Creating Subordinate CA from PKIaaS Root CA

To create subordinate CA from PKIaaS root CA:

  1. Go to (Menu) icon > PKI+ > CA Inventory.
    The CA Inventory page appears.
  2. Click +Create CA on the top-right corner of the page.
    The Create CA page is displayed.
  3. Enter the fields as described in the table.
    Table 1. Field Description for PKIaaS Management page
    Field Description
    Select CA Type
    *CA Name Provide a name for reference. The CA name can contain letters, numbers, hyphen (-), and underscore (_). Character length is between 2 and 64.
    Tier This is a ready-only field.
    Certificate Authority Type Select Subordinate CA.

    On clicking Subordinate CA, you see Root CA field with External and PKIaaS options.

    Root CA This field appears only on selecting Subordinate CA.

    Select PKIaaS if root CA is already in the AppViewX system.

    Note: Subordinate CAs must be activated and will display as status of Create - Approval Pending until they are approved by the active custodians.
    *Issuer Name This field appears only on selecting Subordinate CA as PKIaaS.

    Select an issuer name from the dropdown list.

    *Template This field appears only if AppViewX PKIaaS Native (PQC Ready - AVX CA). Select a template from the dropdown list.
    *Valid for Select the number of years to CA expiry.
    Configure CA Subject Name
    *CA Common Name Enter the root CA subject name.
    *Organization Enter the organization name owning the CA.
    Organization Unit Enter the business unit for CA operations.
    City Enter the city name.
    State Enter the state name.
    Country Enter the country of the organization.
    Configure CA Key Size and Algorithm
    CSR Generation This field appears only on selection of AppViewX PKIaaS Native (PQC Ready - AVX CA). Select AppViewX if you are generating keys in the encrypted AppViewX CA database, else select HSM.
    *Device This field appears only on selection of AppViewX PKIaaS Native (PQC Ready - AVX CA) and when CSR Generation = HSM. Select a configured device from the dropdown list.
    *Key Handler Name This field appears only on selection of AppViewX PKIaaS Native (PQC Ready - AVX CA) and when CSR Generation = HSM. The field is auto-populated on selecting the device.
    *Key Size and Algorithm Select the CA key size and algorithm from the dropdown list.
    Configure CA Artifacts
    Path Length Constraint This is an optional parameter in an issuing CA certificate; it defines the number of sub CA chains created under that specific issuing CA certificate holding the path constraint value.

    This field can have any of these values: 0, 1, 2, 3, or none. For example, if it is set to 2, it means that only two intermediate CAs are allowed between the end-entity certificate and this CA certificate. None indicates unlimited.

    Note: Fields marked with red asterisk (*) symbol are mandatory.
  4. Click Save.
    A window with the summary of values entered appears.
  5. Click Proceed to trigger the approval flow.
    The newly created CA appears in the table with the status as Create - Approval Pending.

    An email from AppViewX is sent to all the active custodians for approving the CA. If you want to abort the action, then click Abort.

    Table 2. Action Status Description and Required Action
    Action Status Status Description Required Action
    Email Verification - Pending Awaiting Approval The custodian's email verification is pending approval and is not active.
    Note: If you want to abort the action, click Abort. Any workflow that is triggered and is in progress is killed from the Request page prior to triggering any further actions.
    The requester receives a notification email. Click the here hyperlink to be directed to the AppViewX login page and approve the request by going to Menu > Requests > All requests.
    Create - Approval Pending Awaiting Approval The custodian has been added but is awaiting approval from active custodians. Active custodians must click the here hyperlink in the email to be redirected to the AppViewX login page.
    Create - Approved Active The custodian has been approved and added successfully. -
    Email Verification - Rejected Inactive The custodian has been rejected. On rejecting a request, a confirmation popup window appears if the requester wants to submit the request. Click OK to resubmit.
  6. Click the (Refresh) icon on the PKIaaS Management page to see the Active status. Click Resubmit if the action fails for any reason.
    Once the PKIaaS subordinate CA is activated, the status changes to Active.
  7. [Optional] Click the Audit Log against the CA to view the audit log details. You can also download the audit log by clicking the Download button on the Audit Log view page. The audit log is exported in the .xls format.
    Note: Once the audit log is fully loaded, the Loading button will turn to View. Refresh the page to see the View button.
  8. [Optional] Click the Approval Status column value link to check the update on approvals.