Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Verify the subdomain of the host you are requesting an SSL certificate for has already been approved by your Department InCommon Administrator (DRAO)
  2. Verify the FQDN of the host you are requesting an SSL certificate for is properly registered in DNS
  3. Go to the Certificate Manager at https://cert-manager.com/customer/InCommon/ssl?action=enroll
  4. Enter your @uci.edu email address and use the Access Code given to you by your DRAO and click Check Access Code (OIT staff please see /wiki/spaces/adcom/pages/68016119)
  5. Submit your CSR request (minimum 2048 bit required, wildcard certificates not allowed)
    1. Most often, you will use "InCommon SSL (SHA-2)" as the Certificate Type
      1. Use "InCommon Multi Domain SSL (SHA-2)" or "InCommon Unified Communications Certificate (SHA-2)" when there is a legitimate requirement to have multiple SSL hostnames for the same IP address and port, this allows subject alternative names (SAN)
      2. Use "InCommon Intranet SSL (SHA-2)" for hosts on the UCI private network (10.*.*.*) that may not conform to public DNS
      3. If you need an EV (extended validation) certificate please let your DRAO know ahead of time
    2. Choose up to 3 year for Certificate Term
    3. Enter CSR for your system and other related data
    4. Optional: Add extra SAN entries for multi domain certificate type
    5. Click Submit and the request will be routed to the DRAO(s) for approval
  6. After all approvals and the certificate is generated and ready to use, a link will be emailed to you for download
    1. Note: It can take up to 24 hours to obtain a certificate from Comodo after it has been approved.
  7. If you need technical support for problems related to the SSL Certificate request or installation please see https://www.incommon.org/cert/support.html

...