Edit a PKIaaS CA
Once you create the PIV Content Signer for a PKIaaS CA, you can edit the digital ID configurations.
To edit a PKIaaS CA:
-
Log in to your Identity as a Service administrator account.
-
Click > Resources > Certificate Authorities. The Certificate Authorities List page appears.
-
Click the name of your PKIaaS CA. The Edit Entrust PKIaaS Certificate Authority page appears.
-
You can edit the following:
- Name
- Digital ID Configurations
- PIV Content Signer Algorithm
-
To edit the digital ID configurations:
- Click the digital ID, for example, PIV Card. The Edit Entrust PKIaaS Digital ID Configuration page appears.
- Edit the following fields, as required:
- Name
- Searchbase
- Select a new Type from the drop-down list. A smart credential can have two digital IDs:
- PIV Card Holder
- PIV Card
- DN Format
- Deselect Include Searchbase in DN if you do not want to include the searchbase in the DN.
-
Add additional Cert Templates, as follows:
- Do one of the following:
- Click Add to add a new certificate template. The Add Cert Template dialog box appears.
- Click an exiting certificate template. The Edit Cert Template dialog box appears.
- From the Type drop-down list, select the type of certificate template defined in PKIaaS. The options include:
- Piv Authentication
- Card Authentication
- Digital Signature
- Key Management (encryption)
- From the Key Type drop-down list, select the key type of that matches the certificate container in the smart credential.
- Set the Certificate Lifetime, choosing one of the following options:
- Select Use CA Default Certificate Lifetime to set the certificate template to expire when the default CA certificate expires.
- Set the Certificate Lifetime (months) to set the lifetime of the CA certificate. The range is 0-100 months.
- Click Add.
- Do one of the following:
-
Add additional Subject Alt Names. The
subjectAltNameextension can contain alternative names for the subject of the certificate. These entries in the Identity as a Service Digital ID listsubjectAltNamevalues that Identity as a Service sends to the CA so that they are included in the certificate. For example, the default template includes the user's email address and userPrincipalName.To add SubjectAltNames
- Click Add to add Subject Alt Names. The Add Subject Alt Name dialog box appears.
- From the Type drop-down list, select
- Enter a Value.
- Click Add.
- To delete a Certificate Template, click next to the certificate template.
-
Click Save.