Skip to main content
Version: Axidian CertiFlow 7.1

Issue

You can get a ready-to-use card or issue a card yourself if you have an empty card. If you have a ready-to-use card, all information about this card is displayed when you log in to Self-Service.

Issue a card

The administrator defines the list of issuance options in policy settings. The following instruction describes how to issue a card with the maximum available options.

  1. Connect a card to the workstation.

  2. Click Issue card.

  3. Select certificate templates.

    Administrator settings

    The user can select certificates if you enable the Select optional certificates when card is issued option in policy settings (Workflow→User permissions→Card issuing operations).

  4. Depending on the administrator settings, the card is either initialized or not initialized when issued.

    1. Enter User PIN.
    2. Enter Admin PIN.
    Administrator settings

    The Admin PIN field is displayed if the card was not added to Axidian CertiFlow and you enabled the Allow user to add cards when they are issued option in policy settings (Workflow→General).

    info

    If you do not set Admin PIN and User PIN, Axidian CertiFlow uses the PIN values specified by the administrator in Card types.

    1. Click Issue.
    2. If your card stores third-party certificates, select the certificates to register them in Axidian CertiFlow.
    Administrator settings

    The user can select certificates if you enable the Search for certificates when card is issued or updated to track validity period and Allow user to select tracked certificates options in policy settings (Workflow→General).

  5. If a random PIN was set during the card issue, it is displayed on your screen. If necessary, save your PIN and email it to yourself or your manager.

    Administrator settings

    A random PIN is set if you enable the Set random user PIN option in policy settings (Issuance).

    The PIN value can be sent by email if you configure email notifications.

  6. Click Close.

After you issue a card, it is displayed in Your cards.

If you have not set the answers to secret questions, proceed to the secret questions settings.

Documents check

Card issue can be suspended if your company’s regulations require the documents check and approval before you obtain your certificates.

In the card issue window, you can see this message: Card issue pending. The card has Pending status. This means that your card issue request is awaiting approval.

You can send the documents in the following ways:

  • Using Axidian CertiFlow if the administrator configured the internal electronic document management functionality.
  • By any other means authorized in your company. For example, via email.

If the administrator configured the internal electronic document management functionality, send your documents to the administrator in Self-Service.

info

The administrator defines the document approval settings. For more information, see Administrator guide.

Sign and upload the following documents to Axidian CertiFlow.

Certificate request

Submit a signed certificate request form for it to be approved in the certification authority (CA). The administrator can precheck the certificate request before it is sent to the CA.

  1. Upload the signed certificate request to Axidian CertiFlow:
    1. Print out the certificate request. Open the Contents tab in your card menu and click ! .
    2. Sign the certificate request and upload it to Axidian CertiFlow. How to sign and upload a document to Axidian CertiFlow
  2. Wait for the certificate request to be approved in the CA. On the Contents tab in your card menu you can check the certificate status – Pending.
  3. If the certificate request is approved in the CA, it gets the Approved status and is written on the card. Open the card menu and click Continue card issue.
    If the request is rejected, revoke and clear the card or contact the administrator, then restart the card issue operation.
info

If the administrator configured user email notifications, you will receive an email with the approval status notification – Card issue approved or Card issue rejected.

If user notifications are not configured, wait for the Continue card issue option to appear in the card menu.

Certificate form

If your company’s e-signature verification certificate policy requires additional approval of the certificate form, the administrator must approve the document before writing the certificate to the card.

In this case, the CA approves the certificate automatically. On the Contents tab in the card menu, you can check the status of the certificate – Valid. This means that the certificate has been issued in the CA, but not yet written to the card.

  1. Upload the signed certificate form to Axidian CertiFlow:
    1. Print the certificate form. Open the Contents tab in the card menu, click ! next to the certificate template and select Certificate.
    2. Sign the certificate form and upload it to Axidian CertiFlow. How to sign and upload a document to Axidian CertiFlow
  2. Wait for the administrator to approve the document.
  3. If the administrator has approved the document, the certificate is written to the card. Open the card menu and click Continue card issue.
    If the administrator has rejected a document, edit and sign the document again and upload it back to Axidian CertiFlow.
info

If the administrator configured user email notifications, you will receive an email with the approval status notification– Document approved.

If user notifications are not configured, wait for the Continue card issue option to appear in the card menu.

Certificate request and certificate form

To continue the card issue operation and write a certificate to the card:

  1. Submit a signed certificate request form and wait for the request to be approved in the CA.
  2. Submit a signed certificate form and wait for the administrator to approve the document.

Use the following procedure:

  1. Upload the signed certificate request to Axidian CertiFlow:

    1. Print out the certificate request. Open the Contents tab in your card menu and click ! .
    2. Sign the certificate request and upload it to Axidian CertiFlow. How to sign and upload a document to Axidian CertiFlow
  2. Wait for the certificate request to be approved in the CA.

  3. If the certificate request is approved in the CA, the certificate status is Valid. This means that the certificate has been issued in the CA, but not yet written to the card. Upload the signed certificate form to Axidian CertiFlow for admininstrator's check:

    1. Print the certificate form. Open the Contents tab in the card menu, click ! next to the certificate template and select Certificate.
    2. Sign the certificate form and upload it to Axidian CertiFlow.

    If the request is rejected in the CA, revoke and clear the card or contact the administrator, then restart the card issue operation.

  4. If the administrator has approved the document, the certificate is written to the card. Open the card menu and click Continue card issue.
    If the administrator has rejected a document, edit and sign the document again and upload it back to Axidian CertiFlow.

info

If the administrator configured user email notifications, you will receive an email with the approval status notification – Document approved, Card issue approved or Card issue rejected.

Issue virtual cards

You can issue the following types of virtual cards in Axidian CertiFlow:

  • Registry
  • TPM Virtual Smart Card (VSC)
  • Windows Hello for Business
  • AirСard
Administrator settings
  1. Configure Registry cards support.
  2. Add the Registry.xml card type in Axidian CertiFlow.
  3. Install the CertiFlow.Registry.Middleware component on user workstations.
Registry cards issue properties
  • Only RSA certificates are supported
  • PIN management is not supported
  • Card initialization is not supported

To issue a Registry card:

  1. Click Issue card.
  2. Enter the card name.
  3. In the Card field, select the following:
    • Registry - Machine: Registry, to issue a certificate in the local computer certificate store.
    • Registry - User: Registry, to issue the certificate in the current user’s certificate store.
  4. click Issue. Axidian CertiFlow send the certificate request to the CA.
  5. Create a password for the private key container in the RSA private key creation window.
    This is required if the administrator has enabled the Prompt the user during enrollment and require user input when the private key is used option on the Request Handling tab in the Microsoft CA Certificate Template settings.
    1. Click Select security level.. and enter a password that meets your company’s security requirements.
    2. Click Finish and ОК.

caution

It is not possible to reset the key container password. If you do not remember the key container password, issue the certificate again.