A knowledge base article about Recruiting and Training Delegated Administrators provided by the UC Berkeley IT Service Hub - Knowledge Portal
The Sectigo Certificate service is managed by UC Berkeley's CalNet team, which oversees Identity and Access Management services for our campus. The members of the CalNet team have all been granted RAO level permissions. For any given week, the "on-call" staff person processes certificate requests.
Submit a Service Request Form via ServiceNow for certificate requests.
Instructions to customers making certificate requests are included in our published TLS Certificates.
UC Berkeley already had a pre-established program for registering a Security Contact for all campus hosts. As part of implementing the Sectigo Certificate program, CalNet team members were given access to the Security Contact Application so that RAO's could look up the Security Contact for any given host. The CalNet RAO forwards the certificate request to the registered Security Contact. Once approved, the CalNet team member uses the Sectigo SCM application to enter and review the CSR and approve the certificate.
We anticipate some campus customers will continue to send certificate requests directly to the CalNet team, but our hope is that the vast majority of requests can be handled by local, departmental certificate administrators (DCAs). Please see sections below on our approach to recruiting and training those administrators.
The CalNet team began by requesting that the Deputy CIO approve DCA status for a handful of central IST staff. These staff manage hosts on behalf of other campus departments and for campus-wide services. They were granted permission to approve certificates at the top level .berkeley.edu domain.
The CalNet team then identified the highest level IT staff in large campus departments like the business school, law school, EECS, etc, asking that they appoint delegated certificate administrators for their departments. We also asked approved departmental administrators to provide us the subdomains/hosts to enroll for that department.
We maintain the list of approved departmental administrators in our internal wiki, noting the department name, managerial sponsor, and date the administrator was approved. We will review the list of DCAs at least annually to remove accounts for employees who have left the university.
Once management has appointed or approved a DCA, we contact the administrator to request enrollment information.
While we hope to catch as many departments as possible in our initial efforts to recruit departmental administrators, we know we will miss some. When requests for new DCAs come to calnet-admin@berkeley.edu, our response includes a paragraph requesting contact information for a high level manager in that department who could authorize departmental administrators. We check that person's standing via the campus directory and then reach out to the manager to confirm the recruitment of delegated administrators.
At UC Berkeley, we require all DCAs to participate in training with their existing team members. If this DCA is the first DCA for a new department, the CalNet team will assist with training before we approve their DCA status. Below is an outline of the training and some related documentation. Below is our training outline: