Creating Subordinate CA from External Root CA

If you already have a PKI hierarchy and want to create a subordinate CA from AppViewX, you can generate the subordinate CA CSR in AppViewX and have it signed by your external CA.
Note: If you are using the complimentary root CA created in AppViewX, then you can create subordinate CA from external root CA as explained here.

To create subordinate CA from external root CA:

  1. Go to (Menu) icon > PKI+ > CA Inventory.
    The CA Inventory page appears.
  2. Click +Create CA on the top-right corner of the page.
    The Create CA page is displayed.
  3. Enter the fields as described in the table.
    Table 1. Field Description for PKIaaS Management page
    Field Description
    Select CA Type
    *CA Name Provide a name for reference. The CA name can contain letters, numbers, hyphen (-), and underscore (_). Character length is between 2 and 64.
    Tier This is a ready-only field.
    Certificate Authority Type Select Subordinate CA.

    On clicking Subordinate CA, you see Root CA field with External and PKIaaS options.

    Root CA This field appears only on selecting Subordinate CA.

    Select External if root CA is outside of the AppViewX system.

    *Template This field appears only if AppViewX PKIaaS Native (PQC Ready - AVX CA). Select a template from the dropdown list.
    *Valid for Select the number of years to CA expiry.
    Configure CA Subject Name
    *CA Common Name Enter the root CA subject name.
    *Organization Enter the organization name owning the CA.
    Organization Unit Enter the business unit for CA operations.
    City Enter the city name.
    State Enter the state name.
    Country Enter the country of the organization.
    Configure CA Key Size and Algorithm
    CSR Generation This field appears only on selection of AppViewX PKIaaS Native (PQC Ready - AVX CA). Select AppViewX if you are generating keys in the encrypted AppViewX CA database, else select HSM.
    *Device This field appears only on selection of AppViewX PKIaaS Native (PQC Ready - AVX CA) and when CSR Generation = HSM. Select a configured device from the dropdown list.
    *Key Handler Name This field appears only on selection of AppViewX PKIaaS Native (PQC Ready - AVX CA) and when CSR Generation = HSM. The field is auto-populated on selecting the device.
    *Key Size and Algorithm Select the CA key size and algorithm from the dropdown list.
    Configure CA Artifacts
    Path Length Constraint This is an optional parameter in an issuing CA certificate; it defines the number of sub CA chains created under that specific issuing CA certificate holding the path constraint value.

    This field can have any of these values: 0, 1, 2, 3, or none. For example, if it is set to 2, it means that only two intermediate CAs are allowed between the end-entity certificate and this CA certificate. None indicates unlimited.

    Note: Fields marked with red asterisk (*) symbol are mandatory.
  4. Click Save.
    A window with the summary of values entered appears.
  5. Click Proceed to trigger the approval flow.
    The newly created CA appears in the table with the status as Create - Approval Pending. If you want to abort the action, then click Abort.

    An email from AppViewX is sent to all the active custodians for approving the CA.

    Table 2. Action Status Description and Required Action
    Action Status Status Description Required Action
    Email Verification - Pending Awaiting Approval The custodian's email verification is pending approval and is not active.
    Note: If you want to abort the action, click Abort. Any workflow that is triggered and is in progress is killed from the Request page prior to triggering any further actions.
    The requester receives a notification email. Click the here hyperlink to be directed to the AppViewX login page and approve the request by going to Menu > Requests > All requests.
    Create - Approval Pending Awaiting Approval The custodian has been added but is awaiting approval from active custodians. Active custodians must click the here hyperlink in the email to be redirected to the AppViewX login page.
    Create - Approved Active The custodian has been approved and added successfully. -
    Email Verification - Rejected Inactive The custodian has been rejected. On rejecting a request, a confirmation popup window appears if the requester wants to submit the request. Click OK to resubmit.
  6. Click the (Refresh) icon.
  7. Click Activate. Until the signed certificate is uploaded, the status of the external subordinate CA remains as Pending Signed Certificate.
    The Certificate Authority Activation window appears.
  8. Click Download CSR.
  9. Once the CSR is downloaded, sign with valid root CA and click Upload.
    Note: Copy and paste or upload the complete certificate chain, ordered from leaf to root, starting with the subordinate certificate authority being activated.
    Once the external subordinate CA is activated, the status changes to Active. Click Resubmit if the action fails for any reason.
  10. [Optional] Click the Audit Log against the CA to view the audit log details. You can also download the audit log by clicking the Download button on the Audit Log view page. The audit log is exported in the .xls format.
    Note: Once the audit log is fully loaded, the Loading button will turn to View. Refresh the page to see the View button.
  11. [Optional] Click the Approval Status column value link to check the update on approvals.