Skip to main content

Configure X9 PKI for TLS product

Use these instructions to enable or disable the X9 PKI for TLS certificate and to configure the product settings. These settings affect your X9 PKI for TLS order, renewal, and reissue request forms. The changes aren’t retroactive and don’t affect issued certificates, pending certificate requests, or pending certificate orders.

Before you begin

Note

Note: If needed, you can use the Restore the Default Settings and Restore Product Settings options to reset your product configurations.

Account versus division versus user role configurations

When you configure your X9 PKI for TLS certificate settings, you can do it at the account level or at the division level if using divisions in your account. You can also configure it for specific roles in your account or division, Administrator, Manager, Finance Manager, Standard User, and Limited User depending on the roles available in your account. Learn more about what CertCentral user roles.

Configurable product settings

For X9 PKI for TLS certificates, you can configure the following product settings:

  • Whether the product is enabled

  • Allowed validities

  • Whether custom validity is allowed

  • Default Key Usage

  • Default Extended Key Usage

  • Signature hashes

  • Automatic renewals

  • Maximum SANs

  • Certificate formatting

Configure your X9 PKI for TLS product and request form

Configure the scope and select the product

  1. In the CertCentral menu, go to Settings > Product Settings.

  2. On the Product Settings page, use the following settings to determine the granularity of your X9 PKI for TLS product settings:

    1. Enable Product Configuration Per Division (must be using divisions to see this option)

      Select this option to configure the certificate for a specific division. For example, if you don't want division ordering this specialty certificate, you can disable X9 PKI for TLS for that division.

      1. Select Enable Product Configuration Per Division.

    2. Configure products by role

      Use this option to configure the certificate for a specific role in CertCentral. For example, if you justwant Administrators and Managers ordering this specialty certificate, you can disable X9 PKI for TLS for the Finance Managers, Standard Users, and Limited Users.

      1. Select Configure products by role.

      2. In the Role column, select a role: Administrator, Manager, Finance Manager, Standard User, or Limited User.

  3. In the Product column, select X9 PKI for TLS.

Configure X9 PKI for TLS certificate settings

In the Product Settings column under X9 PKI for TLS, update the product settings as needed.

Enable / Disable product

This setting controls whether X9 PKI for TLS appears as an option on the Request a Certificate menus and page. Select Enable this product to enable the product.

Allowed validities

X9 PKI for TLS certificates support 1-, 2-, and 3-year certificate validities. By default, all these options appear on request forms. Using this option also removes the custom validity options from the request form.

  1. In the Allowed validity period menu, select the validity options to appear on the request form.

  2. Clear all the validity selections to allow all validity options to appear on the request form and to include the custom validity options on the request form.

Enable / disable custom validity option

By default, requesters can configure custom validities for their X9 PKI for TLS certificate request by entering a custom length (for example, 400 days) or selecting a custom expiration date (for example, 19 Aug 2028).

Select Do not allow custom validity to remove the custom validity options from the request form.

Default Key Usage

The Digital signature key usage is selected by default.

In the Default Key Usage menu, select the key usage selected by default on the request form:

  • Digital signature: The Digital signature KU allows a key to create digital signatures that verify the signer's identity.

  • Digital signature and key encipherment:

    • If using an RSA CSR, the certificate contains the key encipherment KU.

    • If using an ECC CSR, the certificate contains the key agreement KU.

Default Extended Key Usage

The Server Authentication extended key usage is selected by default.

In the Default Extended Key Usage menu, select the extended key usage selected by default on the request form: Server Authentication and Client Authentication, Server Authentication, or Client Authentication.

Note

Note: Server authentication secures websites using HTTPS. Client authentication identifies who you are for host-to-host communications.

Signature hashes

By default, DigiCert issues RSA certificates with a SHA-256 signature hash and RSA signing algorithm. DigiCert recommends using the default RSA settings unless you have specific reasons for using a different key size or signing algorithm.

  1. In the Allowed signature hashes menu, select the signature hash options to appear on the request form: SHA-256 or SHA-384.

  2. Clear all the signature hash selections to allow all signature hash options to appear on the request form.

Automatic renewals

By default, the Auto-renew option appears on the request form.

Deselect Allow automatic renewal to remove the Auto-renew option from the request form.

Maximum SANs

By default, you can include 250 subject alternative names (SANs) in a certificate request.

In the Maximum number of allowed SANs (up to 250) field, enter your maximum number of SANs limit (for example, 100). Leave the field blank to restore to 250 SANs maximum limit.

Certificate formatting

By default, DigiCert uses the Windows formatting in our TLS certificates.

To use Linux newlines certificate formatting, under Certificate formatting for downloading a certificate, select Use Linux newlines certificate formatting instead of Windows formatting.

Note

Note: Why should I use Linux newlines formatting?

You may want to use Linux newlines if:

  • You’re a former QuoVadis TrustLink Enterprise customer.

  • Your platform or system only supports Linux newlines.

Save your changes

To save your X9 PKI for TLS product updates, go to the bottom of the page and select Save Settings.

What's next after you save your changes?

Review your changes on the X9 PKI for TLS certificate request form. In the CertCentral menu, select Dashboard. On the Dashboard, in the Request a Certificate menu, select X9 PKI for TLS.