Renew Certificate

This workflow allows you to renew a certificate based on the certificate group and certificate authority.

To trigger this workflow:

  1. From the Certificate Lifecycle Automation catalog, under the Renewal category, hover your mouse over the Renew Certificate workflow and click .
    Tip: You can also search for the workflow by typing the workflow name in the search bar.
    The workflow execution page is displayed with the workflow inputs requested at the first stage.
  2. Under the General Information section, select the Certificate Type (mandatory).
  3. Under the General Information section, select the Assign Group (mandatory).
  4. Under the CA Details section, select the Certificate Authority (mandatory).
  5. Under the CA Details section, add a description for the certificate being renewed (optional).
  6. Under the Certificate Information section, select the Certificate from the dropdown list (mandatory).
    The Serial Number field is populated based on the Certificate selected.
  7. Under the CSR Parameters section, enter or select the requested field information as described in the table below.
    Table 1. Field Description for CSR Parameters section
    Field Description
    *Common Name Enter the Fully Qualified Domain Name (FQDN) of the server for which the certificate is requested.
    Subject Alternative Name (SAN) Select the SAN as either:
    • DNS
    • IP Address
    DNS Enter a valid DNS if you select the DNS option in the SAN field.
    IP Address Enter a valid IP Address if you select the IP Address option in the SAN field.
    Organization Enter the name of the organization.
    Organization Unit Enter the name of the organization unit with which the certificate will be associated.
    State Enter the name of the state in which the organization is located.
    Country Enter the name of the country in which the organization is located.
    Zip Code Enter the zip code of the organization.
    Note: This field is displayed only when DigiCert is selected as the Certificate Authority.
    Email Address Enter the email address.
    *Validity Unit Select the validity unit as:
    • Days
    • Months
    • Years
    *Validity Value Select a valid validity value.
    *Key Type Select a Key Type from the available options.
    *Bit Length Select the Bit Length from the available options. The values displayed in the dropdown will differ depending on the Key Type selected.
    *Hash Function Select the Hash Function from the available options.
    All Asterisk (*) marked fields are mandatory.
  8. Under the Certificate Attributes section, select the Attribute from the available options.
  9. Enter a value for the selected attribute.
    Table 2. Actions available in the Certificate Attributes grid
    Action Description
    Allows you to add the attribute to the Certificate Attributes grid.
    Allows you to edit the value of a particular attribute. You can do this by selecting the attribute in the grid, click , enter the new value for the attribute, and click again.
    Allows you to delete a certificate attribute.
    Allows you to maximize the Certificate Attributes grid.
    Search bar Allows you to search for a particular attribute in the grid.
  10. Under the Vendor Specific Details section, select the field information from the options available in the dropdown.
    Note: This section is displayed only when DigiCert, EJBCA, or Entrust is selected as the Certificate Authority under the CA Details section. The field(s) displayed will vary based on the CA selected.
  11. Under the Notifications section, enter the Email ID to which the certificate creation notification will be sent.
    Note: The Email ID field will auto-populate with the logged in user’s email address by default if the email address has been configured in the SMTP settings. You can also enter a different email address in this field or enter multiple email addresses separated by commas.
  12. Click Submit.
    Certificate is renewed successfully.
  13. To download the certificate, at the View | Download Certificate stage, hover your mouse over and from the options displayed, click Download Certificate.
  14. Hover your mouse over to view the Certificate status.