Register a User for PKI Authentication
-
Follow the steps in Search for Users to search for the user.
-
In the user’s Details page, select the Wallet tab.
-
Click Register PKI.
-
From the drop-down list, select the Authentication Policy and click Next.
Note:- The available authentication policies depend on the user's User Type.
- For the PKI Certificate Matching authentication policy, you are not prompted to bind a certificate or device to the user. Click Next and then Close to complete the registration.
-
Select the assignment option for the certificate:
Import the user's certificate and assign it as a new device
Select the option Import Certificate and click Next.
Click Browse.
From the File Upload page, select the .cer file, and then click Open.
Click Next.
From the Device Type drop-down list, select PKI Container on Server.
From the Credential Profile (the Credential Type) drop-down list, select:
- PKI Challenge Response v1 for direct PKI authentication
- PKI Certificate Check v1 for indirect PKI authentication.
Note: For information about direct and indirect PKI authentication, see .Optionally, enter a Serial Number.
The Serial Number can be used if you want to override the serial number of the certificate you are importing with another serial number. For example:
- For a device-based PKI credential, you could enter the smart card serial number.
- For a browser-based PKI credential, you could enter the unique serial number of the private key (.pfx or .p12).
Optionally, enter a positive integer as an Issue Number to identify the user's credential.
Note: The number is not checked during authentication. It is only used as part of your device identification scheme.Select the required Status from the drop-down list.
- Optionally, enter a Device Friendly Name.
Assign a previously imported certificate credentialPrerequisites: You have imported the user's PKI certificate and have the serial number available.Select the Select a device for assignment option.
Enter the Device Serial Number for the imported certificate and click Next.
Verify the certificate details are correct.
- Optionally, enter a Device Friendly Name.
- Click Next.
Note: If the device is unknown or has already been assigned to another user, then the following warning appears. - Configure the Policy Settings, and click Save to complete the registration.
- Click Close.
The user’s Wallet is updated with the new PKI credential.