This article describes how a Workplace certificate agent enrolls a profile in the Workplace package in Smart ID Identity Manager.
Prerequisites
Prerequisites
A certificate profile must have been created and be in the state "active". See Create certificate profile.
Step-by-step instruction
Enroll profile
In Identity Manager Operator, go to theSearchpage and select Workplace certificate profiles from the drop-down list.
Click Search to get a list of certificate profiles, and select the active profile that you want to enroll.
SelectEnroll profile. For the selected enrollment protocol, follow the instructions below.
Enroll P10 profile
In Upload CSR, click to search for and upload the certificate signing request (CSR) file.
Click Next.
Edit the server request.
Click Download to download the P10 certificate. The P10 certificate is related to the asset or to the certificate profile.
ClickNextto proceed with the process orCancelto close the process.
Enroll P12 profile
Without domain policies set
Click Search asset and select an existing asset or create an asset. For more information, see Create asset.
ClickNextto proceed with the process orCancelto close the process.
Enter data in the fields under Certificate data,
Click Next.
In Certificate password, do the following:
Click the download icon to download the certificate to your system.
Enter password and select the Confirm displayed password checkbox to confirm the password conditions. The password cannot be stored or retrieved.
Click Next.
In Confirm certificate installation, click Confirm to confirm the installation.
With domain policies set
Enter data in the fields under Certificate profile data.
Enter data in the fields under Certificate data.
Enter the domain name in the DNS field. If more than one DNS entry is required, the entries must be comma-separated.
ClickNextto proceed with the process orCancelto close the process.
In Certificate password, do the following:
Click the download icon to download the certificate to your system.
Enter password and select the Confirm displayed password checkbox to confirm the password conditions. The password cannot be stored or retrieved.
Click Next.
In Confirm certificate installation, click Confirm to confirm the installation.
Enroll ACME profile
Without domain policies set
Enter data in the fields underCertificate data.
ClickNextto proceed with the process orCancelto close the process.
With domain policies set
Enter data in the fields underCertificate data.
Enter the domain name in the DNS field. If more than one DNS entry is required, the entries must be comma-separated.
ClickNextto proceed with the process orCancelto close the process.
The registration request is sent directly to CM.
Enroll SCEP profile
Without domain policies set
Enter data in the fields underCertificate data.
ClickNextto proceed with the process orCancelto close the process.
With domain policies set
Enter data in the fields underCertificate data.
Enter the domain name in the DNS field. If more than one DNS entry is required, the entries must be comma-separated.
ClickNextto proceed with the process orCancelto close the process.
Approvals
Profiles that require approval
Once the enroll profile action is completed, a notification for approval is sent to the administrator and you will get further information via email.
If the request has been sent already, you will also get a notification. An administrator with approval rights will approve or reject the request. For more information, see Workplace - Approval handling.
View approval status
Once the request has been approved, go to theSearchpage and selectWorkplace requests.
ClickSearch. The request will now have the statusApproved.
Use case details
Overview and technical details
Use case description
A Workplace certificate agent wants to enroll a profile.
Outcome
For ACME or SCEP registrations, the asset is only registered on the Certificate Manager side. No visible outcome in Identity Manager Operator.
For P12 or P10 requests, a certificate will be related to the asset on which the request was triggered.
Symbolic name
AssetsProcEnrollProfile
P10: AssetsSubProcEnrollP10Profile
P12: AssetsSubProcEnrollP12Profile
ACME: AssetsSubProcEnrollACMEProfile
SCEP: AssetsSubProcEnrollSCEPRegistration
Process name
Enroll profile
Component
Identity Manager Operator
Process start
Option 1: Search>Workplace asset>Search for assets (in state "Active")>Enroll profile
Option 2: Search>Workplace certificate profiles>Search for a certificate profile (in state "Active")>Enroll profile
If the process is started on an asset, the asset data is used as predefined values for the request or registration.