(DC) [CertMgr] Certificate Request (New)

(DC) [CertMgr] Certificate Request (New)

Description

The articles describes using the Sectigo / InCommon Certificate Manager to generate a new SSL Certificate based on a provided Certificate Signing Request and other required information from the customer in a service ticket.

If a certificate is download in one format, it can be easily converted to other formats.  Please refer to:  (DC) Certificate Format Conversion

Step to request certificate(s)

Prerequisite

Ensure that all information necessary to process a certificate is included in the request. Refer to: (DC) What to include in a request

Process

  1. Login into the Sectigo / InCommon Certificate Authority Certificate Manager.
    (DC) [CertMgr] Logging into Certificate Manager

  2. Locate the (hamburger menu icon) and click to expose the navigation menu.   Locate "Certificates", click the down arrow, click it to expose and click "SSL Certificates".

  3. A list of certificates will appear.  Locate the following icons (list options). 

    1. Click the filter icon (filter_icon.png) and click it. 

    2. Under the "Group By", choose "Requester".

    3. Click filter_icon.png.

    4. Under the "Add Filter" choose "Common Name".   Type in the FQDN, domain name, or certificate common name (it has various names) into the field.  You can use partial word searches, you do not need to type in the entire FQDN.

    5. Click + Add Filter.

  4. The list will now update with common names that match you filter criteria.  You should see something like below.

  5. Locate the ADD ( ) button and click it.  You should see the following:

  6. Select "Using a Certificate Signing Request (CSR)".    Click Next .

Please note that the other options "Generation of CSR", "Generation of CSR with Auto Installation" and "Generations of CSR in Azure Key Vault" are not supported.  DO NOT choose any of these options.

  1. A request form will appear:

  2. Fill in the appropriate fields.   Most fields will be auto-populated and this should NOT be changed unless you know exactly what you are doing.

    • Certificate Profile:

      • For standard certificates (without SAN, wildcard, or EV requirement) choose:  InCommon SSL (SHA-2) → may be changing to InCommon SSL Single General Profile

      • For certificates with SANs, choose: InCommon SSL Multi Domain General Profile

      • For wildcard certificates, choose: InCommon SSL Wildcard Certificate

      • For all other certificates, please consult with tier-2 support.

    • Certificate Term Length:  Choose from 1-year (365 days) or 398 days (1-year + 1 month).

    • Commentsoptional, add anything relevant.

    • Notifications:  The GROUP email address should be placed here.

  3. Click Next.

  4. Paste the CSR from the file provided by the customer / requester. 
    You can also click the upload () button to upload the CSR from a file on your computer.

  5. Click Next.

  6. Update the request regarding domains.

    1. If this a standard certificate (" InCommon SSL (SHA-2)"), then only the domain verification appears.

    2. If the certificate profile was "InCommon Multi Domain SSL (SHA-2)", then you are given thew option to update any changes to the SANs list.  If SANs entries were part of the CSR, they are populated here.

  7. Click Next.

  8. In the next option, ensure the "Enable Auto-Renew" feature is DISABLEDThis feature is NOT supported.

  9. Go back and forth through the pages to ensure all information is correct, then proceed to the last page and click "OK".  The certificate will be generated.
    If the "Request New SSL Certificate" window does not close, you will need to click the CLOSE button.

At this point, the certificate processing has begun.  If the filter you used above is still in place, you will see a new line appear in the list of certificates matching the filter (which the new one will), and should have the status of "Requested" and will soon change to "Issued".

Once the status is issued, you can proceed to download / retrieve the certificate: (DC) [CertMgr] Certificate Download