Sub-CAs signed by ICAs - ICA's now may sign sub-CAs that can be used for issuance or other certificate management.
Edit CA configurations - Existing CA configuration (OCSP, CRL, and AIA settings) may now be edited from the details page of the desired CA.
Designate CAs to sign SCEP Requests - When creating new CAs, there is now an option to designate that CA as being able to sign and decrypt SCEP packets when called from IOT manager and others.
Dynamic issuance of CAs - Account scope users may be permitted to create CAs within various constraints set by their administrators, so that creation responsibilities may be delegated to users with limited-access.
Was this helpful?