Certification Profile for Device Enrolment – ACME


Expand External Services > Certification Profiles from the left menu. The system will display the certification profiles listing screen. 



To add a new certification profile, click the ‘+’ button on the left side of the table header. The system displays the ‘Profile’ screen. 


The Profile screen consists of the following two sections:


  • Basic Information
  • Service



Basic Information


The Basic Information section displays the following fields:


Field

Description

Name

Specify a unique name for this profile. 

Description

Specify any description related to this certification profile. (Optional)


Service


The Service section displays the following fields:


Field

Description

ADSS Service

This field will display the ADSS Services (i.e. Certification Service and CSP Service) that are available for ADSS Web RA. 


Select the ‘Certification Service’ option from the dropdown. 

ADSS Certification Server

This field will display the list of active ADSS connectors in ADSS Web RA. Select the one to use for this certification service profile, for example: 192.168.2.64.

ADSS Certification Service Profile

In this field, enter the certification profile that you created on the ADSS Sever, for example: adss:certification:profile:001.

Active

Select this checkbox to make the profile active.



You can view the details of the selected ADSS connector by clicking the ‘Eye’ icon next to the connector name. When you click the icon, the system displays the ‘Connector’ dialog on the screen containing the information. 



To view complete details of the connector, navigate to the ‘Details’ tab.



After providing the required information on the 'Profile' screen, click the next ‘>’ button to proceed to the ‘Profile Settings’ screen.


Profile Settings


The Profile Settings screen consists of the following sections:


  • Certificate Information
  • ADSS Server Client Secret
  • Certificate Enrolment
  • Verification
  • Open MPIC
  • Go Sign Token


Certificate Enrolment


To create a certification profile for 'Device Enrolment - ACME' enrolment protocol, follow the instructions mentioned in the table below:


Field

Description

Certificate Enrolment 

This dropdown displays the following options: 


  • None – Select this option if you want to create a simple certification profile.
  • Enrolment Protocol(s) - It enables you to create a device enrolment profile. If you select this option, an additional dropdown named "Select Enrolment Protocol(s)" appears on the screen, allowing you to select the required enrolment protocol(s).
  • Windows Enrolment – If this option is selected, an additional dropdown appears that allows you to select the "Active Directory Profile". 



To create a certification profile for ACME, you need to select ‘Enrolment Protocols’ option from the ‘Certificate Enrolment’ dropdown. 


Then you have to select ‘ACME’ protocol from the ‘Select Enrolment Protocol(s)’ dropdown.


After selecting ‘ACME’ as the enrolment protocol, the system will display the ‘External Account Binding Type’ dropdown. This dropdown will display three options.


  • None
  • Fixed
  • Random


External account bindings are used to associate an ACME account with an external account such as a CA custom database. 

Choose an external account binding type from the drop down:


None: No binding is required. ADSS Web RA will process ACME requests using the default certificate profile settings defined here.

Fixed: A fixed HMAC key is generated and associated with the user’s existing ADSS Web RA account. This same key is used to authenticate each ACME request.


Random: A random HMAC key is generated for every ACME request. This key is linked to the user’s existing ADSS Web RA account and used to authenticate that specific request.


If you have selected the ‘Fixed’ binding option, the system will display the ‘HMAC Key’ field. 



You can generate the HMAC key by clicking the ‘Generate’ button, and copy the key by clicking the folder icon next to the Generate button.


After making all the required selections, click the next ‘>’ button to navigate to the ‘Details’ screen.


Set the options in the 'Details', and 'Settings' screens to their default values. The operator can also modify these configurations as needed; however, they are not specifically related to device enrolment. To learn more about the options in these sections, refer to the Certification Service Profile page.


Note: While creating the certification profile for device enrolment, keep Vetting disabled in the 'Settings' tab.


After completing the configuration in the Settings tab, click Create to set up the certification profile.