Dogtag CA
Configure connection to Dogtag CA and create certificate templates.
Prerequisites
To allow access to the Dogtag CA section:
- Launch the Axidian CertiFlow Configuration Wizard and go to Certificate authorities.
- Enable integration with Dogtag CA.
Connect to the CA
- Go to Configuration and open the policy settings.
- In the PKI settings section, go to Dogtag CA → Certificate authorities.
- Click Add CA.
- In the Server address field, specify the Dogtag CA server address. For example,
https://<CA server name>:8443. - In the Client certificate field, select the CA Agent certificate to connect to the CA. How to issue the CA Agent certificate
- Click Add.
Create certificate templates
Before you begin, make sure that the certificate templates are configured in Dogtag CA.
How to configure Dogtag CA certificate templates
To create a certificate template:
- Open policy settings and go to Dogtag CA → Templates section.
- Click Create certificate template.
- Configure the required parameters and click Create.
| Parameter | Description |
|---|---|
| Name | The certificate template name |
| CA | The CA name |
| Dogtag CA certificate template | Certificate template loaded automatically from Dogtag CA |
| Key size | RSA key size. If the Dogtag CA certificate template has a supported structure, the available values are loaded automatically. |
| Key name prefix | An arbitrary string added at the beginning of the key container name. If no prefix is specified, the container name is generated automatically. The container name with the prefix is displayed in Axidian CertiFlow and in third-party software for managing private key containers. Some devices may not support displaying the container name with a prefix. |
| Include in subject name | Specify the attributes to form the certificate Subject name:Attribute list
|
| Include in alternative subject name | Specify the attributes to form the certificate Subject Alternative Name:Attribute list
|
| Backup key | When a key pair is generated on a card, its backup copy is saved on the Axidian CertiFlow server. A key pair copy can only be saved once. If this option is disabled, the key pair is generated on the card directly. |
| Copy backup key to temporary card | Certificate and private key copies are written to the card during a temporary replacement. |
| Import certificate if exists | Axidian CertiFlow uses the certificate from the card instead of issuing a new certificate (for the specified user, CA, and template). If the card is initialized before issuance, the certificate is removed. |
| Do not remove certificate at card updating/clearing | When a card is updated or cleared, the expiring or expired certificates are not removed from the card and the certificates are not revoked in the CA. When a card is updated, a new certificate with a new private key is requested and written to the card. The expiring or expired certificates are removed if the card is withdrawn and initialized. |
| Revoke certificate at card revoking/disabling | Certificates are revoked when a card is disabled or revoked. |
| Install certificate to local store | When a card is issued or updated in the Self-Service, the certificates written to the card are added to the user's local certificate store. |
| Publish certificate to user catalog | The issued certificate is published to the user catalog. Certificates are not removed from the catalog when a card is revoked. |
| Remove published certificate at card revoking | When a card is revoked, the published certificate is removed from the user catalog. |
| Publish certificate to file storage | The issued certificate is published to network file storage. Certificates are not removed from the storage when a card is revoked. This option is available if the Publish certificates to file storage option is enabled in the Configuration Wizard under System features. |
| Accept certificate request automatically | The certificate request is approved automatically. If this option is disabled, you must wait for the CA to approve the request. |
| Require signed certificate document before continuing card issuing/updating | The certificate is written to the card after the user provides a signed certificate form to the administrator for verification. After the CA approves the request, the certificate form becomes available to the user in the Self-Service. The user can download the certificate form, sign and submit it for review. |
| Tracked user attributes | Specify user attributes that require certificate renewal when updated.Attribute list
|
| Print templates | Upload the document templates in the Configuration → Print templates section. If there are no document templates, the default print templates are used. |
| Renewal period (days) | The time period during which the certificate and private key can be renewed. The default value is 30 days. |
| Optional certificate | When a card is issued or updated, you can select which optional certificates to write to the card. If this option is disabled, certificates are written to the card by default. |