Create a certificate template
A certificate template defines the key parameters and constraints for certificates issued within a certificate management policy. It establishes essential settings such as allowed key types, signature algorithms, and the fields included in the certificate.
Certificate templates standardize the attributes of certificates issued to devices by defining core elements that must be present in each certificate. This consistency ensures that certificates meet technical, security, and regulatory requirements.
Before you begin
Before creating certificate templates, understand the following:
You must have a user role that contains the
Solution administratorpermission.You need a JSON-formatted certificate template prepared.
To create a certificate template:
In the Device Trust Manager menu, go to Certificate management > Certificate settings > Certificate templates.
Click Create > Create certificate template.
Enter a Name for the Certificate template.
Under the Certificate template type, select either End entity or Intermediate CA, depending on your requirement.
In the Format dropdown, select the format for the certificates you want to issue from this template:
X.509:
Supports RSA and ECDSA certificates
X.509 is the International Telecommunication Union (ITU) standard format of public key certificates
Global platform:
Supports ECDSA certificates only
These certificates are around 1/10 the size of an x509v3 certificate
Attribute certificate:
Binds authorization attributes (such as roles or permissions) to an identity, rather than binding a public key
Used primarily for authorization and access control
In the Template body, add your JSON-formatted certificate template information.
Example JSON certificate template:
The following example shows a JSON structure of a certificate template.
{ "key_gen": { "enabled": true, "key_type": { "allowed_types": [ "ecdsa" ], "default_key_type": "ecdsa" }, "ecdsa_curve": { "allowed_curves": [ "P-256", "P-384", "P-521" ], "default_curve": "P-256" } }, "issue_types": [ "client_authentication" ], "signature_algorithm": { "allowed_algorithms": [ "sha256WithECDSA", "sha384WithECDSA", "sha512WithECDSA", "match_issuer" ], "default_algorithm": "match_issuer" }, "subject": { "attributes": [ { "type": "common_name", "include": "optional", "encoding": "auto", "allowed_source": [ "csr", "fixed_value", "user_supplied" ] } ] }, "extensions": { "key_usage": { "critical": true, "required_usages": { "rsa": [ "digital_signature", "key_encipherment" ], "ecdsa": [ "digital_signature" ] }, "optional_usages": { "rsa": [ "data_encipherment" ], "ecdsa": [ "key_agreement" ] } }, "extended_key_usage": { "critical": true, "include": "optional", "required_usages": [ { "oid": "client_authentication", "name": "Client Authentication" } ] } }, "serial_number_size": 20, "validity": { "min_duration": { "value": 1, "unit": "DAYS" }, "max_duration": { "value": 10, "unit": "YEARS" }, "default_duration": { "value": 10, "unit": "YEARS" } } }In the Limited accounts dropdown, select the accounts that can use this template.
When ready, select:
Create: Creates the certificate template
The completed certificate template is listed under Certificate management > Certificate settings > Certificate templates
Create and select: Create the certificate template and proceed to the Certificate profile creation section.