# Create New User

Click on the "+ New User" button to create a new user. The following dialog box will appear:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FmuBDsUJ8kCTTGX38GbsG%2Fimage.png?alt=media&#x26;token=2fd64708-fc6f-487a-aac9-9ff465b95587" alt=""><figcaption></figcaption></figure>

When creating a new user, the CA Administrator requires the user's information to be provided in three sections:\
\
**1. Map to group** - assigns the user to a specific group.\
**2. Basic Information** - contains basic details about the user.\
**3. Other Details**         - contains details such as the login type, signature algorithm, key algorithm and size, and validity.

### Map a Group&#x20;

{% hint style="info" %}
Please note that fields marked with an asterisk (\*) are mandatory.
{% endhint %}

CA Admin users can select a group and access type from a dropdown, or choose an existing group with a predefined access type.

![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FLFnCej3YfxDOCrgS7FhT%2Fimage.png?alt=media\&token=ba1fd497-9a5c-41c4-a7db-df752669bb9e)

When selecting a group, please choose from the available options.

* New (to create a new mandate group)
* or an existing group (default group is GRP\_001)

If the user selects "New" as the group and "ALL" as the access type from the dropdown, the screen will prompt with certificate features as shown below:

![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FMy3BpiicQjicqqaqDtQF%2Fimage.png?alt=media\&token=eda904e0-5841-48b3-adc9-e1605c84f6b8)

The user can then select the certificate features based on their requirements.

* X509 Certificate
* EMV Certificate&#x20;
* CVC Certificate&#x20;

By default, the system selects at least one certificate feature. Users can select multiple features by checking the respective boxes.

### Basic Information

In the "Basic Information" section, CA Admin users must provide mandatory information.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FKGxojlz8qDdbBniUkYv4%2Fimage.png?alt=media&#x26;token=bca9e862-46a5-478a-80f8-753b82dbae55" alt=""><figcaption></figcaption></figure>

**Common Name (CN):** Provide a unique "Common Name" (CN) for the Administrator certificate, serving as the alias of the new role owner.

**Email:** Enter the **"Email"** for the new Administrator, used as the username and contact for the E-Mail Notification Service.

**Organization Name (O):** Enter the legal **"Organization Name"** (O) of your company to associate the certificate with the correct organization.

**Country Code:** Enter the **"Country code"** using either the 2- or 3-letter Country Code, specifying the country code for proper identification.

**Role Selection:** Select **"Administrator"** from the dropdown box as the only available role for CA Administrators.

**Optional Parameters:** Optionally fill in any additional parameters as required for customization based on specific needs or preferences.

### Other Details

The image below which illustrates the **"Other Details"** section for user login preferences.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FfdZSxmNSuM3wq9whD9z2%2Fimage.png?alt=media&#x26;token=e3142f99-24c5-40f2-b6e8-6e543cbfa42b" alt=""><figcaption></figcaption></figure>

Users can choose from three login types based on their needs.

* Hard token
* Soft token&#x20;
* Password

#### Hard token

If a user selects the **"Hard token"** option, they need to insert the crypto token into their system. Once the token is plugged in, they can select it from the dropdown menu. In addition, they must enter the token password. Following this process, a pfx file will be created and saved in the crypto token. This pfx file enables the user to use the token while logging in.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2Fi9qF8uSzkAp2bdrcJmSf%2Fimage.png?alt=media&#x26;token=189a5548-989d-4050-862e-a883528ab797" alt=""><figcaption></figcaption></figure>

**Soft token**

When a user chooses the **"Soft token"** login type, they have two options to choose from: **"Manual"** and **"Automatic"**.&#x20;

If the user must select **"Manual"** and click **"Browse"** to save the Administrator's soft token in the preferred location.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FZArOIPJXKkfV98ci3wD5%2Fimage.png?alt=media&#x26;token=8d0e2e41-bae3-4c7c-a7d8-29f04a376de8" alt=""><figcaption></figcaption></figure>

If the user selects the **"Automatic"** option, the user must click **"Browse"** to specify where the Administrator's soft token should be generated.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FsUdjGqoMVDuEjSbZFYLD%2Fimage.png?alt=media&#x26;token=011f4c35-70c2-47e4-b293-553668ef8f2b" alt=""><figcaption></figcaption></figure>

#### Password

When the user selects the Password-based login type, they are given the same two options **"Manual"** and **"Automatic"**:

Choosing the **"Manual"** option prompts the user to enter and confirm their password.&#x20;

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2F7h28clZ8DOK7TNWzEZWm%2Fimage.png?alt=media&#x26;token=538aca4e-ec7c-466a-ace7-7409cb6d1161" alt=""><figcaption></figcaption></figure>

The **"Automatic"** option does not require a password.

After selecting the login type, choose a recommended "signature algorithm" for either soft or hard token login, and then select a recommended key algorithm and size.

&#x20;Finally, specify the new period of validity in the designated fields next to **"Validity"**.

{% hint style="info" %}
Note that the period of validity cannot exceed the period of validity of any of the CA Administrators.
{% endhint %}

After providing all necessary information, click "Proceed" and authenticate the action by verifying user identity with CA Administrator tokens and clicking "Authenticate."

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FmrRRNwzBBxOn9AZZHP2a%2Fimage.png?alt=media&#x26;token=330002c9-cb92-4abb-b312-0f970b74b322" alt=""><figcaption></figcaption></figure>

Once authentication is successful, click on the **"Create User"** button to generate the new Administrator user.&#x20;

After successfully creating the Administrator user, various options will become accessible such as **"Create New"** and **"View All"**

**Create New:**

Selecting **"Create New"** allows users to initiate the process of generating another new Administrator User. This involves following the same process as before.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FzUevJTfioZC4YB8t17vZ%2Fimage.png?alt=media&#x26;token=78b2a0f7-3515-4684-898f-6003029ff766" alt=""><figcaption></figcaption></figure>

**View All**

By selecting the **"View All"** option, users can access a grid that showcases all the Administrator users that have been created. This grid provides a clear overview of the existing Administrator accounts.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FdiUwRpxgKx1cNjYFBJVO%2Fimage.png?alt=media&#x26;token=b58f5133-eacd-41e6-9851-840d2787393a" alt=""><figcaption></figcaption></figure>

In the following screen, click on ![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2F0oP9uCpC5q26JT3E7Vm2%2Fimage.png?alt=media\&token=e24fc446-66f9-4727-a229-72700cec41d7) to view the Administrator certificate details:

![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FJxowU0j6zH2X9mJUt6GO%2Fimage.png?alt=media\&token=9d8cf5a5-af9f-423d-b2aa-cedc955d8786)&#x20;

**Renew:**

* Click on ![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2Fqfz0Bn1V4SGoiZYMd8Nd%2Fimage.png?alt=media\&token=32faae9b-cf7b-4e8b-8358-d78fd0730d74)to renew an Administrator that is about to expire.
* This icon is only available for soon-to-expire Administrators. The default threshold for expiring Administrators is 31 days but may vary depending on the customer specific configuration.

**Deactivate:**

* Click on ![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FtA5Nd1JFGmnR7QAADpgP%2Fimage.png?alt=media\&token=22a2a15b-4445-454b-ad80-9943d1eadff7) to deactivate an Administrator.
* Deactivating an Administrator blocks them from logging into emCA. It does not revoke their access but merely suspends it.
* After clicking on ![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FWmI7Ftk6ECGsRGlzvEDL%2Fimage.png?alt=media\&token=109502aa-6dbd-4c11-887f-7594b30f0d20), the following warning message is shown:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2F9z3kYSorLNuGvYFutAdV%2Fimage.png?alt=media&#x26;token=779571c5-5074-46b1-80ae-7a10392a28a9" alt=""><figcaption></figcaption></figure>

* Click **Yes** to proceed. You will be prompted to authenticate the deactivation action:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2F6uVKriBULAzMD4PJ7wRv%2Fimage.png?alt=media&#x26;token=6731b358-beae-4159-83f6-7334723005d5" alt=""><figcaption></figcaption></figure>

* Authenticate using all CA Administrator Credentials and proceed by pressing Authenticate.
* Click on Deactivate to proceed. The following message is displayed upon completion:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FgVI3j6nQ74nbQFCG5SjJ%2Fimage.png?alt=media&#x26;token=f15dbde6-ff7e-4b49-91b9-f3f8e76aed9e" alt=""><figcaption></figcaption></figure>

* Click on ![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FkL7K0vypfvIw1Hha3R74%2Fimage.png?alt=media\&token=6f7a50bb-04e2-4f98-bdc6-c78cd07a4e36) to activate an Administrator.
* Activating an Administrator reenables their access to emCA.
* After clicking on ![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FVJHIkRokZ9zHNMyu7QPR%2Fimage.png?alt=media\&token=edc570e0-d3f4-440e-b7a8-d67c10a91d02) , the following warning message is shown:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2Fz71JVFC4mGjYj3GBQFFW%2Fimage.png?alt=media&#x26;token=362686e4-3d4e-4f18-8223-4f5750a740d0" alt=""><figcaption></figcaption></figure>

Click Yes to proceed. You will be prompted to authenticate the activation action:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FsIUOtQbAD4680NWisMvI%2Fimage.png?alt=media&#x26;token=f248f0e2-eea3-4ab3-89c7-8a6160246eb7" alt=""><figcaption></figcaption></figure>

Authenticate using **all CA Administrator Credentials** and proceed by pressing Authenticate.

Click on **Activate** to proceed. The following message is displayed upon completion:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2Fnva6HOxztVRIEgsVuwJh%2Fimage.png?alt=media&#x26;token=dba77fa4-5ad9-44ce-afa7-96e3daa2a994" alt=""><figcaption></figcaption></figure>

* Click on ![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FLP7aH2GTzWSmfZ0VJ3hx%2Fimage.png?alt=media\&token=88737abd-402e-47d7-bce6-8b962f910166) to delete an Administrator.&#x20;
* An Administrator that has been deleted, cannot be recovered! Consider deactivating an Administrator before deleting it.
* After clicking on ![](https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2F12YMp4TTBZXWuNO09GSJ%2Fimage.png?alt=media\&token=ea7fb47e-9ef9-40c6-abb8-0b4dea0a6c99) , the following warning message is shown:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FKJgjyysaTeM7plZepZlm%2Fimage.png?alt=media&#x26;token=cade0c27-256b-47d2-a1a3-fa1d2f63593b" alt=""><figcaption></figcaption></figure>

Click Yes to proceed. You will be prompted to authenticate the deletion action:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FbaP3ZbXnNACSlTlppKjl%2Fimage.png?alt=media&#x26;token=61e5b79e-e642-4e9e-a315-74f762847804" alt=""><figcaption></figcaption></figure>

Authenticate using **all CA Administrator Credentials** and proceed by pressing **Authenticate.**

Click on **Delete** to proceed. The following message is displayed upon completion:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FS2EwkZ5wv3nOERqh3j80%2Fimage.png?alt=media&#x26;token=0ad1dc0d-5a5f-4de1-8ee7-f389e3fc4e31" alt=""><figcaption></figcaption></figure>

* Clicking on **Export to Excel** will trigger an automatic download of an XLSX file to the standard download location of your OS.
* The generated XLSX file will have the name **ManageUsers\_Report.xlsx.**
* This XLSX file contains the displayed table of Administrators in a tabular format.
