TLS Certificate Self-Service

A knowledge base article about TLS Certificate Self-Service provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Background

This process is for requesting TLS certificates for delegated domains within the Sectigo Certificate Manager. This guide assumes you have already been granted a login to the manager and that your departmental domains have been delegated to your account.


Certificate Manager Login

  1. Access the Sectigo Certificate Manager.
  2. Select CalNet Login as the Sign In option.
  3. After authentication, you will be redirected to the manager dashboard.

Certificate Request Process

Prerequisite: To request a certificate, you must have a valid Certificate Signing Request (CSR) with a minimum RSA-2048 key. For help generating a CSR, please refer to the Sectigo CSR Generation Guide.

  1. Within the certificate manager, select the Menu icon (top-left) and then navigate to Certificates > SSL Certificates.
    Sectigo Certificate Manager sidebar menu highlighting SSL Certificates selection.
  2. In the top-right corner, select the green Add (+) button to open the request wizard.
  3. Leave the enrollment method as Using a Certificate Signing Request (CSR) and select Next.
  4. On the Details page, select the appropriate Certificate Profile:
    • SSL Single Domain General Profile: For the majority of single-subject certificates.
    • Multi Domain General Profile: For certificates with more than one subject name (SAN).
  5. Select the Maximum Certificate Term.
  6. Under Notifications, enter your email address (or preferably a departmental mailing list).

    Important: You must click the Plus (+) button or press Enter after typing the email address, otherwise it will not be saved.

    Certificate enrollment wizard showing Profile selection, Term, and Notification email entry.
  7. Click Next.
  8. Paste your CSR into the text field and click Next.
    Certificate Request screen with a CSR block pasted into the text area.
  9. Validate your domain(s) and click Next.
  10. Ensure Auto-Renewal is turned OFF.
  11. Click OK to finish the request.

You will return to the SSL Certificates list. Your request will initially show a status of Applied. Refresh after a short time, and once verified, the status will update to Issued. An email with download links will be sent to the address provided in Step 6.