Two smart card readers are available or alternatively one smart card reader and one smart card printer attached to the PC.
A pre-personalized smart card is available in the card reader/printer.
It is possible to use a virtual registration officer certificate, that is, a software token, instead of a smart card to authenticate the officer, but for security reasons, this is not recommended.
Step-by-step instruction
Update smart card certificate
Options
Use the Reload button in the RA application window to load data from the current smart card.
Insert the smart card to be updated in the card reader/printer.
Existing keys and, if they are available, certificates, are shown in the Contents section. One key is presented on each line. If a smart card with a transport certificate (TC) is inserted in the card device, the common name from the TC appears in the Certificate column.
Select what action you want to perform for each key. First click the down arrow and then choose an action:
Blank - no action.
Issue - secondary certificate is not stored on the card.
Redo - remove current and insert another certificate. Use this action if the smart card contains a Transport Certificate (TC).
Add - issue another certificate based on the same key.
Do not use Add if the smart card has a TC, as this action may put an additional certificate on the card and keep the TC.
Select a procedure for the new certificate.
To issue certificates on a smart card with a TC, you must select a procedure that includes the necessary controls to verify the authenticity of the TC. Various error situations related to TCs are explained in Troubleshooting Certificate Manager clients.
More information on how to enter Qualified Certificates (QC) statements is available in Qualified certificates.
Enter your PIN code in Signature PIN.
Click Submit to send the request to the CM host.
A dialog box will open. Depending on the type of certificate (end-user or Certificate Authority (CA) certificate) to be updated, the look of this dialog will vary.
For end-user certificate:
Enter the PIN code and click OK. Depending on the contents on the smart card, two PIN codes may be required.
For CA certificate: The dialog changes appearance depending on what information is needed.
When an operator PIN is required (depending on specification in the token procedure), and this PIN is not available in the CM database, you must enter the OP PIN.
If the token procedure specifies that CA certificates should be written to the card, the option Replace CA certificate(s) is shown.