Setting up TLS Issuance
For TLS Issuance, firstly Administrator needs to create a TLS Certificate Profile, using which an Officer can create and issue the TLA certificate.
TLS Certificate Profile Creation
Login as an Administrator
Click on Manage Profiles
Certificate Profiles -> X509

Click on “+New Profile” to create a new certificate profile

Basic Information
Profile Type: User for SSL/ TLS Certificates
Sub Type: New
Profile Name: anything for identification
Validity: as per your Region Certifying Authority Guidelines
Issuing CA: Select your Issuer CA
Signature Algorithm: Select the preferred Algorithm type for SSL/TLS Certificate
Subject DN Details: Select as per your SSL Guidelines
Common Name
Email
Country
Organization
Organization Unit

Certificate Extensions: Select as per your SSL Guidelines
Basic Constraint
Key Usage
Enhanced Key Usage
Authority Key Identifier
Subject Key Identifier
Subject Alternative Name
CRL Distribution Points
Certificate Policy
Authority Information Access

Authentication: Administrator needs to authentication for Security Purpose

X509 TLS Certificate Profile successful creation after successful authentication.

Same certificate with the profile basic information and status will be displayed under the menu. An Officer can issue the TLS using this Certificate Profile created by Administrator.

TLS Certificate Issuance
Officer can use the TLS Certificate Profile created by Administrator to create and issue the TLS Certificates or Sign CSR for TLS Certificates as a CA. This section covers both.
Issue New TLS Certificate
Login as an Officer
Click on Manage User Certificates -> Enroll
Select the Token (Soft/Hard) where the Certificate needs to be stored
Select the TLS Certificate Profile that Administrator has created
Enter Subject DN, SAN, and other details as per the Certificate Profile
Authentication as an Officer before requesting to create the certificate for security purposes

After successful authentication, please proceed to “Create” the certificate.

Certificate will be ready to “Download”

Sign CSR
If the request is coming from Client/ externals in the form of CSR – follow this tutorial.
Login as an Officer
Click on Manage User Certificates -> Sign CSR
Select the Configuration Type, either file Upload or Text Area
Select the Certificate Profile crested by Administrator
Finally, the Certifying Authority (CA)

Click on Proceed
Enter CSR details as per the Certificate Profile
Common Name
Email
Country
Organization
Organization Unit
SAN details

Check Other details
Key Size
Certificate Profile
Certifying Authority
Click on Proceed

Authenticate as an Officer
Finally, Sign CSR

Signed CSR as a CA will be ready to download for TLS issuance.
Last updated