Use the profile configuration wizard
When you create a new certificate profile, DigiCert® Trust Lifecycle Manager presents a wizard to help you configure the required certificate options. The wizard screens and options you see depend on the base template you use as the basis for creating the certificate profile.
This page describes the general workflow and available options for creating a certificate profile with the profile configuration wizard.
Before you begin
Identify the best certificate template to use to create your certificate profile. The certificate template determines:
Available certificate properties and use cases.
Issuing certificate authorities (CAs), enrollment methods, and automation options.
Important
If your Trust Lifecycle Manager account uses the legacy licensing model (with different seat types), each base template has a corresponding seat type. You must have available seats of that type in your account, otherwise the base template is disabled and you can't create certificate profiles from it. To learn more, see Legacy seat types.
Step 1: Begin creating the certificate profile
Use one of the following methods to launch the profile configuration wizard for creating a certificate profile:
From the certificate templates view (Policies > Base templates), select a certificate template by name to start creating a certificate profile from that template. Alternatively, open the actions (three dot) menu next to the certificate template name and select Create profile from template.
From the certificate profiles view (Policies > Certificate profiles), select the Create profile button above the table to start creating a certificate profile. This takes you to the certificate templates view. Select a certificate template by name to start creating a certificate profile from it.
Step 2: Customize the certificate profile
Follow the Create certificate profile wizard to customize the certificate profile.
Note
The screens and options available in the wizard depend on the certificate template you started with and your specific business needs. The options described in this procedure are representative and may vary by template. Additional options may also be available depending on the selected template and configuration.
Configure details on the following screens as necessary. At any time, select Certificate preview to preview the certificate with the details you have configured.
On the Primary options screen of the wizard, configure the following:
Profile name: Enter a name to help identify the certificate profile.
Profile description (optional): Enter an optional description for the profile.
Business unit: Select the business unit to assign for certificates issued from this profile.
Issuing CA: Select the issuing CA to issue end-entity certificates for the profile.
Enrollment method: Select an enrollment method to use for requesting certificates from this profile.
Authentication method: Select a method to authenticate the enrollment requests and configure any required authentication options.
Select Next to continue to the Certificate options screen of the wizard.
On the Certificate options screen of the wizard, configure the following options:
Certificate fields: Configure certificate validity period, signing algorithm, key type, and key size.
Some certificate profile types and enrollment methods support multiple key sizes. Select all possible key sizes you want to allow in your certificates. The final key size is determined based on what's sent in the CSR for each enrollment.
You can also customize the length of the certificate serial number for profiles configured using the three generic base templates. To do this, you must enable the Customize length of certificate serial number checkbox. The options that you can select from are:
16 bytes (32 hexadecimal characters)
17 bytes (34 hexadecimal characters)
18 bytes (36 hexadecimal characters)
19 bytes (38 hexadecimal characters)
20 bytes (40 hexadecimal characters) (default)
Note
We recommend that you use the 20-bytes option since it’s more secure and reduces the possibility of serial number collisions.
Flow options: Configure if you can issue multiple certificates from the profile, and if you can override the default certificate validity by a REST API request.
Renewal options: Set renewal window, and configure grace period.
Subject DN and SAN fields: Configure Subject Distinguished Name (DN) and Subject Alternative Name (SAN) attributes for the profile. For technical details about supported certificate attributes, see Certificate attributes and extensions.
Select Next to continue to the Extensions screen of the wizard.
On the Extensions screen of the wizard, you can view and configure extensions other than the SAN that define how a certificate is used and validated:
Configure extensions such as Basic constraints, Key usage, and Extended key usage to control certificate capabilities and permitted operations.
Review issuer and validation-related extensions, such as Authority information access, Authority key identifier, Certificate distribution points, and Subject key identifier, which help support certificate chain building and revocation checking.
Some private certificate types also support custom extensions.
Select Next to continue to the Additional options screen of the wizard.
On the Additional options screen, you can configure certificate delivery and management settings for the profile.
Configure options such as Delivery formats, Email configuration and notifications, Contact details, Alerts, and Certificate owners.
Note
If you sign in using single sign-on through your DigiCert® account, you have access to customize and configure alert options. See View and manage profile-specific alerts for more information.
Configure LDAP search settings and assign metadata to help organize, track, and manage certificates issued from the profile.
Apply Tags to help identify all certificates issued from a particular profile for tracking and management purposes in Trust Lifecycle Manager.
Some templates provide a Custom attributes option. These are user-defined metadata fields that store business-specific information if configured under Settings.
Note
Available custom attributes vary based on the selected enrollment method. For example, different custom attributes may be available for web-based and automated enrollment methods.
Select Certificate owners who should receive notifications for all certificates issued from this profile.
Select Next to continue to the Advanced settings screen of the wizard.
On the Advanced settings screen, you can configure advanced profile options that affect certificate enrollment, lifecycle management, and end-user experience.
Configure Seat ID mapping where you can select a certificate field to be bound to your Seat ID. This is used to uniquely identify the entity (for example, the user, device, or server) that is using each seat license.
Upload a user instructions file for how to use the certificate for profiles configured with a web-based enrollment method (
Browser PKCS12,CSR, orDigiCert Trust Assistant) and an authentication method ofEnrollment Code,Manual ApprovalorDigiCert ONE Login.Enable a grace period, which allows you to add the days before expiration to the renewed certificate. When not selected, the renewed certificate takes a strict validity period based on the set Certificate expires in value.
Configure the self-service portal option for some templates to allow end users to manage their own certificates via a web-based self-service portal, if enabled under Settings.
For Microsoft CA profiles configured with the SCEP method, you can regenerate the RA certificate used by the solution to decrypt SCEP before Microsoft CA issues the certificate. This ensures that:
All issues related to RA certificate expiring and not being automatically renewed by Trust Lifecycle Manager are prevented.
You have a fresh RA key and RA certificate bound to the profile at all times helping adhere to security policies.
To regenerate an RA certificate, select the Regenerate RA certificate button at the end of the wizard.
Step 3: Save the certificate profile
Review the configuration before saving. Select Next to continue through the wizard, or select Back to return to previous screens and make changes.
When you're ready, select Create to save and create the new certificate profile.