Difference between revisions of "Certificate Enrollment with PKI CLI"

From Dogtag
Jump to: navigation, search
m (Edewata moved page Issuing SSL Server Certificate with PKI CA to Certificate Enrollment with PKI CLI without leaving a redirect)
m (Reviewing Certificate Request)
 
Line 28: Line 28:
 
<pre>
 
<pre>
 
$ pki <agent authentication> ca-cert-request-review <request ID> --action approve
 
$ pki <agent authentication> ca-cert-request-review <request ID> --action approve
 +
</pre>
 +
 +
or
 +
 +
<pre>
 +
$ pki <agent authentication> ca-cert-request-<action> <request ID>
 
</pre>
 
</pre>
  

Latest revision as of 23:39, 24 June 2020

Submitting Certificate Request

To submit a certificate request:

$ pki ca-cert-request-submit --profile caServerCert --csr-file sslserver.csr

Reviewing Certificate Request

To review the certificate request:

$ pki <agent authentication> ca-cert-request-review <request ID> --file <filename>

It will store the certificate request in the output file and wait for an action. The file should be reviewed manually and may be edited if necessary.

Then enter one of the following actions to complete the review:

  • approve
  • reject
  • cancel
  • update
  • validate
  • assign
  • unassign

Alternatively, the approval process can be done in a single step:

$ pki <agent authentication> ca-cert-request-review <request ID> --action approve

or

$ pki <agent authentication> ca-cert-request-<action> <request ID>

Checking Certificate Request Status

To check the certificate request status:

$ pki ca-cert-request-show <request ID>

Retrieving Certificate

To download the certificate:

$ pki ca-cert-show <certificate ID> --encoded --output <filename>

See Also