Replace Identity Certificate field descriptions

Last Updated : Sep 23, 2020 |

Certificate Details

Name

Description

Subject Details

The certificate holder details.

Valid From

The date and time from when the certificate is valid.

Valid To

The date and time till the certificate is valid.

Key Size

The key size in bits for encryption. The default key size is 2048.

Issuer Name

The name of the certificate issuer.

Certificate Fingerprint

The fingerprint that authenticates the certificate.

Subject Alternative Name

An alternative name of the certificate holder.

Serial Number

The serial number of the certificate.

Basic Constraints

The extension that identifies whether the subject of the certificate is a CA and the maximum depth of valid certification paths that include this certificate.

Key Usage Extension

The extension that defines the purpose of the key contained in the certificate. For example, Digital Signature, Content Commitment, Key Encipherment, Data Encipherment, and Key Agreement.

Extended Key Usage

The extension that indicates one or more purposes for which the certified public key can be used. These are in addition to or in place of the basic purposes indicated in the key usage extension.

Name

Description

Replace this Certificate with Internal CA Signed Certificate

The option to replace the current certificate with the internal CA signed certificate.

Import third party certificate

The option to replace the identity certificate with the PKCS #12 file that you imported from a third-party source.

Generate Certificate Signing Request (CSR) for third party certificate

The option to generate a certificate signing request for a third-party certificate.

When you select Replace this Certificate with Internal CA Signed Certificate or Generate Certificate Signing Request (CSR) for third party certificate, the system displays the following fields.

Name

Description

Common Name (CN)

The common name of the certificate holder.

Key Algorithm

The algorithm used to generate the key for the certificate.

The option is RSA.

System Manager uses the SHA2 hash algorithm for generating certificates.

Key Size

The key size in bits for encryption. The options are:

  • 1028

  • 2048

  • 4096

    Note:

    Session Manager Release 6.3.12 and later support 4096.

Use 2048 as the key size.

Subject Alternative Name

An alternative name of the certificate holder. The options are:

  • DNS Name: The DNS IP address.

  • IP Address: The IP address.

  • URI: The URI address.

Note:

In DNS Name, IP Address, and URI fields, you can enter more than one value separated by a comma.

Do not add spaces between comma-separated IP addresses and DNS names.

Button

Description

Commit

Replaces the current identity certificate with the selected certificate.

Generate CSR

Generates a third-party certificate signing request.

When you select the Generate Certificate Signing Request (CSR) for third party certificate option, the system enables the Generate CSR button.

Cancel

Cancels the certificate replacement operation.

When you select Import third party certificate, the system displays the following fields.

Name

Description

Please select a file (PKCS #12 format)

The full path of the PKCS #12 file where you saved the certificate.

Password

The password to retrieve the certificate.

Button

Description

Retrieve Certificate

Retrieves the details of the imported certificate and displays them in the Certificate Details section.

Commit

Replaces the current identity certificate with the selected certificate.

Cancel

Cancels the certificate replacement operation.