Recruiting and Training Delegated Administrators

A knowledge base article about Recruiting and Training Delegated Administrators provided by the UC Berkeley IT Service Hub - Knowledge Portal

Recruiting DCAs

Central administrative team

Who administers the program?

The Sectigo Certificate service is managed by UC Berkeley's CalNet team, which oversees Identity and Access Management services for our campus. The members of the CalNet team have all been granted RAO level permissions. For any given week, the "on-call" staff person processes certificate requests.

How do customers submit requests?

Submit a Service Request Form via ServiceNow for certificate requests.

Instructions to customers making certificate requests are included in our published TLS Certificates.

How are requests reviewed/validated as legitimate?

UC Berkeley already had a pre-established program for registering a Security Contact for all campus hosts. As part of implementing the Sectigo Certificate program, CalNet team members were given access to the Security Contact Application so that RAO's could look up the Security Contact for any given host. The CalNet RAO forwards the certificate request to the registered Security Contact. Once approved, the CalNet team member uses the Sectigo SCM application to enter and review the CSR and approve the certificate.

Central vs. delegated administration

We anticipate some campus customers will continue to send certificate requests directly to the CalNet team, but our hope is that the vast majority of requests can be handled by local, departmental certificate administrators (DCAs). Please see sections below on our approach to recruiting and training those administrators.

Initial recruitment of delegated administrators

Central IT Staff

The CalNet team began by requesting that the Deputy CIO approve DCA status for a handful of central IST staff. These staff manage hosts on behalf of other campus departments and for campus-wide services. They were granted permission to approve certificates at the top level .berkeley.edu domain.

Departmental IT Staff

The CalNet team then identified the highest level IT staff in large campus departments like the business school, law school, EECS, etc, asking that they appoint delegated certificate administrators for their departments. We also asked approved departmental administrators to provide us the subdomains/hosts to enroll for that department.

We maintain the list of approved departmental administrators in our internal wiki, noting the department name, managerial sponsor, and date the administrator was approved. We will review the list of DCAs at least annually to remove accounts for employees who have left the university.

Adding DCAs to the Sectigo SCM

Once management has appointed or approved a DCA, we contact the administrator to request enrollment information. 

Ad hoc recruitment of delegated administrators

While we hope to catch as many departments as possible in our initial efforts to recruit departmental administrators, we know we will miss some. When requests for new DCAs come to calnet-admin@berkeley.edu, our response includes a paragraph requesting contact information for a high level manager in that department who could authorize departmental administrators. We check that person's standing via the campus directory and then reach out to the manager to confirm the recruitment of delegated administrators. 

Training DCAs

At UC Berkeley, we require all DCAs to participate in training with their existing team members. If this DCA is the first DCA for a new department, the CalNet team will assist with training before we approve their DCA status. Below is an outline of the training and some related documentation. Below is our training outline:

Your responsibility as a DCA

Some tips for generating CSRs

Using the Sectigo SCM tool

Additional Information: