate profile and view the success message as shown below.

<figure><img src="/files/L1hi9oGjH7fdlSJRczsG" alt=""><figcaption></figcaption></figure>

You can create new profiles by clicking on "+New" or return to the Certificate Profile overview by clicking "View All".

This way, you can easily set up an X509 User profile with the necessary details for your specific use.

## Create OCSP Certificate Profile

Click on the "+ New Profile" button to create a new certificate profile. This will open the Certificate Profile Edit Dialog.&#x20;

**Basic Information:**

The image below displays the "Basic Information" section of the Certificate Profile Edit Dialog:

<figure><img src="/files/SH7OCxsq5IG6xnHl8Qft" alt="" width="563"><figcaption></figcaption></figure>

**OCSP Selection:** Choose OCSP by selecting the OCSP radio button.

**Profile Name Entry:** Give your profile a unique name.

**Validity Duration:** Choose how long the certificate should be valid in terms of days, hours, minutes, and seconds.

**Issuing CA Selection:** Pick the issuing CA from the dropdown.

**Signature Algorithm Selection:** Choose the signature algorithm that suits your needs.

**Subject DN Details:**

The following image displays the Subject DN Details section of the Certificate Profile Edit Dialog.&#x20;

<figure><img src="/files/7lFTCRPKoHH2V5w7KCHM" alt=""><figcaption></figcaption></figure>

**Subject DN Attributes**

Subject DN attributes can be added to a certificate by selecting the checkbox for the desired attribute. Once an attribute is selected, use the dropdown menu to specify the data type. The data types available are Printable String, BitString, IA5String, BMPString, and UTF8String.

Attributes can be marked as Mandatory or Optional. The order of attributes can also be changed using the arrows next to the Mandatory/Optional checkbox.

**Optional: Custom Subject DN OIDs**

To add a custom Subject DN OID, click the "+ Subject OID" button. Enter a valid OID and select the corresponding values to include this OID in the certificate creation process.

**X.509 Certificate Extensions:**

The following are the list of extensions available for selection as part of the ‘X.509 Certificate Extensions’ section. To select a specific extension, select the ‘Use’ checkbox attached to the respective extension. In addition it, for selected extensions, an option to mark a specific section as ‘Critical’ is also provided.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    &#x20;

* **Key Usage:** This tells how you can use your certificate key. For example, you can use it to sign other certificates or revoke them. You can pick one option from the dropdown list. The default option is Key Agreement, Key Certificate, CRL Sign.
* **Enhanced Key Usage:** This adds more ways to use your certificate key, besides the basic ones. You can pick one option from the dropdown list. This feature is optional.
* **Authority key identifier:** This helps to identify the key that signed your certificate. This feature is optional.
* **Issuer alternate name:** This adds more names for the issuer of CRL. CRL is a list of revoked certificates. This feature is optional.
* **Subject Key Identifier:** This tells how to find information and services for your certificate. This feature is mandatory.
* **Authority Information Access**: This tells how to find information and services for the issuer of your certificate. This feature is optional.
* **Subject alternative names:** This adds more names for your certificate, besides the one you already have. It can be an email, a website, an IP address, or a web address. This feature is optional.
* **CRL distribution points:** This tells how to get the list of revoked certificates. Revoked certificates are the ones that are no longer valid. This feature is optional.
* **Certificate policy:** This tells the rules and responsibilities of the certificate issuer and user. The issuer is the one who gives you the certificate, and the user is you. You can enter your own policy in the text box by clicking on the (+) button. This feature is mandatory.
* **Freshest URL:** This tells how to get the latest information about revoked certificates. This feature is optional.
* **Subject information access:** This tells how to find information and services for your certificate. For example, you can find out how to renew or revoke your certificate. This feature is optional.
* **Subject directory attributes:** This adds more details about your identity, such as your name, address, or phone number. This feature is optional.
* **OCSP No Revocation Checking:** This tells the rules and responsibilities of the certificate issuer and user, without checking for revoked certificates. This feature is optional.

**Save Certificate profile**

Click "Proceed" to confirm saving the profile will redirect to the next page you will then be prompted to authenticate the action using your Administrator Username, and Token Pin and click on the ‘Authenticate’ button. The admin credentials will be validated

Click "Confirm" to finalize the certificate profile and view the success message as shown below.

<figure><img src="/files/Zu25Hiaa3MgzCJt6ra3N" alt=""><figcaption></figcaption></figure>

You can create new profiles by clicking on "+New" or return to the Certificate Profile overview by clicking "View All".

This way, you can easily create an OCSP profile with specific details for your use case.


# Create  CVC CA certificate profile

The Card Verifiable Certificate (CVC) Certificate Authority (CA) profile is essential in securing credentials. It plays a critical role in establishing a strong and verifiable framework for certificates. This profile outlines the necessary steps for creating CVC certificates, emphasizing the unique characteristics required for verification.

In order to generate a CVC certificate, the user must select the CVC certificate type while setting up the CA certificate profile.

There are two types of CVC certificate profiles, each explained in the following section:

&#x20; • CA Certificate Profiles

&#x20; • User Certificate Profiles

**Basic Information:**

&#x20;The visual representation below depicts the "Basic Information" segment found within the Certificate Profile Edit Dialog:

<figure><img src="/files/eGH1PXwwTd6NQ3unqljZ" alt=""><figcaption></figcaption></figure>

**Profile Type:** When you start, the system already sets the Profile Type to CA (Certificate Authority) for you.

**Profile Name:** Give your certificate profile a unique name in the "Profile Name" field. You can use any regular letters or numbers.

**Validity Period:** Specify how long you want the certificate to be valid in the "Validity" fields. Remember to account for leap days if your certificate will be valid across leap years.

**Issuing CA:** Choose "Self-Signed" as the only option available. This means that your certificate is validated by itself.

**Signature Algorithms:** Depending on your preferences, you can choose different signature algorithms for your certificate.

Users can choose the Signature Algorithms, the following options are available:

<figure><img src="/files/65MP1OX3vj5sKKEPkbSs" alt="" width="325"><figcaption></figcaption></figure>

When selecting the "DSA" algorithm, the corresponding signature algorithm is "SHA1WithDSA."

<figure><img src="/files/uFaseXUGVSWwD6s09AzV" alt="" width="330"><figcaption></figcaption></figure>

For the "RSA" algorithm, signature algorithms include "SHA1WithRSA," "SHA256WithRSA," "SHA384WithRSA," and "SHA512WithRSA."

<figure><img src="/files/ELEefw5JGf2ZdCFVqK67" alt="" width="320"><figcaption></figcaption></figure>

Opting for the "ECDSA" algorithm entails signature algorithms such as "SHA1WithECDA," "SHA256WithECDSA," "SHA384WithECDSA," and "SHA512WithECDSA."

<figure><img src="/files/CcwB6AsYrF2Q0L6CBbB7" alt="" width="308"><figcaption></figcaption></figure>

**Subject DN Details**

The following image displays the Subject DN Details section of the Certificate Profile Edit Dialog:

<figure><img src="/files/7Ke5VvT9AGcFxiKqrf2a" alt=""><figcaption></figcaption></figure>

The Subject Distinguished Name (Subject DN) is the unique name that is attributed to the certificate owner.

A Subject DN consists of a list of Subject DN attributes such as Common Name, Country and Serial Number which are prefixed and not editable.

Click "Proceed" to confirm saving the profile. You will be prompted to authenticate the action by using your Administrator token and pressing Authenticate.

To complete the certificate profile, please click on the 'Confirm' button.

<figure><img src="/files/Nw2uOYq8E8c7qz6kZnDI" alt=""><figcaption></figcaption></figure>

You can create new profiles by clicking on "+New" or go back to the Certificate Profile overview by clicking on "View all".




---

[Next Page](/llms-full.txt/1)

