Digi-Sign, The Certificate Corporation
Published on Digi-Sign, The Certificate Corporation (http://www2.digi-sign.com)

Home > Issuing Certificates

By Digi-Sign
Created Apr 29 2010 - 07:39

Issuing Certificates

Step 3 - Issuing Digi-Access™ Certificates to the End Users

The Digi-CA™ [1] Certificate Authority [CA] system (that issues the Digi-Access™ end user certificates) can issue thousands of certificates every hour. This 'endless' capacity means that getting Digi-Access™ certificates to the end users can occur as quickly as your environment demands.

Allow 30+ Minutes

How the Digi-Access™ certificates are issued is set by the 'Enrolment Policy [2]'. The options within the Enrolment Policy are designed to be very flexible. They can be customised to meet almost any requirement with many different settings and combinations. The three basic options are:


  • Manual

    • Inviting and approving requiring manual input from the Administrator

  • Automated

    • Inviting and approving are completely automated

  • Combination

    • Inviting and approving may require some manual input from the Administrator

Overview of the Issuing Process

Issuing the Digi-Access™ certificates is either a one or two stage process. Either the user receives an email inviting them to apply for their certificate, or they are referred from an existing online site/system to the Certificate Application form.

However the user is prompted to get their certificate, in the first stage, the Digi-CA™ Inviting 'action' requires the end user 'reaction' (completing an application form). In the second stage, the Digi-CA™ Approving 'action' requires the end user 'reaction' (activating the certificate) and this completes the process. It is best understood as follows:


  • Inviting each end user to complete the online enrolment form

    • Completing the enrolment form by the end user

  • Approving each correctly completed enrolment and issuing the approval notice

    • Activating the certificate by the end user

Sample Issuing Process

As stated, because the Enrolment Policy is very flexible, there are many different ways to invite and approve end users certificates. The following is a sample issuing process only. You may wish to include other options, as required.

Stage One 'Digi-CA™ Action' - Inviting Digi-Access™ Certificate Applications

Using the Digi-CA™ RA Management Console interface, the Administrator uploads a .CSV batch file inviting [3] as many users as required.


Review the other available invitation [3] options.

Stage One 'User Reaction' - Completing Enrolment Form

The Digi-CA™ system sends an email to each end user with a unique link to the Digi-Access™ certificate enrolment form. Using the link provided in the email, the end user then completes the Digi-Access™ certificate enrolment form.

Note:- this is the default Digi-Access™ End Entity Digital Certificate Enrolment Form. This form uses basic HTML programming that can be altered [4] to match your specific design requirements.


See other sample enrolment [4] forms.

Stage Two 'Digi-CA™ Action' - Approving Enrolment Applications

Once the end user completes all the fields and submits the enrolment form to the Digi-CA™ system, the Administrator is notified. The Administrator then approves [2] each end user application using the Digi-Access™ certificate Authorization Panel.


Depending on the Enrolment Policy [2] this stage may be automated.

Stage Two 'User Reaction' - Activating the Digi-Access™ Certificate

Assuming the Administrator approves the application, the Digi-CA™ system sends a new email to the end user advising them that their application has been approved. Using the link provided in the email, the end user then activates [5] the Digi-Access™ certificate and this completes the issuing process.


See other sample certificate activation [5] forms.
Thumbnail: 

Sample Application Forms


Examples of How the Digi-Access™ Application Forms can be Customised
The Digi-Access™ End Entity Digital Certificate Enrolment Form uses basic HTML programming that can be altered to match your specific design requirements. Below are some samples of customised enrolment pages:





Note:- In addition to changing the 'look and feel' of the enrolment page you will notice that the fields required on the form can be altered according to the specific Enrolment Policy [2] set by the organisation.




Once the enrolment form is completed and submitted by the end user, the Enrolment Policy enforces how the application is handled by the Digi-CA™ system. Learn more about the Enrolment Policy [2] options or browse the other pages below.

Sample Mobile Application Form


Sample Customised Digi-Access™ Mobile Application Form

The Digi-Access™ [6] Mobile End Entity Digital Certificate Enrolment Form for mobile users is basic HTML programming that can be altered to match your specific design requirements. Below is a sample of a customised enrolment page:





Note:- In addition to changing the 'look and feel' of the enrolment page you will notice that the fields required on the form can be altered according to the specific Enrolment Policy [2] set by the organisation.


Once the enrolment form is completed and approved, the user is notified by email and uses the link in that email to download [7] and install their Digi-Access™ certificate to their mobile device.


Certificate Invitation Options

Descriptions of the Digi-Access™ invitations options
Digi-Access™ certificates are issued according to the Enrolment Policy. The first stage is the Inviting stage that is controlled by the End Entity Account Manager interface in Digi-CA™. There are three options:

  • Single manual invitation

    • Inviting each end user one-at-a-time





  • Batch manual invitation

    • Inviting multiple end users in a single batch upload





  • Automated invitation

    • Inviting multiple end users automatically





Once the invitation is issued, the end user must complete the enrolment form. View customised enrolment [4] forms or browse the other pages below.


Enrolment Policy

Descriptions of the Digi-Access™ invitations options
The Enrolment Policy for Digi-Access™ controls the entire certificate issuing process. Enrolment Policy is set by the Certificate Policy [CP] for the Digi-CA™. This is a specialist subject and requires experienced knowledge of Certificate Authority [CA] systems and Public Key Infrastructure [PKI]. Keeping this complex topic simple, there are three basic options for Enrolment Policy:
  • Manual

    • Inviting and approving requires manual inputs from the Administrator



  • Automated

    • Inviting and approving are completely automated. If the Enrolment Policy is to completely automate the approval process, it will be based on rules. Enrolment Policy Rules are also too complex a topic to explain here, however, here are some simple examples where certificates requests are approved based on:


                • a specific domain being used in the enrolment form

                • a specific phone number being used in the enrolment form

                • a specific PIN number being used in the enrolment form


  • Combination

    • Inviting and approving may require some manual input from the Administrator. Again in this instance, part of the process (and most likely the approval) will be automated and will be based on rules similar to those above.


    Once the application is approved, the end activates their Digi-Access™ certificate using the End Entity Digital Certificate Collection form. View customised activation [5] forms or browse the other pages below.

Sample Activation Forms


Examples of How the Digi-Access™ Application Forms can be Customised
The Digi-Access™ End Entity Digital Certificate Enrolment Form uses basic HTML programming that can be altered to match your specific design requirements. Below are some samples of customised enrolment pages:





Note:- In addition to changing the 'look and feel' of the enrolment page you will notice that the fields required on the form can be altered according to the specific Enrolment Policy [2] set by the organisation.




Once the enrolment form is completed and submitted by the end user, the Enrolment Policy enforces how the application is handled by the Digi-CA™ system. Learn more about the Enrolment Policy [2] options or browse the other pages below.


Sample Mobile Activation Form


Examples of How the Digi-Access™ Application Forms can be Customised

The Digi-Access™ End Entity Digital Certificate Enrolment Form uses basic HTML programming that can be altered to match your specific design requirements. Below are some samples of customised enrolment pages:

Note:- In addition to changing the 'look and feel' of the enrolment page you will notice that the fields required on the form can be altered according to the specific Enrolment Policy [2] set by the organisation.

Once the enrolment form is completed and submitted by the end user, the Enrolment Policy enforces how the application is handled by the Digi-CA™ system. Learn more about the Enrolment Policy [2] options or browse the other pages below.

Digi-Access™ can be used with most modern smart phones and tablets (contact support [8] to check your specific device).


  • IIS Implementation Guide

Source URL: http://www2.digi-sign.com/digi-access/distribute

Links:
[1] http://www2.digi-sign.com/digi-ca
[2] http://www2.digi-sign.com/digi-access/distribute/policy
[3] http://www2.digi-sign.com/digi-access/distribute/invite
[4] http://www2.digi-sign.com/digi-access/distribute/enrol
[5] http://www2.digi-sign.com/digi-access/distribute/activate
[6] http://www2.digi-sign.com/digi-access/mobile
[7] http://www2.digi-sign.com/digi-access/mobile/download
[8] http://www2.digi-sign.com/mailto