Skip to main content

CA Manager


  • Create new CRLs for existing CAs – Additional CRLs with configurable Generation and Frequency settings now may be created for existing CAs.

  • Authority Information Access (AIA) – A section has been created in which to manage and create AIAs.

  • Design and functional improvements - The design and functionality of creation forms and detail pages for Root CAs and ICAs has been overhauled to provide options for CRL, OCSP, AIA and other configurations, as well as improved usability.

  • Certificate improvements

    • Online CAs may now be configured to Decrypt and Sign incoming SCEP authentication calls for DigiCert​​®​​ IoT Trust Manager via the API

    • Certificates may now be signed via the API using SubjectPublicKeyInfo (RFC 5280) I instead of a Certificate Signing Request (CSR)

    • Certificates support additional Subject DN fields:

      • unstructuredName (OID 1.2.840.113549.1.9.2)

      • unstructuredAddress (OID 1.2.840.113549.1.9.8)

      • serialNumber (OID

      • uniqueIdentifier (OID 0.9.2342.19200300.100.1.44)

      • description (OID

    • Private Server now supports these additional Subject Alternative Name (SAN) attributes to better support Enterprise PKI Manager:

      • IP Address (ipAddress)

      • Other Name (GUID) (otherNameGUID)

      • Registered ID (registeredID)

      • URI (uniformResourceIdentifier)

      • Directory Name (directoryName)