Creating certificate objects on TPP
Depending on where you access this feature, you can create one of the following certificate types:
- A wholly new certificate
- A certificate based on an existing certificate
A wholly new TPP certificate has the TPP Certificate Folder, TPP Device Folder, and TPP Device Object fields already populated. This information comes from the TPPServer statement in the EC for Venafi gateway configuration member ECVGPARM.
A new certificate that is based on an existing certificate can have additional information populated in the Create new object in TPP window, for example, the certificate label, certificate owner, and common name.
To create a certificate
- From the EC for Venafi UI, choose the type of certificate you want to create by selecting one of the following options from the main menu:
- New certificate—Select Create New Certificate > Create Certificate on TPP.
- Based on existing certificate—Select Certificates > Show Certificates, and then next to the certificate that you want to use as a basis, click Select > Create Certificate on TPP.
The Create new certificate window is displayed.
Configure the certificate as required.
Parameter Description TPP Certificate Folder Location where you want to store the certificate TPP Certificate Object Name of the TPP certificate object associated with the certificate TPP Device Folder Location of the physical host on which the certificate will be installed TPP Device Object Name of the TPP device object associated with the certificate Certificate Label Unique identifier representing the certificate Certificate Owner Individual or entity responsible for managing the certificate CN Common name or host name for which the certificate is issued O Organization for which the certificate is issued OU Organizational unit for which the certificate is issued L Locality for which the certificate is issued S State for which the certificate is issued C Country for which the certificate is issued Site certificate Is the certificate a site certificate ICSF certificate Is the certificate stored in ICSF Key algorithm Algorithm used for encryption
EC for Venafisupports both Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC) keys.
Post Implement Script Script that can perform site-specific tasks after the successful creation of a certificate Select LPAR Target LPAR on which the certificate will be installed
The Response box shows if the LPAR you select is active.
- Click Submit.
The Response box shows if the certificate was created successfully.