Certificates

The Certificates view, accessible from the left navigation pane of ActivClient Console, enables you to access and manage the certificates and keys stored on a selected token.

Here, you can view both the free slots and the keys and certificates currently stored in them. The slots are displayed as individual tiles.

The Certificates view with bubbles indicating individual UI components described in this chapter.

Tip! See Actions Available From the Certificates View for more information about the accessible features.

Available Slots

Note: The available slots displayed in the Certificates view depend on your token type. Some of the listed slots may not be available for your specific token.
Note: From a Microsoft Windows perspective, the specific slots do not impact how the operating system interacts with the device, as Windows does not differentiate by slot type. However, PIV-compatible applications will recognize the designated purpose of each slot and use the cryptographic keys stored in them appropriately.

Validity

If a certificate has been generated or imported to your device, the tile displays the expiration date.

  • Yellow text "Expires soon" indicates that the certificate will expire within a month.

  • Red text "Expired" indicates that the key or certificate has already expired.

If one or more certificates expire within a month or have already expired, a yellow warning icon Warning icon image. is displayed on the Certificates navigation pane tab.

The Certificates navigation link with the yellow warning icon displayed.

More details about a certificate's validity can be viewed by clicking on the respective tile.

Actions Available From the Certificates View

Note: The actions available from the Certificates view depend on your token type. Some of the actions and options described may not be available for your specific token.

Generating Keys, CSRs, and Certificates

Viewing, Copying and Exporting Certificate/CSR/Key Details

To view more details about a key, certificate signing request or certificate stored in a slot, click on the slot tile.

Slot tile in the Certificates view

Importing Keys and Certificates

To import keys and certificates to your devices, you have several options to choose from:

Deleting Keys, Certificates, and Certificate Signing Requests

To delete a key, certificate, or a certificate signing request (CSR), click the trash-bin icon Trash Bin Icon in the bottom-right corner of the slot tile in the Certificates view.

A slot tile with the trash bin icon highlighted.

A dialog will open, prompting you to confirm the deletion.

If the slot contains a certificate or a CSR, you can choose to keep the key and delete only the certificate/CSR by checking the checkbox:

The Deleting Slot content dialog with the Delete certificate only checkbox. The Deleting Slot content dialog with the Delete CSR only checkbox.

Uploading Certificates to the Certificate Store

To upload certificates from your token to the Certificate Store:

  1. Go to the Certificates view in the left navigation pane.

  2. If necessary, select the token using the token selector in the right of the title bar.

  3. Click the Upload icon Upload Certificates icon. next to the Certificates view title.

    Certificates view with the Upload to certificate store icon highlighted.

    Certificates from the selected token will be uploaded to the Certificate Store.