Adding SSL certificates
Enroll an SSL certificate in SCM
Domains must be added and validated before enrolling for publicly trusted SSL certificates. For more information, see Understanding domains. |
-
Navigate to
. -
Click the Add icon.
-
Select Using a Certificate Signing Request (CSR), and click Next.
-
Complete the Details tab fields based on the information provided in the following table.
Field Description Organization
The organization to which the certificate belongs.
Department
The department to which the certificate belongs.
Certificate Profile
The certificate profile to be used for certificate issuance.
Certificate Term
The validity period of the certificate. The available terms are dependent on the certificate profile.
Comments
Comments or notes about the certificate.
External Requesters
The email address of any external requester(s).
Depending on your configuration, additional custom fields may be available. -
Click Next.
-
On the CSR tab, paste your CSR, and click Next.
-
Complete the Domains tab.
-
If prompted, enter any required Subject Alternative Names (SANs).
-
Click Next.
-
-
If prompted, on the EV details tab, review the EV details, and click Next.
EV details for the organization can be updated on the Organizations page. For more information, see Update EV details. -
Complete the Auto-Renewal tab.
-
(Optional) Enable auto-renewal.
-
Specify whether or not a new key pair should be created when the certificate is renewed.
-
Set the number of days prior to expiration that the certificate should be renewed.
-
-
Click Next/OK.
-
-
If prompted, read the EULAs, select I Agree for each, and click OK.
This requires the configuration of a private key agent. For more information, see Understanding private key agents. |
-
Navigate to
. -
Click the Add icon.
-
Select Generation of CSR, and click Next.
-
Complete the Details tab fields based on the information provided in the following table.
Field Description Organization
The organization to which the certificate belongs.
Department
The department to which the certificate belongs.
Certificate Profile
The certificate profile to be used for certificate issuance.
Certificate Term
The validity period of the certificate. The available terms are dependent on the certificate profile.
Comments
Comments or notes about the certificate.
External Requesters
The email address of any external requester(s).
Depending on your configuration, additional custom fields may be available. -
Click Next.
-
Complete the Private Key tab.
-
Select a key type.
-
(Optional) Set a password required to download the private key for the issued certificate.
Make note of the password for future use. -
Click Next.
-
-
Complete the Domains tab.
-
Enter the domain for which the certificate will be issued.
-
Enter any required Subject Alternative Names (SANs).
-
Click Next.
-
-
If prompted, on the EV details tab, review the EV details, and click Next.
EV details for the organization can be updated on the Organizations page. For more information, see Update EV details. -
Complete the Auto-Renewal tab.
-
(Optional) Enable auto-renewal.
-
Specify whether or not a new key pair should be created when the certificate is renewed.
-
Set the number of days prior to expiration that the certificate should be renewed.
-
-
Click Next/OK.
-
-
If prompted, read the EULAs, select I Agree for each, and click OK.
This requires the configuration of a network agent for the appropriate organization. For more information, see Understanding network agents. |
-
Navigate to
. -
Click the Add icon.
-
Select Generation of CSR with Auto-Installation, and click Next.
-
Complete the Details tab fields based on the information provided in the following table.
Field Description Organization
The organization to which the certificate belongs.
Department
The department to which the certificate belongs.
Certificate Profile
The certificate profile to be used for certificate issuance.
Certificate Term
The validity period of the certificate. The available terms are dependent on the certificate profile.
Comments
Comments or notes about the certificate.
External Requesters
The email address of any external requester(s).
Depending on your configuration, additional custom fields may be available. -
Click Next.
-
Complete the Private Key tab.
-
Select a key type.
-
Click Next.
-
-
Complete the Domains tab.
-
Enter the domain for which the certificate will be issued.
-
Enter any required Subject Alternative Names (SANs).
-
Click Next.
-
-
If prompted, on the EV details tab, review the EV details, and click Next.
EV details for the organization can be updated on the Organizations page. For more information, see Update EV details. -
Complete the Nodes & Ports tab.
For information on configuring nodes and ports, see Configuring network agents. -
Click the Add icon.
-
Select the node(s) to which the certificate will be installed.
-
Click Next.
-
-
Complete the Auto-installation tab.
-
Specify whether certificate installation should be performed manually or on a schedule.
-
If scheduled, configure the installation schedule.
-
Click Next.
-
-
Complete the Auto-Renewal tab.
-
(Optional) Enable auto-renewal.
-
Specify whether or not a new key pair should be created when the certificate is renewed.
-
Set the number of days prior to expiration that the certificate should be renewed.
-
-
Click Next/OK.
-
-
If prompted, read the EULAs, select I Agree for each, and click OK.
This requires the configuration of Azure Key Vault. For more information, see Configuring Azure Key Vault. |
-
Navigate to
. -
Click the Add icon.
-
Select Generation of CSR in Azure Key Vault, and click Next.
-
Complete the Details tab fields based on the information provided in the following table.
Field Description Organization
The organization to which the certificate belongs.
Department
The department to which the certificate belongs.
Certificate Profile
The certificate profile to be used for certificate issuance.
Certificate Term
The validity period of the certificate. The available terms are dependent on the certificate profile.
Comments
Comments or notes about the certificate.
External Requesters
The email address of any external requester(s).
Depending on your configuration, additional custom fields may be available. -
Click Next.
-
Complete the Private Key tab based on the information provided in the following table.
Field Description Azure Account
The name of the SCM Azure account configured for the Azure Key Vault.
Resource Group
The name of the resource group in Azure containing the appropriate Azure Key Vault.
Key Vault
The name of the Azure Key Vault in which the CSR should be generated.
Key Type
The key size or curve to be used for encrypting the private key.
Reuse Key
Indicates whether the existing private key should be reused when renewing the certificate. If this policy is changed in Azure, the Azure policy will take precedence during certificate renewal or replacement.
Once the certificate is issued, this setting cannot be changed.
Exportable Key
Indicates whether the private key can be exported from the Azure Key Vault. If this policy is changed in Azure, the Azure policy will take precedence during certificate renewal or replacement.
Once the certificate is issued, this setting cannot be changed.
Store Key in HSM
Indicates whether the key will be stored in a hardware security module (HSM).
Once the certificate is issued, this setting cannot be changed.
-
Click Next.
-
Complete the Domains tab.
-
Enter the domain for which the certificate will be issued.
-
Enter any required Subject Alternative Names (SANs).
-
Click Next.
-
-
If prompted, on the EV details tab, review the EV details, and click Next.
EV details for the organization can be updated on the Organizations page. For more information, see Update EV details. -
Complete the Auto-Renewal tab.
-
(Optional) Enable auto-renewal.
-
Specify whether or not a new key pair should be created when the certificate is renewed.
-
Set the number of days prior to expiration that the certificate should be renewed.
-
-
Click Next/OK.
-
-
If prompted, read the EULAs, select I Agree for each, and click OK.
Import SSL certificates
-
Navigate to
. -
Click the Import icon.
-
Select the organization to which the certificates will be assigned.
-
(Optional) Select the department to which the certificates will be assigned.
-
Click Next.
-
Click the Upload SSL button.
-
Select your
.zip
file, and click Open.Certificates in the .zip
file must be in.cer
,.crt
, or.pem
format.