Skip to main content

Create a certificate profile for REST API

To create a profile using the REST API enrollment method:

  1. In DigiCert​​®​​ Trust Lifecycle Manager, navigate to Policies > Base templates.

  2. Select Public S/MIME Secure Email (via CertCentral) template.

    Nota

    If you have not created a CertCentral CA connector you see the summary steps to create one.

    Create_CC_connector.png
  3. Under Primary options, enter a Profile name.

    1. Select a Business unit, Certificate type and publicly-trusted Issuing CA from the respective drop-down lists.

      Primary_options.png
    2. The REST API enrollment method and Third Party app authentication method is populated.

      Third_party.png
    3. Click Next to configure Certificate options.

      • Certificate expiry period

      • Signing algorithm

      • Key type and size

      • Flow options

        Nota

        Duplicate certificates are set to Yes. Also, we do not support a Cloud Key Escrow option yet.

        Certificate_options.png
    4. Set the allowed Renewal window.

    5. Set the required Subject DN and SAN certificate fields, and their sources: REST Request or Fixed Value.

      Subject_DN_and_SAN.png
  4. To configure the Key Usages and Extended Key Usages extensions, click Next.

    1. Key usage

      key_usage.png
    2. Extended key usage

      ex_key_usage.png
  5. To configure Additional options, click Next.

    1. Configure revocation email notification.

      revocation_email.png
    2. Add organization details. Select or search for an organization from the list of organizations available on your CertCentral account. All issued certificates are bound to the selected organization and include the Organization value inside the Subject DN.

      org_details.png
    3. Add contact details. Select contact details (Name, Email, Phone) linked to the validated organization, or select custom contact details.

      contact_details.png
  6. To configure Advanced settings, click Next.

    • Select one or multiple service users from the drop down list, which are configured with an API KEY or Certificate for authentication. See Create a service user section above for details.

      adv_settings.png
  7. Click Create to save the profile configuration.