Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Minor
Info

This article includes updates for Certificate Manager 8.1011.

...

The shaded objects show the foundation of the Certificate Manager PKI environment, which is created in the bootstrap procedure. 

...

  1. Use the key Officer and system CA key created in the previous step, to create an Officer and System CA, according to Create CA in Certificate Manager.

  2. In Authority name, enter Officer and system CA.

  3. Do the following selections in the Authority Request dialog box:

...

  1. Issue a software token based on the token procedure for TLS and PIN encryption, according to Issue software token in Certificate Manager.

  2. Name the file tls.p12.

  3. Make a note of the assigned PIN code.

  4. Save the file to a removable media for use in later tasks.

Elliptic Curve keys using Brainpool curves are not supported for TLS. 

Issue software token for PIN encryption

...

After removing this CA key, any procedures created with the Boot CA key can no longer be used and CIS log entries signed with this key can no longer be verified.

...

Additional information

Expand
titleUseful links

The following tasks are done during the bootstrapping procedure. 

In Administrator's workbench (AWB):

Using hwsetup: 

In Key Generation System:

In Registration Authority (RA) in Certificate Manager