To add or share certificates, follow these steps.
To add a new certificate
-
In the SPP web client, navigate to Vaults > Certificates.
-
Click Upload Certificate. Select a certificate in one of the supported file formats to upload it. SPP can read most *.cer, *.crt, *.der, *.pfx, *.p12, and *.pem file formats.
-
This is also how you redeem or fulfill a previously created certificate signing request that exists for your user in SPP. If the uploaded certificate’s public key matches the key of a CSR, SPP will automatically associate them to complete the CSR. The CSR will then be automatically deleted.
To share a certificate with another user or user group
-
On the certificates section in the grid, click Edit.
-
On the Edit dialog, set the following:
-
Owner: Assign certificate ownership to another user.
-
Owner group: Assign certificate ownership to a user group.
-
Private Key Shareable: To allow share members access to the private key, select this check box. Otherwise, they will only be granted access to the public portion of the certificate.
-
Passphrase Required: To require the share members to enter a password used to encrypt the certificate before allowing them to download it, select this check box.
NOTE: This option is not typically used with just public key certificates.
-
Notify Days Before Expiration: Enter the number of days before the certificate’s expiration date that an email notification will be sent to the owner(s).
NOTE: Only one email will be sent. SPP will not, for example, continue to send out emails.
-
Notify Days After Expiration: Enter the number of days after the certificate’s expiration date that an email notification will be sent to the owner(s).
-
(Optional) Notes: Enter any additional information about the certificate.
-
You can then add one or more users or user groups to share the certificate with:
-
To save the certificate share details, click Save .
To replace certificate with existing certificate
-
Click Replace Certificate and select a new certificate to replace the selected item with. Certificates typically have an expiration date and need to be updated. To preserve the settings you might have configured, such as the list of shared users, use this option instead of uploading a completely new item.