Background
The process described here is for requesting SSL certificates for your delegated domains within the Sectigo / InCommon certificate manager. This process assumes you have been granted a login to the certificate manager and that domains have been delegated to your department already.
Process
Certificate Manager Login
- Access the certificate manager at https://cert-manager.berkeley.edu
- Select University of California, Berkeley as your home organization to be redirected to CalNet SSO.
- After authentication you will be redirected to the certificate manager.
Certificate Requests
|
NOTE: To request a certificate you must already have a valid certificate signing request (CSR) with a minimum RSA - 2048 key. For help generating CSRs please see your operating system or application documentation. Additional help can be found at https://sectigo.com/faqs/product/Choose_Your_Server_Here and https://calnet.berkeley.edu/calnet-technologists/web-certificates
|
- Within certificate manager select the menu icon at the top-left and then select Certificates > SSL Certificates.
- Select the green add button in the top-right corner of the screen to open the certificate request wizard.
- Leave the enrollment method as Using a Certificate Signing Request (CSR) and select Next.
- In the Details page select the appropriate Certificate Profile. Common profiles include:
V2 InCommon SSL (the majority of use-cases for single subject certificates)V2 InCommon Multi Domain SSL (for certs with more than one subject name or SAN) - Select the maximum Certificate Term.
- Under Notifications enter your email address, or preferably a mailing list for your department. Important: You must click the plus button or hit <enter> when adding email addresses, otherwise they will not be saved.
- Click Next
- Paste your CSR and then click Next.
- Validate your Domain(s) and then click Next.
- Click OK to finish the request.
- You will be returned to your list of SSL certificates. You should see your new request with the status of REQUESTED.
- Check the box next to your new certificate request and then select Approve. Enter anything you like for the message.
- The certificate request will change to ISSUED after a short period.
- An email with download links to your certificate will be sent to the address you entered in step 6.
Related KBs
InCommon Certificate Chain