TLS Certificate Self-Service

A knowledge base article about TLS Certificate Self-Service provided by the UC Berkeley IT Service Hub - Knowledge Portal

Background


The process described here is for requesting TLS certificates for your delegated domains within the Sectigo certificate manager.  This process assumes you have been granted a login to the certificate manager and that domains have been delegated to your department already. 

Process


Certificate Manager Login

  1. Access the certificate manager
  2. Select "CalNet Login" as the Sign In option. 
  3. After authentication you will be redirected to the certificate manager.

Certificate Requests

NOTE: To request a certificate you must already have a valid certificate signing request (CSR) with a minimum RSA - 2048 key. For help generating CSRs please see your operating system or application documentation. Additional help can be found at the following links Choose Your Server Here 
  1. Within certificate manager select the menu icon at the top-left and then select Certificates > SSL Certificates.

    A screenshot of the top left sidebar of the Sectigo Certificate Manager that shows "SSL Certificates"
  2. Within SSL Certificates, in the top right corner, select the green add button to open the certificate request wizard.
  3. Leave the enrollment method as Using a Certificate Signing Request (CSR) and select Next.
  4. In the Details page select the appropriate Certificate Profile.
    1. Profiles include:
      SSL Single Domain General Profile (the majority of use-cases for single subject certificates)
      Multi Domain General Profile (for certs with more than one subject name or SAN)

  5. Select the maximum Certificate Term.
  6. Under Notifications enter your email address, or preferably a mailing list for your department. Important: You must click the plus button or hit <enter> when adding email addresses, otherwise they will not be saved.

    A screenshot of the certificate enrollment wizard that shows Steps 4, 5, and 6.

  7. Click Next
  8. Paste your CSR and then click Next.

    Screenshot of Certificate Request page with CSR pasted in

  9. Validate your Domain(s) and then click Next.
  10. Leave Auto-Renewal turned off.
  11. Click OK to finish the request.
  12. You will be returned to your list of SSL certificates. You should see your new request with the status of Applied.
  13. After a short amount of time, you can refresh the page and the certificate should show Issued.
  14. An email with download links to your certificate will be sent to the address you entered in step 6.

Related Guides


Sectigo Certificate Manager (SCM) Administrator Guide

Related KBs


Certificate Chain