A knowledge base article about TLS Certificate Self-Service provided by the UC Berkeley IT Service Hub - Knowledge Portal
Background
The process described here is for requesting TLS certificates for your delegated domains within the Sectigo certificate manager. This process assumes you have been granted a login to the certificate manager and that domains have been delegated to your department already.
Process
Certificate Manager Login
- Access the certificate manager
- Select "CalNet Login" as the Sign In option.
- After authentication you will be redirected to the certificate manager.
Certificate Requests
NOTE: To request a certificate you must already have a valid certificate signing request (CSR) with a minimum RSA - 2048 key. For help generating CSRs please see your operating system or application documentation. Additional help can be found at the following links Choose Your Server Here
|
- Within certificate manager select the menu icon at the top-left and then select Certificates > SSL Certificates.

- Within SSL Certificates, in the top right corner, select the green add button to open the certificate request wizard.
- Leave the enrollment method as Using a Certificate Signing Request (CSR) and select Next.
- In the Details page select the appropriate Certificate Profile.
- Profiles include:
SSL Single Domain General Profile (the majority of use-cases for single subject certificates)
Multi Domain General Profile (for certs with more than one subject name or SAN)
- Select the maximum Certificate Term.
- Under Notifications enter your email address, or preferably a mailing list for your department. Important: You must click the plus button or hit <enter> when adding email addresses, otherwise they will not be saved.

- Click Next
- Paste your CSR and then click Next.

- Validate your Domain(s) and then click Next.
- Leave Auto-Renewal turned off.
- Click OK to finish the request.
- You will be returned to your list of SSL certificates. You should see your new request with the status of Applied.
- After a short amount of time, you can refresh the page and the certificate should show Issued.
- An email with download links to your certificate will be sent to the address you entered in step 6.
Related Guides
Related KBs
Certificate Chain