Configuring a PKI Application Using a Symantec/VeriSign MPKI v7 CA

  1. Go to the Device Policy - Creation page.

  2. In the Action column, next to PKI1, click Add, and then click Configure.

    The Device Policy - Set Application Information page appears:

  1. Friendly Name—Enter a name that easily identifies the type of application you have selected for the device policy.

  2. Provisioning Method —Select Create Credential.

  3. Provider drop-down list—Select Symantec MPKI 7.0 (Verisign) Authority.

  4. Certificate Authority drop-down list—Select the Symantec/VeriSign® CA that issues the certificate for this application.

  5. Important: You cannot escrow PKI keys that have been generated on the device
  6. Template drop-down list—Select the template to use to issue the certificate. The template specifies how the PKI credentials can be used (for example, digital signature).

  7. In the User Name Prefix and User Name Suffix fields, enter a prefix and suffix for the certificate (if applicable).

  8. Revocation Settings — By default, the credentials are revoked for all the listed states of the device. You can clear the check box(es) to indicate any state(s) for which you do not want to revoke the credentials. For example, if you clear the Damaged check box, the credentials in a device in the Damaged state will not be revoked.

  9. Click Submit.

    The Configure PKI1 application page appears:

    If you specified the Symantec policy file when you declared the Symantec CA in ActivID CMS, then the information in the previous illustration appears in the Enrollment Policy Attributes field. This lists the mandatory and optional parameters that must be provided to the Symantec CA in order to issue certificates.

  10. In the Directory Attribute column, enter the name of the LDAP Lightweight Directory Access Protocol attribute that contains the value for each parameter defined in the policy file.

  11. Next to the Challenge Phrase field, select the Random option if you want ActivID CMS to generate random challenge phrases before requesting the certificate.

  12. Note: Select the Key Escrow check box (not shown) if you want the CA to back up the PKI credentials.
  13. Click Set.