External CAs
External CA could be used which may be operated internally by the organisation operating the ADSS Server or alternatively it may be a CA operated by an external managed certificate service provider.
Integration of ADSS Server with other External CAs is possible because standard data structures are used by ADSS Server (e.g. PKCS#10 for certificate requests and PKCS#7 for certificate responses).
When using an external CA to issue certificates for keys generated by the ADSS Certification Services then the workflow is expected to be as follows:
The ADSS Developers Guide explains the XML schema used for both the certification service request messages and the certification service response messages.
To configure the settings for external CAs, click the Configure External CAs button in the screenshot below. This shows a list of configured external CAs:
You can configure as many External CAs as your license allows. Clicking on the New button will show the screen to configure the following External CAs:
By clicking on the Issued Certificate button after selecting the relevant External CA, the following screen will be displayed where all the certificates issued by this CA are shown:
This screen shows certificates issued by Key Manager, Certification Service and Manual Certification while the Certification Service's Issued Certificate sub module only shows the certificates issued by the Certification Service.
You can select a certificate, and then either View, Revoke or Delete it. Clicking on Revoke button will show the following screen where invalidity date, revocation code and hold instruction code can be provided before revoking the certificate:
A certificate revoked with the certificateHold instruction code can be activated later on by using the Reinstate button.
By clicking on the Search button on Issued Certificates main page will display following screen:
See also