2.2.4.1.4.1 Creating CSR from OCLM Node Fields

The following table describes the fields used when creating a CSR from an OCLM node:

Table 2-38 Create CSR From OCLM Node Fields

Fields Description Data Input Notes
Country The 2 letter country code where the entity being described lives. Required. Must be exactly 2 uppercase letters.

Range: A to Z

State or Province The state or province full name where the entity being described lives. Required.

Range: 1-100 characters. Allowed characters are A-Z, a-z, spaces, and hyphens.

Locality The locality name, for example, city, of the entity being described. Required.

Range: 1-100 characters. Allowed characters are A-Z, a-z, spaces, and hyphens.

Common Name The common name of the entity being described. Required. Select a server host name from the list. The system domain is appended to the host name. The list includes configured server host names and server group names with the system domain appended. It also includes configured LDAP server host values only when the LDAP host is a DNS name. Common names are case insensitive and must be unique.
Organization The name of the organization to which the entity belongs. Required.

Range: 1-100 characters. Allowed characters are A-Z, a-z, spaces, and hyphens.

Validity (in days) The certificate validity period in days. Required.

Range: Enter a positive numeric value.

Default: 365

Critical Indicates whether the Subject Alternative Name extension is marked as critical. Values: Enabled, Disabled.

Default: Enabled

IP Addresses List of IP addresses to include in the Subject Alternative Name extension. Optional. Up to 32 entries. IPv4 and IPv6 address values can be entered. Blank entries are ignored.
DNS Names List of DNS domain names to include in the Subject Alternative Name extension. Optional. Up to 32 entries. Maximum length is 255 characters for each DNS name. Blank entries are ignored.
Critical Indicates whether the Key Usage extension is marked as critical. Values: Enabled, Disabled

Default: Enabled

Key Usage Values The key usage values to include in the CSR. At least one value is required.

Available values: DIGITAL_SIGNATURE, KEY_ENCIPHERMENT.

Critical Indicates whether the Extended Key Usage extension is marked as critical. Values: Enabled, Disabled

Default: Enabled

Extended Key Usage Values The extended key usage values to include in the CSR. At least one value is required. Available values: CLIENT_AUTH, SERVER_AUTH.

Note:

If the Enable OCLM Feature option is not enabled in General Options, the Certificate Lifecycle Manager configuration cannot be added. Additionally, if the Certificate Lifecycle Manager Configuration is not defined, a Certificate Signing Request (CSR) cannot be generated from an OCLM node.