Skip to main content
Version: Axidian CertiFlow 7.3

Dogtag CA

Configure connection to Dogtag CA and create certificate templates.

Prerequisites

To allow access to the Dogtag CA section:

  1. Launch the Axidian CertiFlow Configuration Wizard and go to Certificate authorities.
  2. Enable integration with Dogtag CA.

Connect to the CA

  1. Go to Configuration and open the policy settings.
  2. In the PKI settings section, go to Dogtag CACertificate authorities.
  3. Click Add CA.
  4. In the Server address field, specify the Dogtag CA server address. For example, https://<CA server name>:8443.
  5. In the Client certificate field, select the CA Agent certificate to connect to the CA. How to issue the CA Agent certificate
  6. Click Add.

Create certificate templates

Before you begin, make sure that the certificate templates are configured in Dogtag CA.
How to configure Dogtag CA certificate templates

To create a certificate template:

  1. Open policy settings and go to Dogtag CATemplates section.
  2. Click Create certificate template.
  3. Configure the required parameters and click Create.
ParameterDescription
NameThe certificate template name
CAThe CA name
Dogtag CA certificate templateCertificate template loaded automatically from Dogtag CA
Key sizeRSA key size. If the Dogtag CA certificate template has a supported structure, the available values are loaded automatically.
Key name prefixAn arbitrary string added at the beginning of the key container name. If no prefix is specified, the container name is generated automatically.

The container name with the prefix is displayed in Axidian CertiFlow and in third-party software for managing private key containers.

Some devices may not support displaying the container name with a prefix.
Include in subject nameSpecify the attributes to form the certificate Subject name:
Attribute list
  • Fully distinguished name (default value)
  • Common name
  • First name
  • Last name
  • Initials
  • E-mail
  • Title
  • Organization unit
  • Organization
  • Street
  • Locality
  • State
  • Country
Include in alternative subject nameSpecify the attributes to form the certificate Subject Alternative Name:
Attribute list
  • E-mail
  • Additional e-mail addresses
  • User principal name
Backup key

When a key pair is generated on a card, its backup copy is saved on the Axidian CertiFlow server. A key pair copy can only be saved once.

If this option is disabled, the key pair is generated on the card directly.
Copy backup key to temporary cardCertificate and private key copies are written to the card during a temporary replacement.
Import certificate if existsAxidian CertiFlow uses the certificate from the card instead of issuing a new certificate (for the specified user, CA, and template). If the card is initialized before issuance, the certificate is removed.
Do not remove certificate at card updating/clearing

When a card is updated or cleared, the expiring or expired certificates are not removed from the card and the certificates are not revoked in the CA. When a card is updated, a new certificate with a new private key is requested and written to the card.

The expiring or expired certificates are removed if the card is withdrawn and initialized.
Revoke certificate at card revoking/disablingCertificates are revoked when a card is disabled or revoked.
Install certificate to local storeWhen a card is issued or updated in the Self-Service, the certificates written to the card are added to the user's local certificate store.
Publish certificate to user catalogThe issued certificate is published to the user catalog. Certificates are not removed from the catalog when a card is revoked.
Remove published certificate at card revokingWhen a card is revoked, the published certificate is removed from the user catalog.
Publish certificate to file storage

The issued certificate is published to network file storage. Certificates are not removed from the storage when a card is revoked.

This option is available if the Publish certificates to file storage option is enabled in the Configuration Wizard under System features.

Accept certificate request automatically

The certificate request is approved automatically.

If this option is disabled, you must wait for the CA to approve the request.
Require signed certificate document before continuing card issuing/updatingThe certificate is written to the card after the user provides a signed certificate form to the administrator for verification.

After the CA approves the request, the certificate form becomes available to the user in the Self-Service. The user can download the certificate form, sign and submit it for review.
Tracked user attributesSpecify user attributes that require certificate renewal when updated.
Attribute list
  • Common Name
  • Email
  • User Principal Name (UPN)
Print templates

Upload the document templates in the Configuration → Print templates section. If there are no document templates, the default print templates are used.

Renewal period (days)The time period during which the certificate and private key can be renewed. The default value is 30 days.
Optional certificateWhen a card is issued or updated, you can select which optional certificates to write to the card.

If this option is disabled, certificates are written to the card by default.