You can create a new CSR, public key, and private key in the New
Signing Request dialogue.
![]() |
NoteCreating and deleting a signing request require the
Admin X509 Certificate Management capability in your
user role and the SMS certificate password.
|
Procedure
- Go to .
- Click New.
- Fill out the General section to specify CSR information used in
the SMS and to create the private key.
- Provide a unique request name for the CSR to be stored in the SMS. The request name is not stored in the generated CSR.
- Select a key size. We recommend 2048 bits or greater.
- For enhanced security, specify a robust signature algorithm (SHA256, SHA384, or SHA512). The default is SHA512.
- Check or uncheck "Make it a Signing Certificate". A signing certificate sets the key certificate sign bit in the key usage extension and sets the basic constraints extension to true.
- Fill out the Subject Distinguished Name section to define the
subject of the certificate to be generated for the CSR.
- (Optional) Provide a valid email address for the subject.
- Provide a fully qualified domain name or the IP address of the owner for the certificate as the CN.
- (Optional) Provide one or multiple (one per line) organization units or
department names of the certificate's subject DN, such as
engineering
andmarketing
. - (Optional) Provide the organization name of the certificate's subject DN.
- (Optional) Provide the locality or the city of the certificate's subject DN.
- (Optional) Provide the state of the certificate's subject DN.
- (Optional) Provide the two-letter ISO code for the country of the certificate's subject DN.
- Fill out the Subject Alternative Name section to add a DNS and
RFC822 name to the subject alternative name extension in the CSR.
- (Optional) Provide a domain name for the subject alternative name.
- (Optional) Provide a user name of the owner as an email address.
- Click
OK.
The CSR fields are saved to the SMS database. A public and private key pair is generated. A certificate is generated from the data and is used to create the actual CSR to be saved in the SMS database.