An attribute certificate (AC) can either be issued together with the linked public key certificate (PKC) or issued after the PKC certificate has been issued. The first alternative requires the token procedure being used to specify that both a PKC and an AC should be issued simultaneously. This is described in Issue smart card certificate in Certificate Manager and Issue software token in Certificate Manager respectively.
Click Search to open the Select Certificate window to select the base certificate to which the new attribute certificate will be linked.
Check Serial Number and Subject as required. Enter the search criteria in the relevant fields and click Search.
The search results are displayed in the right-hand pane of the Select Certificate window.
Details of a highlighted certificate can be displayed in the lower Details section of the right-hand pane.
The Certificate ID is a decimal string that uniquely represents a certificate in a CM installation.
The Certificate Serial Number must be entered as a hexadecimal string and is shown as a hexadecimal string.
Select the appropriate base certificate and click OK.
Click the button next to File for Media and specify a path and file name for the certificate to be stored. You need write access to the location where the attribute certificate is to be stored.
Select procedure to be used when issuing the attribute certificate.
Only token procedures with storage profile Attribute Certificate are listed in the procedure list.
Enter data in the input fields. As long as the PIN field is being disabled, the reason for that is displayed in the status bar at the bottom of the window.
More information on how to enter Qualified Certificates (QC) statements is available in Qualified certificates.