Setting up Client Auth Certificates
For Client Auth Certificates, firstly Administrator needs to create a Client Authentication Certificate Profile, using which an Officer can create and issue the certificates.
Client Auth Certificate Profile Creation
Login as an Administrator
Click on Manage Profiles
Certificate Profiles -> X509

Click on “+New Profile” to create a new certificate profile

Basic Information
Profile Type: User for Client Auth Certificates
Sub Type: New
Profile Name: anything for identification
Validity: as per your Region Certifying Authority Guidelines
Issuing CA: Select your Issuer CA
Signature Algorithm: Select the preferred Algorithm type for Client Auth Certificates
Subject DN Details: Select as per your SSL Guidelines
Common Name
Email
Country
Organization
Organization Unit

Certificate Extensions: Select as per your SSL Guidelines
Basic Constraint
Key Usage
Enhanced Key Usage
Authority Key Identifier
Subject Key Identifier
Subject Alternative Name
CRL Distribution Points
Certificate Policy
Authority Information Access

Authentication: Administrator needs to authentication for Security Purpose
X509 Client Auth Certificate Profile creates successfully.

Same certificate with the profile basic information and status will be displayed under the menu. An Officer can issue the TLS using this Certificate Profile created by Administrator.

Client Auth Certificate Issuance
Officer can use the Client Auth Certificate Profile created by Administrator to create and issue the Client Auth Certificates or Sign CSR for Client Auth Certificates as a CA. This section covers both.
Enroll New Client Auth Certificate
Login as an Officer
Click on Manage User Certificates -> Enroll
Select the Token (Soft/Hard) where the Certificate needs to be stored
Select the Client Auth Certificate Profile that Administrator has created
Enter Subject DN, SAN, and other details as per the Certificate Profile
Authentication as an Officer before requesting to create the certificate for security purposes

After successful authentication, please proceed to “Create” the certificate.

Certificate will be ready to “Download”.
Sign CSR
If the request is coming from Client/ externals in the form of CSR – follow this tutorial.
Login as an Officer
Click on Manage User Certificates -> Sign CSR
Select the Configuration Type, either file Upload or Text Area
Select the Certificate Profile crested by Administrator
Finally, the Certifying Authority (CA)

Click on Proceed
Enter CSR details as per the Certificate Profile
Common Name
Email
Country
Organization
Organization Unit
SAN details

Check Other details
Key Size
Certificate Profile
Certifying Authority
Click on Proceed
Authenticate as an Officer
Finally, Sign CSR

Signed CSR as a CA will be ready to download for TLS issuance.
Last updated