Skip to main content
Version: Axidian CertiFlow 7.3

Issue

You can either receive a ready-to-use card from the administrator or issue a card yourself from an empty one. If your card is already ready to use, you will see all its information when you log in to Self-Service.

Issue a card

The administrator defines the list of issuance options in policy settings. The following steps describe how to issue a card with the maximum set of options.

  1. Connect a card to the workstation.

  2. Click Issue card.

  3. Select certificate templates.

    Administrator settings

    The user can select certificates if you enable the Select optional certificates when card is issued option in policy settings (Workflow→User permissions→Card issuing operations).

  4. Depending on the administrator settings, the card is either initialized or not initialized when issued.

    1. Enter User PIN.
    2. Enter Admin PIN.
    Administrator settings

    The Admin PIN field is displayed if the card was not added to Axidian CertiFlow and you enabled the Allow user to add cards when they are issued option in policy settings (Workflow→General).

    info

    If you do not set Admin PIN and User PIN, Axidian CertiFlow uses the PIN values specified by the administrator in Card types.

    1. Click Issue.
    2. If your card stores third-party certificates, select the certificates to register them in Axidian CertiFlow.
    Administrator settings

    The user can select certificates if you enable the Search for certificates when card is issued or updated to track validity period and Allow user to select tracked certificates options in policy settings (Workflow→General).

  5. If a random PIN was set during the card issue, it is displayed on your screen. If necessary, save your PIN and email it to yourself or your manager.

    Administrator settings

    A random PIN is set if you enable the Set random user PIN option in policy settings (Issuance).

    The PIN value can be sent by email if you configure email notifications.

  6. Click Close.

After you issue a card, it is displayed in Your cards.

Send documents for approval

Card issuance can be suspended if, according to your company's regulations, the certificate is issued only after documents are approved by the CA or the administrator. In the card issue window, you will see the message Card issue pending and the card gets the Pending status.

info

The administrator defines the document approval settings. For more information, see Administrator guide.

Types of documents

Depending on the regulations, the set of documents varies:

  • Certificate request — submitted to the CA for approval. The administrator can precheck the request.
  • Certificate — submitted to the administrator for review after the CA approves the certificate.
  • Certificate request and certificate — first the CA approves the request, then the administrator reviews the certificate.

How to send documents

Send the documents for the certificate:

  • Through Axidian CertiFlow, if the internal document management functionality is configured.
  • Outside Axidian CertiFlow, by any other means authorized in your company. For example, by email.

To send a document for approval:

  1. Open the card menu and go to the Contents tab.

  2. Open the document:

    • For a certificate request — click next to the required certificate template.
    • For a certificate — click next to the required certificate template and select Certificate.
  3. Sign the document. How to sign documents

    Repeat steps 2 and 3 for each requested document.

  4. Wait for approval. The certificate status on the Contents tab changes depending on the stage:

    • Pending — the request has been submitted, the CA or administrator has not yet made a decision.
    • Valid — the CA has approved the request, the certificate is awaiting administrator review.
    • Approved — all checks have been passed, the certificate is ready to be written to the card.
  5. When the certificate gets the Approved status, open the card menu and click Resume issuing.

If the request is rejected in the CA, revoke and clear the card or contact the administrator, then start the card issue operation again.

If the administrator rejected a document, correct the errors and re-upload the document to Axidian CertiFlow.

Notifications

If the administrator configured automatic email notifications, you will receive emails about the progress of approval:

  • Document approved — the administrator approved the document.
  • Card issue approved — the certificate is ready to be written to the card.
  • Card issue rejected — the card issue is rejected.

If notifications are not configured, monitor the certificate status on the Contents tab and the appearance of the Resume issuing option in the card menu.

Issue virtual cards

You can issue the following types of virtual cards in Axidian CertiFlow:

  • Registry
  • TPM Virtual Smart Card (VSC)
  • Windows Hello for Business
  • AirCard
Administrator settings
  1. Configure Registry cards support.
  2. Add the Registry.xml card type in Axidian CertiFlow.
  3. Install the AxidianCertiFlow.Registry.Middleware component on user workstations.
Registry cards issue properties
  • Only RSA certificates are supported
  • PIN management is not supported
  • Card initialization is not supported

To issue a Registry card:

  1. Click Issue card.
  2. Enter the card name.
  3. In the Card field, select the following:
    • Registry - Machine: Registry, to issue a certificate in the local computer certificate store.
    • Registry - User: Registry, to issue the certificate in the current user’s certificate store.
  4. Click Issue. Axidian CertiFlow sends the certificate request to the CA.
  5. Create a password for the private key container in the RSA private key creation window.
    This is required if the administrator has enabled the Prompt the user during enrollment and require user input when the private key is used option on the Request Handling tab in the Microsoft CA Certificate Template settings.
    1. Click Select security level and enter a password that meets your company’s security requirements.
    2. Click Finish and OK.

caution

It is not possible to reset the key container password. If you do not remember the key container password, issue the certificate again.