# Internal CA Certificate Issuer

Administrator shall crate a Profile under Issuing CA. These steps are covered under [Configure CA Certificate Profile](https://emca.emudhra.com/getting-started/configuring-certificate-profiles).

## **Officer Login**

Officer can use this profile to Sing the CSR as displayed in the following interface.

## **Generate Key Pair**

Click on "Generate Key Pair " to open the following dialog:

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FXklnjduEz1brxhtuzNLz%2Fimage.png?alt=media&#x26;token=647c972f-5979-4c98-bbb4-530c79522f19" alt=""><figcaption></figcaption></figure>

Enter the number of keys that you want to generate. In general, you will need 1 key for 1 CA and 1 more key, if that CA will receive an OCSP certificate.

Select the "Key Profile" you want to use from the first dropdown list.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FhJ8gVjxJxkviznDucWvh%2Fimage.png?alt=media&#x26;token=83af51c1-9c32-4514-baf6-194597b9d610" alt=""><figcaption></figcaption></figure>

Choose the "Algorithm" from the drop-down

Select the "Signature algorithm" from the third dropdown list. This will filter the element for the third dropdown list accordingly.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2F7KhZvAxA7GF6iFY8XDs5%2Fimage.png?alt=media&#x26;token=af1fb8dd-dfbc-401e-b9fc-0df58312c520" alt=""><figcaption></figcaption></figure>

Select the "Key Algorithm" and "Key Size" from the fourth dropdown list.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FQrn6gXgeQnfsBLnPTuco%2Fimage.png?alt=media&#x26;token=1ce18839-8b88-432f-b980-af1c36a737b4" alt=""><figcaption></figcaption></figure>

Press "Proceed" to continue and authenticate the action.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FkWvvMU52JlNK3Tkq0TfW%2Fimage.png?alt=media&#x26;token=cd861cf9-5a94-4141-b245-7cd8de3ef4a2" alt=""><figcaption></figcaption></figure>

Click on "Generate Key Pair(s)" to generate the keys.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FqBNjuhQ5X1E3tjf8JXvV%2Fimage.png?alt=media&#x26;token=1993d013-30b6-4445-8df3-e446d7a0af9f" alt=""><figcaption></figcaption></figure>

After the successful generation of the key pair, the success message as shown below.

Click on "View all" or "+ New" to continue with this new Key Pair creation.

## Generate CA Certificate

After creating a key pair, the user needs to select the "Generate Certificate" or "CSR" option available in the "Action" column of the created key pair.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2F2txyJqy2hcNMYpDv5C3R%2Fimage.png?alt=media&#x26;token=13312c28-bb8e-4fd9-8534-ab8861886ab0" alt=""><figcaption></figcaption></figure>

Click on  !\[A black flag on a white background

AI-generated content may be incorrect.]\(data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwkHBgoJCAkLCwoMDxkQDw4ODx4WFxIZJCAmJSMgIyIoLTkwKCo2KyIjMkQyNjs9QEBAJjBGS0U+Sjk/QD3/2wBDAQsLCw8NDx0QEB09KSMpPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT3/wAARCAA0ADgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1yLzpYwwcDNP8uf8A56Ci0/491ovLuOxtJLiX7kYyaTdtwSuHlz/89B+VHlz/APPQVi6F4ysNemeO33Iy/wB7vW+rq/3WB+hqrCIvLn/56Cjy5/8AnoKnpAwJ4IOKQytL50UZYuDiin3f/Hu1FABaf8e61HqkSTabOkgypQ8VJaf8e60l/wD8eM3+4amfwsqO6PCZZ5dP1GYWkhiwxAxU8PiPVoGzHeyCquo/8hKf/eqvketEG+VCkveZ0M3jjV5YdgnZTj7wrqPhxqN3etN9qnaX615tXoPwv+9NWsFuZz6HoN3/AMe7UUXf/Hu1FQWFp/x7rSX/APx4zf7hpbT/AI91qSSMSxsjdGGDSkrpoadnc8u8M+F7PxDe3kl5uwj4AWujm+GmjtERGJFbsc1u6RoVvo7zNASfNbcc1qU7KySFrds80Pwun+0cXKeVnp3rsvD/AIatPD8BS3yWb7xNbNFNNpWE1cgu/wDj3aii7/492opDC0/491qeiigAooooAKKKKAILv/j3aiiigD//2Q==) to start generating a CA certificate.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2Fh2UEvxPTbVMwQpZDwSEd%2Fimage.png?alt=media&#x26;token=08d51b99-a19d-4433-be65-bae4ee623a43" alt=""><figcaption></figcaption></figure>

The above window opens after clicking on “Action”.

Certificate – use the key to generate a new CA certificate directly.

Choose "Certificate" if you want to directly generate a new CA certificate. This option is applicable if the CA is "self-signed", or the "issuing CA" is in the same instance.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FFMhDtImbO6p3wzS48W2N%2Fimage.png?alt=media&#x26;token=ee066462-f00d-45b1-ae78-50e657940fdd" alt=""><figcaption></figcaption></figure>

CA Administrator created certificate profiles will be available under “Certificate profile” dropdown.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FvJp7csEjinhSXQpneXuA%2Fimage.png?alt=media&#x26;token=f149eea9-9d90-433c-a3cb-d2c779081be0" alt=""><figcaption></figcaption></figure>

For "Subject DN Details", enter all Subject Distinguished Name (Subject DN) information for the CA as per the certificate profile selection.

Press "Proceed" to continue. You will be prompted to authenticate the action using your officer token. Press "Authenticate" to proceed.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2F0rpOU3wSQDe6YqSST5oF%2Fimage.png?alt=media&#x26;token=572a5c3f-7f62-47f8-b681-c3b70e90ac97" alt=""><figcaption></figcaption></figure>

Officer is required to successfully authenticate and continue with “Create”.

<figure><img src="https://2804668976-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOwstGDJbR4yGRTr2aEFp%2Fuploads%2FvE7A7Iy121mKrhN7Ebl6%2Fimage.png?alt=media&#x26;token=b9b6cc93-df89-4301-b651-8131e2d11343" alt=""><figcaption></figcaption></figure>

The "Certificate" will be created, and the user is able to download the certificate.
