Creating an issuing CA under an online root CA

See below for how to create an issuing CA after Creating an online root CA.

To create an issuing CA

  1. Navigate to Administration > PKIaaS Management.

    images/download/attachments/161534792/image-2024-2-1_15-55-50-version-1-modificationdate-1706781350821-api-v2.png
  2. In the side pane, click Add Private CA.

  3. In Select CA, choose Issuing Certificate Authority.

    images/download/attachments/161534792/image-2022-11-23_13-45-5-version-1-modificationdate-1669189505661-api-v2.png
  4. Click Next to display the CA Information screen.

    images/download/attachments/161534792/image-2023-6-6_16-39-54-version-1-modificationdate-1686069595030-api-v2.png
  5. Enter the values described below .

  6. Click Next to review the CA information.

    images/download/attachments/161534792/worddav644f0e96024f7093331a0fae6679dde8-version-1-modificationdate-1652777705079-api-v2.png
  7. Click Submit.

  8. In the confirmation request, click OK to start the CA creation process.

  9. When the CA creation completes, check the CA details in the CA grid view.

  10. Refresh the grid. You will notice that the status changes to Active.

Root CA

Select the CA created in Creating an online root CA.

Mandatory: Yes.

Friendly Name

Enter an informal name for the new CA.

Mandatory: Yes.

Signing Key Details

Select one of the algorithms described in Certification Authority instantiation.

Mandatory: Yes.

Region

This view-only field displays the region of the root CA.

You cannot change the region for an issuing CA. The region of the issuing CA will be decided by the region of the root CA that signs the issuing CA.

Enable OCSP

Check box if you want to enable OCSP for this issuing CA.

You cannot change this setting after provisioning the CA.

Mandatory: No.

Expiry Date

Select the expiry date for the CA certificate. Use the date picker or enter a date in the following format.

mm/dd/yyyy

The expiry date of an issuing CA must be earlier than the expiry date of the root CA.

Mandatory: No. If you do not assign a specific expiry date, the expiry period defaults to 10 years for issuing CAs.

Services

Select a predefined set of certificate profiles. For example,

Mandatory: No.

Distinguished Name Fields

Enter a value for each field in the Distinguished Name of the CA certificate.

Mandatory: Only the Common Name certificate field.