The use of third party certificates is optional. Third party certificates are not required.
A third party CA can be a commercial vendor such as VeriSign and Symantec, or an enterprise-run CA that is maintained by the customer’s IT department. You can create third party certificates using openssl or open source tools such as EJBCA (http://www.ejbca.org).
Use this checklist for using third party Identity Certificates.