Configuring Policy for Sectigo CA
- Log in to AppViewX application with valid credentials.
-
Click the menu button located in the upper left corner of the screen.
The left navigation pane appears.
-
Click CERT+.
The CERT+ left navigation pane appears.
- Expand GROUPS & POLICIES.
-
Click CA Policy.
The CA Policy home page appears. -
Click + Create on the top-right of the page.
The Create policy page appears.
-
Refer Configuring Policy Details section in admin guide to
configure,
- Policy Details
- Group Selection
- Compliance Check
- To configure a policy with Sectigo details, click Comodo Certificate Manager in the
Certificate Authority pane on the left side of the screen.
The following table provides the field description in the CA Details section:
Name Description *CA Accounts The Sectigo CA accounts configured in the CA settings screen are listed. Select a CA account from the list to create the policy. *Certificate Type The Certificate Types corresponding to the selected CA account are listed. Select one (or) more Certificate Type from the list to create the policy. *Validity Provide the value and press Enter. Enforce Validity period for selected Certificate Type(s). The validity for Sectigo CA can be represented in Day(s). One (or) more than one Validity period can be added. Note: The asterisk (*) symbol indicates a mandatory field. - Select CA accounts and Certificate Type in the CA details section and provide the Validity period.
- Click Add button. The CA details are saved to the table and the confirmation message displays.
- You can use the Edit option in the table to modify the configuration and Remove
option to delete the configuration.

- In the CA details section, select the Bit Length -Key Type, ECDSA curve, and
Hash Function.
The following table provides the description of other fields in the CA Details section:Name Description Purpose *Bit Length - Key Type All the Key Types are listed with corresponding Bit Length. You can select one (or) more than one Bit Length - Key Type(s) from the drop-down. The discovered certificate's Key Type and Bit length will be compared against the selected Bit Length - Key Type(s) to identify if they are complaint with the policy. Selected Bit Length - Key Type(s) is enforced while performing any certificate request operations such as New, Renew, Regenerate. *ECDSA curve When Key Type is selected as EC, ECDSA curve corresponding to selected Key Type is listed.You can select one (or) more than one ECDSA curve from the drop-down. for a certificate. The discovered certificate's Key elliptic curves will be compared against the selected ECDSA curve(s) to identify if they are complaint with the policy. Selected ECDSA curve(s) is enforced while performing certificate request operations such as New, Renew, and Regenerate. We recommend to use P256/ P384/ P521 ECDSA curve while enrolling. *Hash Function Supported Hash Function(s) are listed. You can select one (or) more than one Hash Function(s) from the drop-down. The discovered certificate's Key Hash Algorithm will be compared against the selected Hash Function(s) to identify if they are complaint with the policy. Selected Hash Function(s) is enforced while performing any certificate request operations such as New, Renew, Regenerate. Note: The asterisk (*) symbol indicates a mandatory field. - You can fill the Certificate parameters section based on your organization's policies
and standards.
The following table provides the field description in the Certificate parameters section:Name Description Common Name You can provide the common name. For example, *.domain.com
It helps enforce domains for which a certificate can be requested. Common Name is enforced while performing any certificate request operations such as New, Renew, and Regenerate.
Note: Use Asterisk (*) for the host part of the FQDN to enforce the domain. For example, *.domain.com will only allow users to request certificates with domain.com. Allowed Special Characters: Asterisk (*), Hyphen (-), Period (.)Organization You can provide the organization's name.
The discovered certificate's Subject Organization will be compared against the organization provided in the policy to identify if they are complaints. The organization is enforced while performing any certificate request operations such as New, Renew, and Regenerate.
Organization Unit You can provide an organization unit.
The discovered certificate's Subject Organization Unit will be compared against the organization unit provided in the policy to identify if they are Complaint. Organization Unit is enforced while performing any certificate request operations such as New, Renew, and Regenerate.
Locality You can provide a locality.
The discovered certificate's Locality will be compared against the locality provided in the policy to identify if they are complaints. The locality is enforced while performing any certificate request operations such as New, Renew, and Regenerate.
State You can provide state.
The discovered certificate's State will be compared against the state provided in the policy to identify if they are complaints. The state is enforced while performing any certificate request operations such as New, Renew, and Regenerate.
Country code You can provide a country code.
The discovered certificate's Country code will be compared against the country code provided in the policy to identify if they are complaints. Country code is enforced while performing any certificate request operations such as New, Renew, and Regenerate.
Email You can provide an organization unit mail address.
The discovered certificate's mail address will be compared against the email address provided in the policy to identify if they are complaints. Mail address is enforced while performing any certificate request operations such as New, Renew, and Regenerate.
Subject Alternative Name You can provide the subject alternative name (SAN)
It helps enforce additional domains for which a certificate can be requested. Subject Alternative Name is enforced while performing certificate request operations such as New, Renew, and Regenerate.
Note: Use Asterisk (*) for the host part of the FQDN to enforce the domain. For example, *.domain.com will only allow users to request certificates with domain domain.com. Allowed Special Characters: Asterisk (*), Hyphen (-), Period (.), At (@)Note: The asterisk (*) symbol indicates a mandatory field. - Click the Save CA Details button to save the configuration. A green tick mark will be
displayed in the Certificate Authority pane against the Comodo
Certificate Manager option to indicate the details are successfully
stored.

- Click Create Policy button to create a new policy.
- The policy is created and a confirmation message displays.
.jpg)