Enroll Certificate and Download

This workflow enables you to create and download certificates based on the certificate group.

To trigger this workflow:

  1. From the Certificate Lifecycle Automation catalog, under the Enrollment category, hover your mouse over the Enroll Certificate and Download workflow and click .
    The workflow execution page is displayed with the workflow inputs requested at the first stage.
  2. Under the Certificate Details section, select the requested field information as described in the table below.
    Table 1. Field description for Certificate Details section
    Field Description
    *Certificate Type Select the required Certificate Type from the available options:
    • Server
    • Client
    • Code Signing
    Note: Server is the default selection.
    *Certificate Group Select the required Certificate Group from the options available in the dropdown.
    All asterisk (*) marked fields are mandatory.
  3. Under the CA Details section, enter or select the requested field information as described in the table below.
    Table 2. Field description for CA Details section
    Field Description
    *Certificate Authority Select the Certificate Authority from the available options:
    • DigiCert
    • Entrust
    • EJBCA
    • Microsoft Enterprise
    • AppViewX
    Note: This list will be populated based on the Certificate Group selected in the Certificate Details section.
    *CA Account Select the CA Account from the options available in the dropdown. Note: This field is populated based on the CA selected.
    *Division Select the Division from the options available in the dropdown.
    Note: This field is displayed only when Digicert is selected as the CA.
    *Cert Type Select the Cert Type from the options available in the dropdown.
    Note: This field is displayed only when DigiCert or Entrust are selected as the CA.
    Description Enter a Description of the workflow, if required.
    All asterisk (*) marked fields are mandatory.
  4. Under the CSR Parameters section, enter or select the requested field information as described in the table below.
    Table 3. Field description for CSR Parameters section
    Field Description
    *Common Name Enter the Fully Qualified Domain Name (FQDN) of the server for which certificate is requested.
    Subject Alternative Name (SAN) Select the SAN as either:
    • DNS
    • IP Address
    DNS Enter a valid DNS, if you select the DNS option in the SAN field.
    IP Address Enter a valid IP address, if you select the IP Address option in the SAN field.
    Organization Enter the name of the organization.
    Organization Unit Enter the name of the organization unit with which the certificate will be associated.
    State Enter the name of the state in which the organization is located.
    Country Enter the name of the country in which the organization is located.
    Zip Code Enter the zip code of the organization.
    Note: This field is displayed only when DigiCert is selected as the Certificate Authority.
    Email Address Enter the email address.
    *Validity Unit Select the validity unit as:
    • Days
    • Months or
    • Years
    *Validity Value Select a valid validity value.
    *Key Type Select a Key Type from the available options.
    *Bit Length Select the Bit Length from the available options. The values displayed in the dropdown will differ depending on the Key Type selected.
    *Hash Function Select the Hash Function from the available options.
    All Asterisk (*) marked fields are mandatory.
  5. Under the Certificate Attributes section, select the Attribute from the available options.
  6. Enter a value for the selected attribute.
    Table 4. Actions available in the Certificate Attributes grid
    Action Description
    Allows you to add the attribute to the Certificate Attributes grid.
    Allows you to edit the value of a particular attribute. You can do this by selecting the attribute in the grid, click , enter the new value for the attribute, and click again.
    Allows you to delete a certificate attribute.
    Allows you to maximize the Certificate Attributes grid.
    Search bar Allows you to search for a particular attribute in the grid.
  7. Under the Vendor Specific Details section, select the field information from the options available in the dropdown.
    Note: This section is displayed only when DigiCert or EJBCA is selected as the Certificate Authority under the CA Details section. The field(s) displayed in this section will vary based on the CA selected.
  8. Under the Notifications section, enter the Email ID to which the certificate creation notification will be sent.
    Note: This field will auto-populate with the logged in user’s email address by default if the email address has been configured in the SMTP settings. You can also enter a different email address in this field or enter multiple email addresses separated by commas.
  9. Click Submit.
    The certificate is created successfully and an email notification is sent to the recipient specified in the input form.
  10. To download the certificate, at the View | Download Certificate stage, hover your mouse over and from the options displayed, click Download Certificate.
  11. Hover your mouse over to view the Certificate status.