Generate a certificate signing request

A web server certificate, such as Certificate Signing Request (CSR) is required for communication between Application server and CipherTrust KMS. You must get the certificate signed and update it on the web interface.

Before you begin 

Create an admin domain

Procedure 

  1. Log on to the Thales CipherTrust Manager as root admin.

  2. To generate the Certificate Signing Request for server, go to CA, select CSR Generator.

    Make sure to select the same domain name (web address) for Common Name and DNS Names (comma-separated) fields.

  3. Select the Algorithm and Size based on the preference of the organization.

  4. Provide the required details and select Generate CSR and Download Private Key.

  5. Copy or download the newly generated private key and save the PrivateKey.pem.

  6. Download CSR and save the CSR.pem.

  7. Get the CSR signed with the same signing authority used for the SSL certificate on the application server.

What to do next 

Upload the certificate