Creating a New Certificate Authority

The first page of the Certificate Authority Settings form is used to create the Onboard Certificate Authority (CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.) and to configure some basic properties:

Give it a name and description

Specify root CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate., intermediate CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate., local CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate., or Registration Authority Type of Certificate Authority that processes certificate requests. The Registration Authority verifies that requests are valid and comply with certificate policy, and authenticates the user's identity. The Registration Authority then forwards the request to the Certificate Authority to sign and issue the certificate. (RA Router Advertisement. The RA messages are sent by the routers in the network when the hosts send multicast router solicitation to the multicast address of all routers.) mode

Configure the identity, private key The part of a public-private key pair that is always kept private. The private key encrypts the signature of a message to authenticate the sender. The private key also decrypts a message that was encrypted with the public key of the sender., and self-signed certificate attributes

To create an Onboard Certificate Authority, go to Onboard > Certificate Authorities, and then either click the Duplicate link for a Certificate Authority in the Certificate Authorities list or click the Create new certificate authority link. The initial setup page of the Certificate Authority Settings form opens.

Figure 1  Mode Options on the Certificate Authority Settings Form

Certificate Authority Settings Form, Basic and Mode Areas

Field

Description

Name

Short name that clearly identifies the Certificate Authority. Certificate Authority names can include spaces. If you are duplicating a CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate., the original name has "Copy" appended to it. You may highlight the name and replace it with a new name.

Description

You may include a brief description of the CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.. This description is shown in the Certificate Authorities list.

The Name and Description fields are used internally to identify this Certificate Authority for the network administrator. These values are never displayed to the user during device provisioning.

Mode

Specifies the type of Certificate Authority:

Root CA—The Onboard Certificate Authority issues its own root certificate. The Certificate Authority issues client and server certificates using a local signing certificate, which is an intermediate CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate. that is subordinate to the root certificate. Use this option when you do not have an existing public-key infrastructure (PKI Public Key Infrastructure. PKI is a security technology based on digital certificates and the assurances provided by strong cryptography. See also certificate authority, digital certificate, public key, private key.), or if you want to completely separate the certificates issued for Onboard devices from your existing PKI Public Key Infrastructure. PKI is a security technology based on digital certificates and the assurances provided by strong cryptography. See also certificate authority, digital certificate, public key, private key..

Intermediate CA—The Onboard Certificate Authority is issued a certificate by an external Certificate Authority. The Onboard Certificate Authority issues client and server certificates using this certificate. Use this option when you already have a public-key infrastructure (PKI Public Key Infrastructure. PKI is a security technology based on digital certificates and the assurances provided by strong cryptography. See also certificate authority, digital certificate, public key, private key.), and would like to include the certificate issued for Onboard devices in that infrastructure.

Imported CA— If you choose Imported CA, the following fields are removed from the form. If you choose Root or Intermediate, complete the following fields.

Registration Authority — Onboard is used as the Registration Authority Type of Certificate Authority that processes certificate requests. The Registration Authority verifies that requests are valid and comply with certificate policy, and authenticates the user's identity. The Registration Authority then forwards the request to the Certificate Authority to sign and issue the certificate. (RA Router Advertisement. The RA messages are sent by the routers in the network when the hosts send multicast router solicitation to the multicast address of all routers.). Instead of issuing certificates, Onboard will proxy a certificate request to another Certificate Authority (CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.) via SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates.. Only client certificates are stored locally.

Figure 2  The Identity Area

Certificate Authority Settings Form, Identity Area

Field

Description

Country

Two-letter ISO country code for your organization. This value forms part of the distinguished name for the certificate.

State

Full name of the state or province for your organization. This value forms part of the distinguished name for the certificate.

Locality

Name of the town or city where your organization is located. This value forms part of the distinguished name for the certificate.

Organization

Name of your organization. This value forms part of the distinguished name for the certificate.

Organizational Unit

(Optional) Name of your organizational unit (section or division of the organization). This value forms part of the distinguished name for the certificate.

Common Name

Descriptive name for the certificate. This value is used to identify the certificate as the issuer of other certificates, notably the signing certificate.

Signing Common Name

(Included for root certificates) Descriptive name for the signing certificate. This value is used to identify the signing certificate as the issuer of client and server certificates from this Certificate Authority. The other identity information in the signing certificate will be the same as for the root certificate.

Email Address

Contact email address. This email address is included in the root and signing certificates, and provides a way for users of the certificate authority to contact your organization.

Figure 3  The Private Key and Self-Signed Certificates Areas

Certificate Authority Settings Form, Private Key and Self-Signed Certificates Areas

Field

Description

Key Type

Specify the type of private key The part of a public-private key pair that is always kept private. The private key encrypts the signature of a message to authenticate the sender. The private key also decrypts a message that was encrypted with the public key of the sender. that should be created for the certificate:

1024-bit RSA (Not recommended for a root certificate. Not available in FIPS Federal Information Processing Standards. FIPS refers to a set of standards that describe document processing, encryption algorithms, and other information technology standards for use within non-military government agencies, and by government contractors and vendors who work with these agencies. mode.)

2048-bit RSA (Recommended for general use.)

4096-bit RSA (Higher security.)

X9.62/SECG curve over a 256-bit prime field

NIST/SECG curve over a 384-bit prime field

CA Expiration

(Included for root certificates) Specifies the lifetime of the root certificate in days. The default value is 365 days.

Digest Algorithm

Specifies which hash algorithm should be used to sign the digital certificate A digital certificate is an electronic document that uses a digital signature to bind a public key with an identity—information such as the name of a person or an organization, address, and so forth. request. Options include:

SHA-1 (not recommended)

SHA-224

SHA-256

SHA-384

SHA-512 (Default)

Create Certificate Authority

Creates the Certificate Authority:

If you selected root mode, the root certificate is included in the Certificate Authorities list.

If you selected intermediate mode, the Intermediate Certificate Request page opens with text for the certificate signing request (CSR Certificate Signing Request. In PKI systems, a CSR is a message sent from an applicant to a CA to apply for a digital identity certificate.). You can send the CSR Certificate Signing Request. In PKI systems, a CSR is a message sent from an applicant to a CA to apply for a digital identity certificate. to a Certificate Authority, who will generate a signed certificate you can install. See Requesting a Certificate for the Certificate Authority.

If you selected imported mode, the Certificate Authority Certificate Import form opens, where you can upload the digital certificates A digital certificate is an electronic document that uses a digital signature to bind a public key with an identity—information such as the name of a person or an organization, address, and so forth. and private key The part of a public-private key pair that is always kept private. The private key encrypts the signature of a message to authenticate the sender. The private key also decrypts a message that was encrypted with the public key of the sender. to the server. SeeInstalling a Certificate Authority’s Certificate .

Figure 4  The Registration Authority Area

Certificate Authority Settings Form, Registration Authority Area

Field

Description

SCEP URL

URL Uniform Resource Locator. URL is a global address used for locating web resources on the Internet. of the SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates. server that will act as the Certificate Authority (CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.) for this Registration Authority Type of Certificate Authority that processes certificate requests. The Registration Authority verifies that requests are valid and comply with certificate policy, and authenticates the user's identity. The Registration Authority then forwards the request to the Certificate Authority to sign and issue the certificate..

SCEP Challenge Password

Shared secret for the SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates. Certificate Authority, used for generating the Registration Authority Type of Certificate Authority that processes certificate requests. The Registration Authority verifies that requests are valid and comply with certificate policy, and authenticates the user's identity. The Registration Authority then forwards the request to the Certificate Authority to sign and issue the certificate. certificate. If the SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates. server will not enforce a challenge password, leave this field empty.

 

Confirm SCEP Challenge Password

CRL URL

URL Uniform Resource Locator. URL is a global address used for locating web resources on the Internet. of the Certificate Revocation List (CRL Certificate Revocation List. CRL is a list of revoked certificates maintained by a certification authority.) for the Certificate Authority. If a URL Uniform Resource Locator. URL is a global address used for locating web resources on the Internet. is entered in this field, Onboard will synchronize the revocation status of certificates.

Fetch CA Certificate

The form expands to show the CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate. certificate details and additional fields for confirming the certificate and customizing the certificate subject.

Confirm CA Certificate

if selected, validates that the certificate is the trusted certificate for your Certificate Authority.

Details

Displays the details of the certificate.

Certificate Subject

if selected, the form expands to include options for modifying the subject fields of the certificates used for the SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates. protocol.

Certificate Subject

if selected, the form expands to include options for modifying the subject fields of the certificates used for the SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates. protocol.

SCEP Client, SCEP Signing, and SCEP Encryption Areas

Country

Two-letter ISO country code for your country.

State

Full name of your state or province.

Locality

Name of your city or town.

Organization

Name of your company or organization.

Organizational Unit

Name of your organizational unit (the section or division or your company).

Common Name

Name for the certificate. This will be the common name of the digital certificate A digital certificate is an electronic document that uses a digital signature to bind a public key with an identity—information such as the name of a person or an organization, address, and so forth..

Email Address

Enter an email address.

Create Certificate Authority

Creates the certificate authority. The RA Router Advertisement. The RA messages are sent by the routers in the network when the hosts send multicast router solicitation to the multicast address of all routers. certificate is included in the Certificate Authorities list.

After you have configured the SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates.-RA Router Advertisement. The RA messages are sent by the routers in the network when the hosts send multicast router solicitation to the multicast address of all routers. certificate, you may specify the CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate. to use for TLS Transport Layer Security. TLS is a cryptographic protocol that provides communication security over the Internet. TLS encrypts the segments of network connections above the Transport Layer by using asymmetric cryptography for key exchange, symmetric encryption for privacy, and message authentication codes for message integrity.  certificates independently of the CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate. used for enrollment by using the SCEP-RA option in the TLS Certificate Authority and Certificate Authority fields on the Provisioning Settings form. For more information, see Configuring General Provisioning Settings.