Confirmed users, Administrators
5,526
edits
m (Add links to PEM Data help) |
m (Add links to PEM Data help) |
||
| Line 104: | Line 104: | ||
#* Or click on "CA Owners/Certificates" tab, then in "View:" select "Community User's CA Owners/Certificates" and click on "Go!". Click on the name of the root certificate to open the record. | #* Or click on "CA Owners/Certificates" tab, then in "View:" select "Community User's CA Owners/Certificates" and click on "Go!". Click on the name of the root certificate to open the record. | ||
# Click on the "New Intermediate Cert" button. This will create a new record for an intermediate cert chaining up to the certificate record you were just viewing. | # Click on the "New Intermediate Cert" button. This will create a new record for an intermediate cert chaining up to the certificate record you were just viewing. | ||
# Click on the "Add/Update PEM Info" button. This will display a window in which you will paste in the PEM data for the intermediate certificate. | # Click on the "Add/Update PEM Info" button. This will display a window in which you will paste in the [[CA:CommonCADatabase#PEM_Data|PEM data]] for the intermediate certificate. | ||
# Copy and paste the PEM data into the window. Starting with ''-----BEGIN CERTIFICATE-----'' and ending with ''-----END CERTIFICATE-----'' | # Copy and paste the [[CA:CommonCADatabase#PEM_Data|PEM data]] into the window. Starting with ''-----BEGIN CERTIFICATE-----'' and ending with ''-----END CERTIFICATE-----'' | ||
# Click on "Validate PEM Info" button. This will invoke a program that will try to parse the PEM data and extract certain information. | # Click on "Validate PEM Info" button. This will invoke a program that will try to parse the PEM data and extract certain information. | ||
# If the cert check is successful, then click on the "Update Intermediate Cert" button. | # If the cert check is successful, then click on the "Update Intermediate Cert" button. | ||
#* If the cert check was not successful, then click on the "Cancel" button. Check that the PEM data is correct and try again, by clicking on the "Add/Update PEM Info" button and copy-pasting the data in, etc. If it still fails, then send email to Kathleen with the PEM data. | #* If the cert check was not successful, then click on the "Cancel" button. Check that the [[CA:CommonCADatabase#PEM_Data|PEM data]] is correct and try again, by clicking on the "Add/Update PEM Info" button and copy-pasting the data in, etc. If it still fails, then send email to Kathleen with the PEM data. | ||
# In the intermediate certificate record you will see that the cert data has been filled in. | # In the intermediate certificate record you will see that the cert data has been filled in. | ||
#* Review the filled-in information (Issuer and Subject information, and SHA-1 Fingerprint) to ensure it is the data you expected. If the data is not what you expected, then check that you have the correct PEM data for the certificate you intended to add. Check the section titled "PEM Information..." to make sure the PEM is as you intended. There should not be extra characters before or after the PEM, and the PEM data should not have extra line feeds in it. You may go through the "Add/Update PEM Info" process as many times as needed. | #* Review the filled-in information (Issuer and Subject information, and SHA-1 Fingerprint) to ensure it is the data you expected. If the data is not what you expected, then check that you have the correct [[CA:CommonCADatabase#PEM_Data|PEM data]] for the certificate you intended to add. Check the section titled "PEM Information..." to make sure the PEM is as you intended. There should not be extra characters before or after the PEM, and the PEM data should not have extra line feeds in it. You may go through the "Add/Update PEM Info" process as many times as needed. | ||
# Fill in the information in the "[[CA:SalesforceCommunity#Audit_Information|Audit Information]]" and "[[CA:SalesforceCommunity#Policies_and_Practices_Information|Policies and Practices Information]]" sections. The audits and policies must cover the intermediate certificate. | # Fill in the information in the "[[CA:SalesforceCommunity#Audit_Information|Audit Information]]" and "[[CA:SalesforceCommunity#Policies_and_Practices_Information|Policies and Practices Information]]" sections. The audits and policies must cover the intermediate certificate. | ||
#* If the information is the '''same as for the issuing (parent) certificate''', then click on the "Edit" button, and check on the '''"... Same as Parent" check-boxes''' ("CP/CPS Same as Parent" and "Audits Same as Parent"), then click on the "Save" button. | #* If the information is the '''same as for the issuing (parent) certificate''', then click on the "Edit" button, and check on the '''"... Same as Parent" check-boxes''' ("CP/CPS Same as Parent" and "Audits Same as Parent"), then click on the "Save" button. | ||