2.2.4.1.4.2 Creating a CSR From OCLM Node
Perform the following procedure to create a CSR from an OCLM node:
- From the main menu, navigate to Administration, General Options, and set Enable OCLM Feature to 1.
- Configure Certificate Lifecycle Manager Config.
- From the Certificate Management page, click Create CSR from OCLM Node.
- From the Create CSR CLM Node page, enter the 2 character country code.
- Enter the full name of the State or Province.
- Enter the Locality name.
- Select the Common Name for the entity being included in the CSR.
- Enter the entity Organization.
- Enter the certificate Validity (in days).
- In the Subject Alternative Name section, select whether Critical is enabled or disabled.
- Enter one or more IP Addresses, if required. Click Add to add another IP address row.
- Enter one or more DNS Names, if required. Click Add to add another DNS name row.
- In the Key Usage section, select whether Critical is enabled or disabled.
- Select the Key Usage Values.
- In the Extended Key Usage section, select whether Critical is enabled or disabled.
- Select the Extended Key Usage Values.
- Click Generate CSR to submit the information to the OCLM node.
- Click Back to return to the Certificate Management page.
Note:
When the selected Common Name matches the subject CN of an existing OCLM managed certificate, the form is prefilled from that certificate. Prefilled values include Country, State or Province, Locality, Organization, Subject Alternative Name IP Addresses, Subject Alternative Name DNS Names, Key Usage values, Extended Key Usage values, and the critical flags for these extensions. If no matching OCLM managed certificate is found the default form values are used.