CSR-based Requests
This section explains how to create CSR-based certificate requests in the Web RA application.
Following are a few things to remember with respect to SDNs, SANs and RDNs:
- When a user creates a new certificate request, the SDNs and SANs will be rendered as configured in the certification profile and its values will be auto-filled from the certificate details.
- A user will not be able to change the values of the RDNs if an operator has configured them in the certificate details.
- An operator will see the rendered values in a disabled form.
- If there is an RDN that is added in certification profile but has not been configured in the user's certificate details, it will be shown as editable in the request form and the user can update its value.
- If no RDN is configured in the user certificate details then the request will be generated.
- In case of an error, the user will not be allowed to move to the next step.
Second Factor Authentication
If second-factor authentication is enabled for certificate requests, the configured authentication mechanism operates accordingly. When the user clicks Generate, an authentication window appears. After the selected method is successfully verified, the certificate is generated.
The authentication mechanism can be one of the following:
- SMS OTP Authentication
- Email OTP Authentication
- Email & SMS Authentication
- SAML Authentication
- Active Directory Authentication
- Azure Active Directory Authentication
- OIDC Authentication
Request Notes
If an operator has added a customized Request Note to certificate requests for a specific enterprise, it will appear in all types of certificates requests -- issued, rekey, revoked, renewed and reissued. The Request Notes appear only on the screens against which the operator has customised them.
An operator can configure Request Notes from the Enterprise Request Notes section in the Admin portal.
The following steps describe how to create a request for “$REQUEST / $PKCS10 / SDN / SAN” certificate type using CSR with vetting:
In the web portal, navigate to Certificate Center > Certificate Requests from the left menu tree.

Click on the ‘+’ plus button in the listing header to create a new certificate request. The system will display the ‘Create Request’ screen.

On this screen, select the certification profile from the ‘Certificate Type’ dropdown and click ‘Create’.
The system will display the ‘Certificate Signing Request (CSR)’ screen. Here, you will be required to either upload a CSR or paste the file in the given box.

After uploading the CSR, the following screen will appear.

You can click on the eye icon to view the details of the CSR. The details will appear in a dialog as displayed below:

You can scroll down the dialog to view the complete details inside the CSR.
Click ‘Next’ to navigate to the ‘Subject Distinguished Name (SDNs)’ screen. Enter the details in the fields as per your requirement.

Note: If the 'Enable Document ID Pairing with Emails' policy is enabled in the Configurations module, and both the Email and Subject Serial Number fields are included in the Subject Distinguished Name (SDN), the system automatically associates the email address with the subject serial number when they are used together for the first time.
After an email address has been associated with a subject serial number, all future certificate requests using that email address must include the same subject serial number. If a different subject serial number is entered, the certificate request is rejected and an error is displayed. The following error will appear on the screen:

A single subject serial number can be associated with multiple email addresses; however, each email address can only be associated with one subject serial number.
If the 'Enable Document ID Pairing with Emails' policy is enabled and the Subject Distinguished Name (SDN) contains either multiple Email fields or multiple Subject Serial Number (SSN) fields, the system does not process the certificate request and displays an error.

After making the required changes on the SDN screen, click the next '>' button to navigate to the the ‘Subject Alternative Name (SANs)’ screen. Enter the details in the fields as per your requirement

Click ‘Next’ to navigate to the ‘Certificate Validity’ screen.

Here, click the 'Generate' button to create the certificate. The system will generate the certificate and display the 'Certificate Generated' dialog on the screen.

This certificate request will appear in the 'Certificate Requests' and 'Issued Certificates' listing.
Note: If the setting for Digital Onboarding is enabled in the Certification Profile, clicking the 'Generate' button displays a dialog containing the providers configured in the selected Digital Onboarding connector.
Select the required provider from the given options.

The system then displays a QR code. Scan the QR code using the Digital Onboarding mobile application.

After scanning the QR code, complete the identity verification process by providing the required documents as configured in the Digital Onboarding policy.
Once the identity verification process is completed successfully, the QR code will disappear and the certificate request will be generated.
After the certificate request generation, you can download, revoke, or renew the certificate using the respective buttons.
Additionally, if the Rekey Certificate policy is enabled in Configurations > Policies > Requests, you can click the More Actions button to rekey the certificate if required.
How to Renew a Certificate
To renew a certificate before its expiration, you need to first open the certificate request generated from the Web RA system.
To do this, expand Certificate Center > Certificate Requests from the left-tree menu in the Web Portal.
Then, click the request number of the certificate that you want to renew. Alternatively, click the three-dot button next to the certificate request entry and select the 'View Request' option.
The system will then open the certificate request in View mode.

To renew the certificate, click the 'Renew Certificate' button.
Note: The 'Renew Certificate' button appears only if the 'Renew Certificate' policy is selected in Configurations > Policies > Requests section under the certificate renewal settings.
The Certificate Signing Request (CSR) screen will appear again, as displayed in the image below.

Click the next '>' button to navigate to the 'Certificate Validity' screen. Here, click the 'Renew' button to renew the certificate.

The system will display the Certificate Renew dialog on the screen. Here, you can optionally enter a message in the Message box.

Click the Renew button. The certificate will be renewed, and a Certificate Renewed alert will appear on the screen.

Each certificate can be renewed only up to the renewal limit configured in the certification profile. For example, if a renewal limit of 1 is configured in the certification profile, a certificate can only be renewed once. Any subsequent attempt to renew the same certificate will result in an error being displayed by the system.
The following error will appear on the screen if you attempt to renew a certificate after the renewal limit has been reached.

Note: If the renewal limit is set to zero in the certification profile, certificates generated under that certification profile cannot be renewed.
How to Provision a Certificate
Expand Certificate Center > Certificate Requests from the left-tree menu in the Web Portal.
Click the request number of the certificate that you want to provision.
Click the Provision button. The Provision dialog will appear on the screen.

Choose the required option from the 'Provision' dropdown and click the Provision button. The certificate will then be provisioned.
When you click the 'Download' button, the 'Download Certificate' dialog appears. From this dialog, you can choose to download either the certificate only or the certificate PFX.

If you click on the 'Download Certificate PFX' radio button, the dialog will display Password and Confirm Password fields. Type in the required password and click 'OK'.

Note: If ‘Enable one-time PFX download” option is enabled in the Certification Profile, the PFX can only be downloaded once. If the option is disabled, the PFX can be downloaded multiple times.
When you click the 'Revoke Certificate' button, the 'Certificate Action' screen appears. On this screen, you must select a reason for revoking the certificate from the 'Certificate Revocation Reason' dropdown and, if required, a message in the optional message box.
Before revoking a certificate, you must select the 'Are you sure you want to revoke this certificate' checkbox. Then, click 'Revoke' to proceed with the revocation.
