Configuring Policy Details

  1. Go to (Menu) > SIGN+ > GROUPS & POLICIES > CA Policy.
    The CA Policy page is displayed.
    Note: SIGN+ is packaged with the following: default policies Default and Certificate-Gateway.
  2. Click + Create from the top-right corner of the page.
    The CA Policy :: Create page is displayed.
  3. Enter/Select the Policy Details.
    Table 1. Field description for Policy Details
    Fields Description
    *Policy name Enter a unique name for the CA policy.
    Note: No special characters other than ., -, and _ are allowed. The policy name should not start with special characters.
    Description Enter a description of the policy.
    *Policy Enforcement Type Select Strict (default) or Suggestive.
    • Strict - Enforces standards defined in the policy where a user cannot modify any parameters.
    • Suggestive - Suggests policy parameters. A user can modify to the suggested values if required.
    Certificate Requests Need Approval When enabled, this feature will enforce peer approval process for any requests made for creation/renewal/regeneration/reissue or revocation of certificates. Peer approval for requests is defined in the approval workflow.
    Enable Access to Private Key When enabled, allows the user to download private keys from the holistic view.
    Enable certificate push-bind access for a read-only user Enabling this feature will allow a user from a read-only user group to perform certificate push, bind, and rollback operations from the holistic view.
    Validate issuer and root certificate for compliance Enabling this option will validate if the issuer and root of a certificate are also compliant with the standards defined in the policy.
    *: Mandatory fields
    Note: You can configure the Policy Details section based on your organization's standards.
  4. From the Group selection, select one or more groups to map to the policy.
  5. From the Compliance Check section, to perform an immediate compliance check, enable Perform Compliance check.
    Note: A scheduled compliance check will run periodically based on the settings defined in the job scheduler.