Generate Keys on Smart Card/Token
Certification profile to generate keys on Smart Card/Token
Expand External Services > Certification Profiles from the left menu. The system will display the certification profiles listing screen.

To add a new certification profile, click the ‘+’ button on the left side of the table header. The system displays the ‘Profile’ screen.
The Profile screen consists of the following two sections:
- Basic Information
- Service

Basic Information
The Basic Information section displays the following fields:
|
Field |
Description |
|
Name |
Specify a unique name for this profile. |
|
Description |
Specify any description related to this certification profile. (Optional) |
Service
The Service section displays the following fields:
|
Field |
Description |
|
ADSS Service |
This field will display the ADSS Services (i.e. Certification Service and CSP Service) that are available for ADSS Web RA. Select the ‘Certification Service’ option from the dropdown. |
|
ADSS Certification Server |
This field will display the list of active ADSS connectors in ADSS Web RA. Select the one to use for this certification service profile, for example: 192.168.2.64. |
|
ADSS Certification Service Profile |
In this field, enter the certification profile that you created on the ADSS Sever, for example: adss:certification:profile:001. |
|
Active |
Select this checkbox to make the profile active. |

You can view the details of the selected ADSS connector by clicking the ‘Eye’ icon next to the connector name. When you click the icon, the system displays the ‘Connector’ dialog on the screen containing the information.

To view complete details of the connector, navigate to the ‘Details’ tab.

After providing the required information on the 'Profile' screen, click the next ‘>’ button to proceed to the ‘Profile Settings’ screen.
Profile Settings
The Profile Settings screen consists of the following sections:
- Certificate Information
- ADSS Server Client Secret
- Certificate Enrolment
- Verification
- Open MPIC
- Go Sign Token
Go Sign Token
To create a certification profile to generate keys on smart cards/tokens, scroll down to the 'Go Sign Token' section on the 'Profile Settings' screen. Fill out the fields as per details mentioned in the table below:
|
Field |
Description |
|
Use this certificate profile to generate keys on smart cards/tokens |
Enable this option if this profile will be used to generate the certificates in the smart card/ token. After enabling this checkbox, the administrator must provide the ADSS Server details along with the ADSS Go>Sign Profile. The system will also display the ‘Enable Reset PIN/PUK dropdown’, allowing the administrator to reset default PIN and PUK values for the token. The following options are available in the dropdown:
The operator has the option to reset default value for either PIN or PUK by selecting the respective option from the dropdown. If Both (PIN and PUK) option is selected, the system will display both fields for Default PIN and Default PUK, where the administrator can reset the default values. Note: By default, ‘None’ option will be selected for the From the “Mechanism” dropdown, the administrator can choose how the default PIN and PUK values will be shared. The available options are:
If Both (Email and SMS) is selected, the entered PIN and PUK values will be shared with the user via both email and SMS. |

After providing the required information on the 'Profile Settings' screen, click the next ‘>’ button to navigate to the ‘Details’ screen. Set the options in the 'Details', and 'Settings' screens to their default values. The operator can modify these configurations as needed.
For detailed information about the fields available on the 'Details', and 'Settings' screens for configuring the Certification Service profile, refer to the 'Certification Service Profile' page.
If you want to continue with default values, then after completing the configuration in the Settings tab, click 'Create' to set up the certification profile.