On this page

Manage Certificates

Issue Certificate

  1. Log in to your Atlas↗ portal.
  2. Click on Certificates dropdown.

    atlas_manage_cert1.png 
  3. Select Request Certificates from the list.

    atlas_manage_cert2.png
  4. In the next window, choose the product from which you would like to issue a certificate.

    atlas_issue_cert2.png
  5. Select the Identity Profile for your certificate. NOTE: You may also request a new Identity Profile from this screen.

    atlas_issue_cert5.png
  6. Enter a valid Certificate Signing Request (CSR) in the box, then click the Check this CSR button to validate. NOTE: The CSR must match the signature algorithm of your selected product type. If the CSR is validated, a Success message will be displayed.

    atlas_issue_cert6.png
  7. In the same window, the certificate Common Name will automatically populate in the next field. You can make edits to these fields if needed.
     
    IMPORTANT: You must have verified control over the requested domains before requesting a certificate. To validate a domain, refer to Manage Domains↗ guide. 

    atlas_issue_cert11.png
  8. Select Add SANs if you want to add SANs according to the maximum number of SANs as specified by your purchased product e.g., if you have 5 maximum SANs in your product pack, you can add up to 4 additional SANs to your certificate. NOTE: One (1) SAN will be taken as the Certificate Common Name.

    atlas_issue_cert4.png
    1. If you want to add SANs in this request, click Add SANs and enter the SAN name in the box.

      atlas_manage_cert4.png​​
  9. In the Validity Period field, the default maximum validity period is set according to your product type. You can choose a lesser validity period by changing the value in the box.

    atlas_issue_cert3.png
  10. Tick the I have read and agree to the Subscriber Agreement checkbox. This is mandatory to proceed with the certificate request.

    atlas_issue_cert7.png
  11.  In the Certificate Summary screen, review the details and click on the Request this certificate button. 

    atlas_issue_cert9.png
  12.  A pop-up will appear to confirm that you have reviewed the details. Click Request this certificate to complete the request. Otherwise, click Make changes to go back to the fields and update the request.

    atlas_issue_cert10.png
  13.  Your certificate request has been submitted. It may take a few moments for the certificate to display in your Issuance Inventory.

Reissue Certificate

Reissuing a certificate is the process of requesting a copy of an existing certificate that will last for the duration of the original certificate. NOTE: Certificates that are reissued will not count against your current usage quota.

  1. Log in to your Atlas↗ portal.
  2. Click on Certificates dropdown.

    atlas_manage_cert1.png 
  3. Select Issuance Inventory from the list.

    atlas_manage_cert3.png
  4. Select the certificate you want to reissue, then click Reissue.

    atlas_reissue2.png
  5. Enter a new CSR signed with a new public/private key pair from the original certificate, then click Confirm.

    atlas_reissue3.png
  6. You have successfully reissued your certificate. NOTE: The original certificate will remain in the issuance inventory until you revoke the certificate or it naturally expires.

Revoke Certificate

Revoking a certificate distrusts the certificate and any endpoints that have it installed. This is an irreversible action and should only be done when the certificate has been successfully replaced.

  1. Log in to your Atlas↗ portal.
  2. Click on Certificates dropdown.

    atlas_manage_cert1.png 
  3. Select Issuance Inventory from the list.

    atlas_manage_cert3.png
  4. Select the certificate you want to revoke, then click Revoke.

    atlas_revoke1.png
  5. Select the revocation reason, and then click Revoke.
    atlas_revoke2.png
  6. Your certificate has been revoked. NOTE: If you have a SAN license, any SANs attributed to this certificate will be returned to your license pool.

Renew Certificate

Renewing a certificate is the process of requesting a new certificate that retains some of the same information as the original certificate. The process requires submitting a new CSR signed with a new public/private key pair from the original certificate. The resulting certificate will have a public key type and length informed by the CSR, an expiration date equivalent to the maximum allowed by your product, and subjectDN fields that match your Atlas identity profile.

  1. Log in to your Atlas↗ portal.
  2. Click on Certificates dropdown.

    atlas_manage_cert1.png 
  3. Select Issuance Inventory from the list.

    atlas_manage_cert3.png
  4. Select the certificate you want to revoke, then click Renew.

    atlas_renew1.png
  5. Enter a valid CSR for the new certificate. This CSR should be signed with a new public/private key pair than from the original certificate. Click Check this CSR to validate. NOTE: If the CSR is validated, a Success message will be displayed.

    atlas_renew2.png

     

  6. In the same window, review the rest of the fields populated.

  7. Tick the I have read and agree to the Subscriber Agreement checkbox. This is mandatory to proceed with the certificate request.

    atlas_issue_cert7.png
  8.  In the Certificate Summary screen, review the details and click Submit Request

    atlas_renew3.png
  9. A pop-up will appear to confirm that you have reviewed the details. Click Request this certificate to complete the request. Otherwise, click Make changes to go back to the fields and update the request.

    atlas_issue_cert10.png
  10.  Your certificate request has been submitted. It may take a few moments for the certificate to display in your Issuance Inventory.

Frequently Asked Questions

Certificate can be renewed within 30 days before the expiry date or 7 days after the expiry date. 

Yes, if you have multiple product types or identity profiles, you can change the issuing product and the identity profile in your certificate request. However, this might result in you losing some of the options you had available in the original certificate (e.g. SAN count).  

No, you don’t have to, and you're encouraged not to. The CSR must be compatible with your selected product type. 

Yes, while the certificate request form will be pre-filled with the common name and SANs from the original certificate, you may change them prior to finalizing your new certificate request. 

Yes, as long as it is within the maximum allowed validity of the issuing product.  

Yes, as this is a new certificate, you will need to agree to the subscriber agreement before you can renew a certificate.  

If the Renew action button is not displayed, the certificate is not available for renewal (outside of the renewal window) or has expired or been revoked.