A knowledge base article about Departmental Certificate Administrator (DCA) FAQ provided by the UC Berkeley IT Service Hub - Knowledge Portal
This is the local UC Berkeley campus name for what is referred to as a DRAO (Department Registration Authority Officer) in other Sectigo documentation.
This will vary depending on the volume of requests for certificates or renewals. If a unit has a request volume that would impact business needs if the primary DCA were unavailable to fulfill these requests, having a designated backup DCA would be appropriate.
If you are interested in performing the DCA function for your unit, please forward your request along with the contact information for a person responsible for your department's or unit's business functions, for example, a departmental manager or MSO or chairperson, to calnet-admin@berkeley.edu for consideration and also to schedule a training session.
If you already have an existing DCA in your unit and would like to request to be added as a backup DCA, contact calnet-admin@berkeley.edu for consideration. The existing DCA for your department should train the backup DCAs.
When you apply for becoming a DCA, please also list the DNS domains and hostnames for which you would like to be responsible for issuing certificates. It is possible to request additional domains via the Sectigo Certificate Manager (SCM) Admin tool, but the initial setup will be smoother if we can provision most of these up front. Examples of UC Berkeley DNS domains and hostnames you might request are: *.mysubdom.berkeley.edu, myhost1.berkeley.edu, etc. The wildcard names represent subdomains which you can claim as being responsible for the identity of all of the hosts.
Starting at the Settings tab, select the Departments menu item. Now click the Domains button in the Controls column for your department. Finally, click the Add button to request a new hostname or domain to be added to the list for your department (the name appears in red text while pending approval). This request will generate an e-mail notice to the appropriate administrator for approval. When the approval step has been completed you will be able to provision certificates for the newly delegated domain.
This depends on whether you want the person listed to receive the notices generated at the various stages of certificate provisioning.
We suggest using ACME for automated SSL/TLS certificate management. Otherwise, API Documentation, Sectigo has documented the REST APIs for the Certificate Manager which underlies the Sectigo Certificate Manager (SCM) web application used by the TLS Certificate Service.
This feature allows you to scan a subset of the network to create an inventory of certificates and their expiration dates. Be sure to create a Discovery Scan Summary notification before running the scan to ensure that the report is delivered correctly. See Understanding network discovery tasks
To create a certificate containing both a wildcard name and a non-wildcard name, use the Multi Domain SSL certificate type and enter the non-wildcard name as the CN and the wildcard name as one in the SAN field.