[{"data":1,"prerenderedAt":17149},["ShallowReactive",2],{"\u002Fzh\u002Fblogs\u002Fpki-cert-service-guide":3,"content-doc-\u002Fen\u002Fblogs\u002Fpki-cert-service-guide":9090,"surround-\u002Fen\u002Fblogs\u002Fpki-cert-service-guide":17147},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"date":10,"category":11,"archives":12,"author":13,"body":17,"_type":9082,"_id":9083,"_source":9084,"_file":9085,"_stem":9086,"_extension":9087,"plainText":9088,"authorNames":9089},"\u002Fzh\u002Fblogs\u002Fpki-cert-service-guide","blogs",false,"","PKI 实践指南：构建完整的证书服务系统","本文是一份基于  的证书服务实践教程，目标是在 Demo 环境中快速跑通 CA\u002FRA 全流程，包括证书模板创建、终端实体模板配置、审批流程启用，以及 RA 端的终端证书申请与下载。教程聚焦“能跑起来”，适合实验、PoC 或内部演示，不涉及生产环境的安全加固与合规细节。","2025\u002F08\u002F11","case","2025-08",[14],{"name":15,"description":16},"沈威","openubmc 社区开发者对BMC与开源固件有长期兴趣，活跃于openubmc社区，热衷于探索和交流新特性。",{"type":18,"children":19,"toc":8986},"root",[20,28,35,49,64,68,74,97,100,106,119,122,128,149,156,169,176,181,238,243,286,292,368,381,386,427,432,475,481,530,539,545,554,629,652,1084,1092,1133,1141,1147,1155,1179,1185,1201,1207,1229,1590,1619,1627,1633,1660,1685,1696,1715,1733,1736,1742,1748,1774,1780,1786,1814,1820,1858,1864,1977,1983,2039,2052,2058,2174,2179,2185,2191,2380,2383,2389,2535,2538,2544,2797,2800,2806,3107,3110,3116,3226,3229,3235,3342,3345,3351,3409,3412,3418,3429,3437,3442,3635,3643,3648,3692,3697,3709,3715,3720,3857,3860,3865,3966,3969,3974,4165,4168,4173,4381,4384,4390,4474,4477,4483,4495,4578,4581,4587,4597,4602,4661,4666,4669,4675,4681,4882,4888,5101,5107,5184,5190,5367,5373,5403,5409,5426,5451,5454,5460,5465,5468,5474,5672,5675,5681,5885,5895,5898,5904,5982,5985,5991,6142,6148,6598,6604,6682,6688,6765,6768,6774,6820,6823,6829,6875,6878,6884,6945,6948,6954,7039,7042,7048,7120,7123,7128,7136,7139,7145,7151,7159,7167,7202,7208,7311,7317,7441,7447,7455,7463,7481,7489,7497,7515,7521,7547,7553,7622,7625,7631,7646,7652,7659,7667,7699,7705,7739,7747,7845,7853,7929,7937,7980,7991,8005,8013,8136,8151,8161,8170,8219,8229,8245,8272,8278,8406,8412,8484,8490,8620,8626,8685,8688,8694,8724,8730,8757,8763,8770,8778,8847,8853,8867,8900,8906,8926,8932,8980],{"type":21,"tag":22,"props":23,"children":25},"element","h1",{"id":24},"pki-实践指南构建完整的证书服务系统",[26],{"type":27,"value":8},"text",{"type":21,"tag":29,"props":30,"children":32},"h2",{"id":31},"_1-引言",[33],{"type":27,"value":34},"1. 引言",{"type":21,"tag":36,"props":37,"children":38},"p",{},[39,41,47],{"type":27,"value":40},"本文是一份基于 ",{"type":21,"tag":42,"props":43,"children":44},"strong",{},[45],{"type":27,"value":46},"EJBCA",{"type":27,"value":48}," 的证书服务实践教程，目标是在 Demo 环境中快速跑通 CA\u002FRA 全流程，包括证书模板创建、终端实体模板配置、审批流程启用，以及 RA 端的终端证书申请与下载。教程聚焦“能跑起来”，适合实验、PoC 或内部演示，不涉及生产环境的安全加固与合规细节。",{"type":21,"tag":50,"props":51,"children":52},"ul",{},[53],{"type":21,"tag":54,"props":55,"children":56},"li",{},[57,62],{"type":21,"tag":42,"props":58,"children":59},{},[60],{"type":27,"value":61},"主要收获",{"type":27,"value":63},"：掌握 EJBCA 的核心操作路径，完成从模板配置到证书签发的全过程",{"type":21,"tag":65,"props":66,"children":67},"hr",{},[],{"type":21,"tag":29,"props":69,"children":71},{"id":70},"_2-方案架构与术语",[72],{"type":27,"value":73},"2. 方案架构与术语",{"type":21,"tag":50,"props":75,"children":76},{},[77,87],{"type":21,"tag":54,"props":78,"children":79},{},[80,85],{"type":21,"tag":42,"props":81,"children":82},{},[83],{"type":27,"value":84},"RA",{"type":27,"value":86},"：负责终端实体注册与身份审核。",{"type":21,"tag":54,"props":88,"children":89},{},[90,95],{"type":21,"tag":42,"props":91,"children":92},{},[93],{"type":27,"value":94},"证书模板（Certificate Profile）",{"type":27,"value":96},"：预设密钥用法、SAN、有效期等。",{"type":21,"tag":65,"props":98,"children":99},{},[],{"type":21,"tag":29,"props":101,"children":103},{"id":102},"_3-实验环境与前置条件",[104],{"type":27,"value":105},"3. 实验环境与前置条件",{"type":21,"tag":50,"props":107,"children":108},{},[109,114],{"type":21,"tag":54,"props":110,"children":111},{},[112],{"type":27,"value":113},"操作系统：Ubuntu 20.04 Server（离线安装）",{"type":21,"tag":54,"props":115,"children":116},{},[117],{"type":27,"value":118},"前置软件：Docker ，docker-compose (apt 包)",{"type":21,"tag":65,"props":120,"children":121},{},[],{"type":21,"tag":29,"props":123,"children":125},{"id":124},"_4-ejbca-docker-部署与持久化",[126],{"type":27,"value":127},"4. EJBCA Docker 部署与持久化",{"type":21,"tag":36,"props":129,"children":130},{},[131,133,138,140,147],{"type":27,"value":132},"本文将详细介绍如何在 Docker 中部署 ",{"type":21,"tag":42,"props":134,"children":135},{},[136],{"type":27,"value":137},"EJBCA 证书服务",{"type":27,"value":139},"，并确保其数据持久化存储在独立数据盘上，避免因容器或虚拟机重启导致数据丢失。内容包括使用内部数据库（默认 H2）的持久化配置、",{"type":21,"tag":141,"props":142,"children":144},"code",{"className":143},[],[145],{"type":27,"value":146},"docker-compose",{"type":27,"value":148}," 方式运行容器、开放远程访问所需的配置。",{"type":21,"tag":150,"props":151,"children":153},"h3",{"id":152},"_41-环境准备与代理配置",[154],{"type":27,"value":155},"4.1 环境准备与代理配置",{"type":21,"tag":36,"props":157,"children":158},{},[159,161,167],{"type":27,"value":160},"由于部分 EJBCA Docker 镜像（如 ",{"type":21,"tag":141,"props":162,"children":164},{"className":163},[],[165],{"type":27,"value":166},"keyfactor\u002Fejbca-ce",{"type":27,"value":168}," ）需要从公网拉取，为确保环境可用，请先配置 Docker Daemon 的 HTTP\u002FHTTPS 代理。",{"type":21,"tag":170,"props":171,"children":173},"h4",{"id":172},"配置-systemd-代理",[174],{"type":27,"value":175},"配置 systemd 代理",{"type":21,"tag":36,"props":177,"children":178},{},[179],{"type":27,"value":180},"Docker Daemon 运行在 systemd 管理下，需添加配置以继承系统代理。",{"type":21,"tag":182,"props":183,"children":187},"pre",{"code":184,"language":185,"meta":7,"className":186,"style":7},"sudo mkdir -p \u002Fetc\u002Fsystemd\u002Fsystem\u002Fdocker.service.d\nsudo nano \u002Fetc\u002Fsystemd\u002Fsystem\u002Fdocker.service.d\u002Fhttp-proxy.conf\n","bash","language-bash shiki shiki-themes github-light github-dark monokai",[188],{"type":21,"tag":141,"props":189,"children":190},{"__ignoreMap":7},[191,220],{"type":21,"tag":192,"props":193,"children":196},"span",{"class":194,"line":195},"line",1,[197,203,209,215],{"type":21,"tag":192,"props":198,"children":200},{"style":199},"--shiki-default:#6F42C1;--shiki-dark:#B392F0;--shiki-sepia:#A6E22E",[201],{"type":27,"value":202},"sudo",{"type":21,"tag":192,"props":204,"children":206},{"style":205},"--shiki-default:#032F62;--shiki-dark:#9ECBFF;--shiki-sepia:#E6DB74",[207],{"type":27,"value":208}," mkdir",{"type":21,"tag":192,"props":210,"children":212},{"style":211},"--shiki-default:#005CC5;--shiki-dark:#79B8FF;--shiki-sepia:#AE81FF",[213],{"type":27,"value":214}," -p",{"type":21,"tag":192,"props":216,"children":217},{"style":205},[218],{"type":27,"value":219}," \u002Fetc\u002Fsystemd\u002Fsystem\u002Fdocker.service.d\n",{"type":21,"tag":192,"props":221,"children":223},{"class":194,"line":222},2,[224,228,233],{"type":21,"tag":192,"props":225,"children":226},{"style":199},[227],{"type":27,"value":202},{"type":21,"tag":192,"props":229,"children":230},{"style":205},[231],{"type":27,"value":232}," nano",{"type":21,"tag":192,"props":234,"children":235},{"style":205},[236],{"type":27,"value":237}," \u002Fetc\u002Fsystemd\u002Fsystem\u002Fdocker.service.d\u002Fhttp-proxy.conf\n",{"type":21,"tag":36,"props":239,"children":240},{},[241],{"type":27,"value":242},"内容如下：",{"type":21,"tag":182,"props":244,"children":248},{"code":245,"language":246,"meta":7,"className":247,"style":7},"[Service]\nEnvironment=\"HTTP_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\nEnvironment=\"HTTPS_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\nEnvironment=\"NO_PROXY=127.0.0.1,localhost,192.168.13.119\"\u002F\u002Fip需要改成自己虚拟机主机ip\n","ini","language-ini shiki shiki-themes github-light github-dark monokai",[249],{"type":21,"tag":141,"props":250,"children":251},{"__ignoreMap":7},[252,260,268,277],{"type":21,"tag":192,"props":253,"children":254},{"class":194,"line":195},[255],{"type":21,"tag":192,"props":256,"children":257},{},[258],{"type":27,"value":259},"[Service]\n",{"type":21,"tag":192,"props":261,"children":262},{"class":194,"line":222},[263],{"type":21,"tag":192,"props":264,"children":265},{},[266],{"type":27,"value":267},"Environment=\"HTTP_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\n",{"type":21,"tag":192,"props":269,"children":271},{"class":194,"line":270},3,[272],{"type":21,"tag":192,"props":273,"children":274},{},[275],{"type":27,"value":276},"Environment=\"HTTPS_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\n",{"type":21,"tag":192,"props":278,"children":280},{"class":194,"line":279},4,[281],{"type":21,"tag":192,"props":282,"children":283},{},[284],{"type":27,"value":285},"Environment=\"NO_PROXY=127.0.0.1,localhost,192.168.13.119\"\u002F\u002Fip需要改成自己虚拟机主机ip\n",{"type":21,"tag":170,"props":287,"children":289},{"id":288},"重新加载并重启-docker",[290],{"type":27,"value":291},"重新加载并重启 Docker",{"type":21,"tag":182,"props":293,"children":295},{"code":294,"language":185,"meta":7,"className":186,"style":7},"sudo systemctl daemon-reload\nsudo systemctl restart docker\nsudo systemctl status docker --no-pager -l\n",[296],{"type":21,"tag":141,"props":297,"children":298},{"__ignoreMap":7},[299,316,337],{"type":21,"tag":192,"props":300,"children":301},{"class":194,"line":195},[302,306,311],{"type":21,"tag":192,"props":303,"children":304},{"style":199},[305],{"type":27,"value":202},{"type":21,"tag":192,"props":307,"children":308},{"style":205},[309],{"type":27,"value":310}," systemctl",{"type":21,"tag":192,"props":312,"children":313},{"style":205},[314],{"type":27,"value":315}," daemon-reload\n",{"type":21,"tag":192,"props":317,"children":318},{"class":194,"line":222},[319,323,327,332],{"type":21,"tag":192,"props":320,"children":321},{"style":199},[322],{"type":27,"value":202},{"type":21,"tag":192,"props":324,"children":325},{"style":205},[326],{"type":27,"value":310},{"type":21,"tag":192,"props":328,"children":329},{"style":205},[330],{"type":27,"value":331}," restart",{"type":21,"tag":192,"props":333,"children":334},{"style":205},[335],{"type":27,"value":336}," docker\n",{"type":21,"tag":192,"props":338,"children":339},{"class":194,"line":270},[340,344,348,353,358,363],{"type":21,"tag":192,"props":341,"children":342},{"style":199},[343],{"type":27,"value":202},{"type":21,"tag":192,"props":345,"children":346},{"style":205},[347],{"type":27,"value":310},{"type":21,"tag":192,"props":349,"children":350},{"style":205},[351],{"type":27,"value":352}," status",{"type":21,"tag":192,"props":354,"children":355},{"style":205},[356],{"type":27,"value":357}," docker",{"type":21,"tag":192,"props":359,"children":360},{"style":211},[361],{"type":27,"value":362}," --no-pager",{"type":21,"tag":192,"props":364,"children":365},{"style":211},[366],{"type":27,"value":367}," -l\n",{"type":21,"tag":36,"props":369,"children":370},{},[371,373,379],{"type":27,"value":372},"若输出中含有 ",{"type":21,"tag":141,"props":374,"children":376},{"className":375},[],[377],{"type":27,"value":378},"Active: active (running)",{"type":27,"value":380}," 即表示代理配置生效。",{"type":21,"tag":170,"props":382,"children":384},{"id":383},"验证代理是否生效",[385],{"type":27,"value":383},{"type":21,"tag":182,"props":387,"children":389},{"code":388,"language":185,"meta":7,"className":186,"style":7},"docker info | grep -i proxy\n",[390],{"type":21,"tag":141,"props":391,"children":392},{"__ignoreMap":7},[393],{"type":21,"tag":192,"props":394,"children":395},{"class":194,"line":195},[396,401,406,412,417,422],{"type":21,"tag":192,"props":397,"children":398},{"style":199},[399],{"type":27,"value":400},"docker",{"type":21,"tag":192,"props":402,"children":403},{"style":205},[404],{"type":27,"value":405}," info",{"type":21,"tag":192,"props":407,"children":409},{"style":408},"--shiki-default:#D73A49;--shiki-dark:#F97583;--shiki-sepia:#F92672",[410],{"type":27,"value":411}," |",{"type":21,"tag":192,"props":413,"children":414},{"style":199},[415],{"type":27,"value":416}," grep",{"type":21,"tag":192,"props":418,"children":419},{"style":211},[420],{"type":27,"value":421}," -i",{"type":21,"tag":192,"props":423,"children":424},{"style":205},[425],{"type":27,"value":426}," proxy\n",{"type":21,"tag":36,"props":428,"children":429},{},[430],{"type":27,"value":431},"出现如下输出说明代理生效：",{"type":21,"tag":182,"props":433,"children":437},{"code":434,"language":435,"meta":7,"className":436,"style":7},"HTTP Proxy: http:\u002F\u002F192.168.xxx.xxx:7890\nHTTPS Proxy: http:\u002F\u002F192.168.xxx.xxx:7890\n","shell","language-shell shiki shiki-themes github-light github-dark monokai",[438],{"type":21,"tag":141,"props":439,"children":440},{"__ignoreMap":7},[441,459],{"type":21,"tag":192,"props":442,"children":443},{"class":194,"line":195},[444,449,454],{"type":21,"tag":192,"props":445,"children":446},{"style":199},[447],{"type":27,"value":448},"HTTP",{"type":21,"tag":192,"props":450,"children":451},{"style":205},[452],{"type":27,"value":453}," Proxy:",{"type":21,"tag":192,"props":455,"children":456},{"style":205},[457],{"type":27,"value":458}," http:\u002F\u002F192.168.xxx.xxx:7890\n",{"type":21,"tag":192,"props":460,"children":461},{"class":194,"line":222},[462,467,471],{"type":21,"tag":192,"props":463,"children":464},{"style":199},[465],{"type":27,"value":466},"HTTPS",{"type":21,"tag":192,"props":468,"children":469},{"style":205},[470],{"type":27,"value":453},{"type":21,"tag":192,"props":472,"children":473},{"style":205},[474],{"type":27,"value":458},{"type":21,"tag":150,"props":476,"children":478},{"id":477},"_42-数据持久化配置",[479],{"type":27,"value":480},"4.2 数据持久化配置",{"type":21,"tag":50,"props":482,"children":483},{},[484,495,506,519],{"type":21,"tag":54,"props":485,"children":486},{},[487,489],{"type":27,"value":488},"使用文件方式保存 H2 数据库：将数据库配置为 ",{"type":21,"tag":141,"props":490,"children":492},{"className":491},[],[493],{"type":27,"value":494},"jdbc:h2:\u002Fmnt\u002Fpersistent\u002Fejbcadb;DB_CLOSE_DELAY=-1",{"type":21,"tag":54,"props":496,"children":497},{},[498,500],{"type":27,"value":499},"宿主机挂载路径：",{"type":21,"tag":141,"props":501,"children":503},{"className":502},[],[504],{"type":27,"value":505},"\u002Fopt\u002Fejbca-data:\u002Fmnt\u002Fpersistent",{"type":21,"tag":54,"props":507,"children":508},{},[509,511,517],{"type":27,"value":510},"避免使用 ",{"type":21,"tag":141,"props":512,"children":514},{"className":513},[],[515],{"type":27,"value":516},"--rm",{"type":27,"value":518}," 启动容器",{"type":21,"tag":54,"props":520,"children":521},{},[522,524],{"type":27,"value":523},"设置宿主机权限：",{"type":21,"tag":141,"props":525,"children":527},{"className":526},[],[528],{"type":27,"value":529},"chown -R 10001:10001 \u002Fopt\u002Fejbca-data",{"type":21,"tag":531,"props":532,"children":533},"blockquote",{},[534],{"type":21,"tag":36,"props":535,"children":536},{},[537],{"type":27,"value":538},"📌 提示：正式环境建议切换到 PostgreSQL \u002F MySQL 等外部数据库，提升可靠性与容灾能力。",{"type":21,"tag":150,"props":540,"children":542},{"id":541},"_43-使用-docker-compose-部署",[543],{"type":27,"value":544},"4.3 使用 Docker Compose 部署",{"type":21,"tag":546,"props":547,"children":548},"ol",{},[549],{"type":21,"tag":54,"props":550,"children":551},{},[552],{"type":27,"value":553},"创建目录结构：",{"type":21,"tag":182,"props":555,"children":557},{"code":556,"language":185,"meta":7,"className":186,"style":7},"mkdir -p \u002Fopt\u002Fejbca-compose\ncd \u002Fopt\u002Fejbca-compose\nmkdir -p \u002Fopt\u002Fejbca-data\nchown -R 10001:10001 \u002Fopt\u002Fejbca-data\n",[558],{"type":21,"tag":141,"props":559,"children":560},{"__ignoreMap":7},[561,578,591,607],{"type":21,"tag":192,"props":562,"children":563},{"class":194,"line":195},[564,569,573],{"type":21,"tag":192,"props":565,"children":566},{"style":199},[567],{"type":27,"value":568},"mkdir",{"type":21,"tag":192,"props":570,"children":571},{"style":211},[572],{"type":27,"value":214},{"type":21,"tag":192,"props":574,"children":575},{"style":205},[576],{"type":27,"value":577}," \u002Fopt\u002Fejbca-compose\n",{"type":21,"tag":192,"props":579,"children":580},{"class":194,"line":222},[581,587],{"type":21,"tag":192,"props":582,"children":584},{"style":583},"--shiki-default:#005CC5;--shiki-dark:#79B8FF;--shiki-sepia:#66D9EF",[585],{"type":27,"value":586},"cd",{"type":21,"tag":192,"props":588,"children":589},{"style":205},[590],{"type":27,"value":577},{"type":21,"tag":192,"props":592,"children":593},{"class":194,"line":270},[594,598,602],{"type":21,"tag":192,"props":595,"children":596},{"style":199},[597],{"type":27,"value":568},{"type":21,"tag":192,"props":599,"children":600},{"style":211},[601],{"type":27,"value":214},{"type":21,"tag":192,"props":603,"children":604},{"style":205},[605],{"type":27,"value":606}," \u002Fopt\u002Fejbca-data\n",{"type":21,"tag":192,"props":608,"children":609},{"class":194,"line":279},[610,615,620,625],{"type":21,"tag":192,"props":611,"children":612},{"style":199},[613],{"type":27,"value":614},"chown",{"type":21,"tag":192,"props":616,"children":617},{"style":211},[618],{"type":27,"value":619}," -R",{"type":21,"tag":192,"props":621,"children":622},{"style":205},[623],{"type":27,"value":624}," 10001:10001",{"type":21,"tag":192,"props":626,"children":627},{"style":205},[628],{"type":27,"value":606},{"type":21,"tag":546,"props":630,"children":631},{},[632],{"type":21,"tag":54,"props":633,"children":634},{},[635,637,643,645,650],{"type":27,"value":636},"当前目录下创建",{"type":21,"tag":141,"props":638,"children":640},{"className":639},[],[641],{"type":27,"value":642},"docker-compose.yml",{"type":27,"value":644},"，编写 ",{"type":21,"tag":141,"props":646,"children":648},{"className":647},[],[649],{"type":27,"value":642},{"type":27,"value":651},"：",{"type":21,"tag":182,"props":653,"children":657},{"code":654,"language":655,"meta":7,"className":656,"style":7},"version: \"3.3\" # 使用 Docker Compose 文件格式版本 3.3\n\nservices:\n  ejbca: # 定义名为 ejbca 的服务\n    image: keyfactor\u002Fejbca-ce:latest # 使用 Keyfactor 提供的 EJBCA 社区版镜像，使用最新版本\n    container_name: ejbca # 容器名称为 ejbca\n    hostname: myejbca.test.local # 容器内部主机名，影响证书中的 CN 等字段\n\n    environment: # 设置环境变量配置 EJBCA 的启动行为\n      - DATABASE_JDBC_URL=jdbc:h2:\u002Fmnt\u002Fpersistent\u002Fejbcadb;DB_CLOSE_DELAY=-1 # 使用嵌入式 H2 数据库，数据保存在挂载目录下\n      - TLS_SETUP_ENABLED=true # 启用自动 TLS 设置（用于 HTTPS 接入）\n      - SMTP_DESTINATION=192.168.xx.xx # 设置 SMTP 邮件服务器地址（用于发送通知邮件）\n      - SMTP_DESTINATION_PORT=25 # SMTP 服务端口，默认 25（未启用加密）\n      - SMTP_FROM=ejbca@example.local # 设置邮件发送的发件人地址\n      - SMTP_TLS_ENABLED=false # 不启用 SMTP 的 STARTTLS\n      - SMTP_SSL_ENABLED=false # 不启用 SMTP 的 SSL\u002FTLS 加密\n\n    ports: # 映射容器端口到宿主机\n      - \"80:8080\" # 宿主机 80 端口映射到容器的 8080（HTTP）\n      - \"443:8443\" # 宿主机 443 端口映射到容器的 8443（HTTPS）\n\n    volumes: # 数据卷挂载，将容器中的目录映射到宿主机，以持久化数据\n      - \u002Fopt\u002Fejbca-data:\u002Fmnt\u002Fpersistent # 将宿主机的 \u002Fopt\u002Fejbca-data 目录挂载到容器中，持久化数据库等数据\n\n    restart: unless-stopped # 如果容器异常退出则自动重启，除非人为停止\n","yaml","language-yaml shiki shiki-themes github-light github-dark monokai",[658],{"type":21,"tag":141,"props":659,"children":660},{"__ignoreMap":7},[661,687,696,709,726,749,772,795,803,821,840,858,876,894,912,930,948,956,974,992,1010,1018,1036,1053,1061],{"type":21,"tag":192,"props":662,"children":663},{"class":194,"line":195},[664,670,676,681],{"type":21,"tag":192,"props":665,"children":667},{"style":666},"--shiki-default:#22863A;--shiki-dark:#85E89D;--shiki-sepia:#F92672",[668],{"type":27,"value":669},"version",{"type":21,"tag":192,"props":671,"children":673},{"style":672},"--shiki-default:#24292E;--shiki-dark:#E1E4E8;--shiki-sepia:#F8F8F2",[674],{"type":27,"value":675},": ",{"type":21,"tag":192,"props":677,"children":678},{"style":205},[679],{"type":27,"value":680},"\"3.3\"",{"type":21,"tag":192,"props":682,"children":684},{"style":683},"--shiki-default:#6A737D;--shiki-dark:#6A737D;--shiki-sepia:#88846F",[685],{"type":27,"value":686}," # 使用 Docker Compose 文件格式版本 3.3\n",{"type":21,"tag":192,"props":688,"children":689},{"class":194,"line":222},[690],{"type":21,"tag":192,"props":691,"children":693},{"emptyLinePlaceholder":692},true,[694],{"type":27,"value":695},"\n",{"type":21,"tag":192,"props":697,"children":698},{"class":194,"line":270},[699,704],{"type":21,"tag":192,"props":700,"children":701},{"style":666},[702],{"type":27,"value":703},"services",{"type":21,"tag":192,"props":705,"children":706},{"style":672},[707],{"type":27,"value":708},":\n",{"type":21,"tag":192,"props":710,"children":711},{"class":194,"line":279},[712,717,721],{"type":21,"tag":192,"props":713,"children":714},{"style":666},[715],{"type":27,"value":716},"  ejbca",{"type":21,"tag":192,"props":718,"children":719},{"style":672},[720],{"type":27,"value":675},{"type":21,"tag":192,"props":722,"children":723},{"style":683},[724],{"type":27,"value":725},"# 定义名为 ejbca 的服务\n",{"type":21,"tag":192,"props":727,"children":729},{"class":194,"line":728},5,[730,735,739,744],{"type":21,"tag":192,"props":731,"children":732},{"style":666},[733],{"type":27,"value":734},"    image",{"type":21,"tag":192,"props":736,"children":737},{"style":672},[738],{"type":27,"value":675},{"type":21,"tag":192,"props":740,"children":741},{"style":205},[742],{"type":27,"value":743},"keyfactor\u002Fejbca-ce:latest",{"type":21,"tag":192,"props":745,"children":746},{"style":683},[747],{"type":27,"value":748}," # 使用 Keyfactor 提供的 EJBCA 社区版镜像，使用最新版本\n",{"type":21,"tag":192,"props":750,"children":752},{"class":194,"line":751},6,[753,758,762,767],{"type":21,"tag":192,"props":754,"children":755},{"style":666},[756],{"type":27,"value":757},"    container_name",{"type":21,"tag":192,"props":759,"children":760},{"style":672},[761],{"type":27,"value":675},{"type":21,"tag":192,"props":763,"children":764},{"style":205},[765],{"type":27,"value":766},"ejbca",{"type":21,"tag":192,"props":768,"children":769},{"style":683},[770],{"type":27,"value":771}," # 容器名称为 ejbca\n",{"type":21,"tag":192,"props":773,"children":775},{"class":194,"line":774},7,[776,781,785,790],{"type":21,"tag":192,"props":777,"children":778},{"style":666},[779],{"type":27,"value":780},"    hostname",{"type":21,"tag":192,"props":782,"children":783},{"style":672},[784],{"type":27,"value":675},{"type":21,"tag":192,"props":786,"children":787},{"style":205},[788],{"type":27,"value":789},"myejbca.test.local",{"type":21,"tag":192,"props":791,"children":792},{"style":683},[793],{"type":27,"value":794}," # 容器内部主机名，影响证书中的 CN 等字段\n",{"type":21,"tag":192,"props":796,"children":798},{"class":194,"line":797},8,[799],{"type":21,"tag":192,"props":800,"children":801},{"emptyLinePlaceholder":692},[802],{"type":27,"value":695},{"type":21,"tag":192,"props":804,"children":806},{"class":194,"line":805},9,[807,812,816],{"type":21,"tag":192,"props":808,"children":809},{"style":666},[810],{"type":27,"value":811},"    environment",{"type":21,"tag":192,"props":813,"children":814},{"style":672},[815],{"type":27,"value":675},{"type":21,"tag":192,"props":817,"children":818},{"style":683},[819],{"type":27,"value":820},"# 设置环境变量配置 EJBCA 的启动行为\n",{"type":21,"tag":192,"props":822,"children":824},{"class":194,"line":823},10,[825,830,835],{"type":21,"tag":192,"props":826,"children":827},{"style":672},[828],{"type":27,"value":829},"      - ",{"type":21,"tag":192,"props":831,"children":832},{"style":205},[833],{"type":27,"value":834},"DATABASE_JDBC_URL=jdbc:h2:\u002Fmnt\u002Fpersistent\u002Fejbcadb;DB_CLOSE_DELAY=-1",{"type":21,"tag":192,"props":836,"children":837},{"style":683},[838],{"type":27,"value":839}," # 使用嵌入式 H2 数据库，数据保存在挂载目录下\n",{"type":21,"tag":192,"props":841,"children":843},{"class":194,"line":842},11,[844,848,853],{"type":21,"tag":192,"props":845,"children":846},{"style":672},[847],{"type":27,"value":829},{"type":21,"tag":192,"props":849,"children":850},{"style":205},[851],{"type":27,"value":852},"TLS_SETUP_ENABLED=true",{"type":21,"tag":192,"props":854,"children":855},{"style":683},[856],{"type":27,"value":857}," # 启用自动 TLS 设置（用于 HTTPS 接入）\n",{"type":21,"tag":192,"props":859,"children":861},{"class":194,"line":860},12,[862,866,871],{"type":21,"tag":192,"props":863,"children":864},{"style":672},[865],{"type":27,"value":829},{"type":21,"tag":192,"props":867,"children":868},{"style":205},[869],{"type":27,"value":870},"SMTP_DESTINATION=192.168.xx.xx",{"type":21,"tag":192,"props":872,"children":873},{"style":683},[874],{"type":27,"value":875}," # 设置 SMTP 邮件服务器地址（用于发送通知邮件）\n",{"type":21,"tag":192,"props":877,"children":879},{"class":194,"line":878},13,[880,884,889],{"type":21,"tag":192,"props":881,"children":882},{"style":672},[883],{"type":27,"value":829},{"type":21,"tag":192,"props":885,"children":886},{"style":205},[887],{"type":27,"value":888},"SMTP_DESTINATION_PORT=25",{"type":21,"tag":192,"props":890,"children":891},{"style":683},[892],{"type":27,"value":893}," # SMTP 服务端口，默认 25（未启用加密）\n",{"type":21,"tag":192,"props":895,"children":897},{"class":194,"line":896},14,[898,902,907],{"type":21,"tag":192,"props":899,"children":900},{"style":672},[901],{"type":27,"value":829},{"type":21,"tag":192,"props":903,"children":904},{"style":205},[905],{"type":27,"value":906},"SMTP_FROM=ejbca@example.local",{"type":21,"tag":192,"props":908,"children":909},{"style":683},[910],{"type":27,"value":911}," # 设置邮件发送的发件人地址\n",{"type":21,"tag":192,"props":913,"children":915},{"class":194,"line":914},15,[916,920,925],{"type":21,"tag":192,"props":917,"children":918},{"style":672},[919],{"type":27,"value":829},{"type":21,"tag":192,"props":921,"children":922},{"style":205},[923],{"type":27,"value":924},"SMTP_TLS_ENABLED=false",{"type":21,"tag":192,"props":926,"children":927},{"style":683},[928],{"type":27,"value":929}," # 不启用 SMTP 的 STARTTLS\n",{"type":21,"tag":192,"props":931,"children":933},{"class":194,"line":932},16,[934,938,943],{"type":21,"tag":192,"props":935,"children":936},{"style":672},[937],{"type":27,"value":829},{"type":21,"tag":192,"props":939,"children":940},{"style":205},[941],{"type":27,"value":942},"SMTP_SSL_ENABLED=false",{"type":21,"tag":192,"props":944,"children":945},{"style":683},[946],{"type":27,"value":947}," # 不启用 SMTP 的 SSL\u002FTLS 加密\n",{"type":21,"tag":192,"props":949,"children":951},{"class":194,"line":950},17,[952],{"type":21,"tag":192,"props":953,"children":954},{"emptyLinePlaceholder":692},[955],{"type":27,"value":695},{"type":21,"tag":192,"props":957,"children":959},{"class":194,"line":958},18,[960,965,969],{"type":21,"tag":192,"props":961,"children":962},{"style":666},[963],{"type":27,"value":964},"    ports",{"type":21,"tag":192,"props":966,"children":967},{"style":672},[968],{"type":27,"value":675},{"type":21,"tag":192,"props":970,"children":971},{"style":683},[972],{"type":27,"value":973},"# 映射容器端口到宿主机\n",{"type":21,"tag":192,"props":975,"children":977},{"class":194,"line":976},19,[978,982,987],{"type":21,"tag":192,"props":979,"children":980},{"style":672},[981],{"type":27,"value":829},{"type":21,"tag":192,"props":983,"children":984},{"style":205},[985],{"type":27,"value":986},"\"80:8080\"",{"type":21,"tag":192,"props":988,"children":989},{"style":683},[990],{"type":27,"value":991}," # 宿主机 80 端口映射到容器的 8080（HTTP）\n",{"type":21,"tag":192,"props":993,"children":995},{"class":194,"line":994},20,[996,1000,1005],{"type":21,"tag":192,"props":997,"children":998},{"style":672},[999],{"type":27,"value":829},{"type":21,"tag":192,"props":1001,"children":1002},{"style":205},[1003],{"type":27,"value":1004},"\"443:8443\"",{"type":21,"tag":192,"props":1006,"children":1007},{"style":683},[1008],{"type":27,"value":1009}," # 宿主机 443 端口映射到容器的 8443（HTTPS）\n",{"type":21,"tag":192,"props":1011,"children":1013},{"class":194,"line":1012},21,[1014],{"type":21,"tag":192,"props":1015,"children":1016},{"emptyLinePlaceholder":692},[1017],{"type":27,"value":695},{"type":21,"tag":192,"props":1019,"children":1021},{"class":194,"line":1020},22,[1022,1027,1031],{"type":21,"tag":192,"props":1023,"children":1024},{"style":666},[1025],{"type":27,"value":1026},"    volumes",{"type":21,"tag":192,"props":1028,"children":1029},{"style":672},[1030],{"type":27,"value":675},{"type":21,"tag":192,"props":1032,"children":1033},{"style":683},[1034],{"type":27,"value":1035},"# 数据卷挂载，将容器中的目录映射到宿主机，以持久化数据\n",{"type":21,"tag":192,"props":1037,"children":1039},{"class":194,"line":1038},23,[1040,1044,1048],{"type":21,"tag":192,"props":1041,"children":1042},{"style":672},[1043],{"type":27,"value":829},{"type":21,"tag":192,"props":1045,"children":1046},{"style":205},[1047],{"type":27,"value":505},{"type":21,"tag":192,"props":1049,"children":1050},{"style":683},[1051],{"type":27,"value":1052}," # 将宿主机的 \u002Fopt\u002Fejbca-data 目录挂载到容器中，持久化数据库等数据\n",{"type":21,"tag":192,"props":1054,"children":1056},{"class":194,"line":1055},24,[1057],{"type":21,"tag":192,"props":1058,"children":1059},{"emptyLinePlaceholder":692},[1060],{"type":27,"value":695},{"type":21,"tag":192,"props":1062,"children":1064},{"class":194,"line":1063},25,[1065,1070,1074,1079],{"type":21,"tag":192,"props":1066,"children":1067},{"style":666},[1068],{"type":27,"value":1069},"    restart",{"type":21,"tag":192,"props":1071,"children":1072},{"style":672},[1073],{"type":27,"value":675},{"type":21,"tag":192,"props":1075,"children":1076},{"style":205},[1077],{"type":27,"value":1078},"unless-stopped",{"type":21,"tag":192,"props":1080,"children":1081},{"style":683},[1082],{"type":27,"value":1083}," # 如果容器异常退出则自动重启，除非人为停止\n",{"type":21,"tag":546,"props":1085,"children":1086},{},[1087],{"type":21,"tag":54,"props":1088,"children":1089},{},[1090],{"type":27,"value":1091},"启动容器服务：",{"type":21,"tag":182,"props":1093,"children":1095},{"code":1094,"language":185,"meta":7,"className":186,"style":7},"docker-compose up -d\ndocker-compose logs -f\n",[1096],{"type":21,"tag":141,"props":1097,"children":1098},{"__ignoreMap":7},[1099,1116],{"type":21,"tag":192,"props":1100,"children":1101},{"class":194,"line":195},[1102,1106,1111],{"type":21,"tag":192,"props":1103,"children":1104},{"style":199},[1105],{"type":27,"value":146},{"type":21,"tag":192,"props":1107,"children":1108},{"style":205},[1109],{"type":27,"value":1110}," up",{"type":21,"tag":192,"props":1112,"children":1113},{"style":211},[1114],{"type":27,"value":1115}," -d\n",{"type":21,"tag":192,"props":1117,"children":1118},{"class":194,"line":222},[1119,1123,1128],{"type":21,"tag":192,"props":1120,"children":1121},{"style":199},[1122],{"type":27,"value":146},{"type":21,"tag":192,"props":1124,"children":1125},{"style":205},[1126],{"type":27,"value":1127}," logs",{"type":21,"tag":192,"props":1129,"children":1130},{"style":211},[1131],{"type":27,"value":1132}," -f\n",{"type":21,"tag":531,"props":1134,"children":1135},{},[1136],{"type":21,"tag":36,"props":1137,"children":1138},{},[1139],{"type":27,"value":1140},"⚙️ 使用 Compose 可轻松管理配置版本，便于团队协作和恢复。",{"type":21,"tag":150,"props":1142,"children":1144},{"id":1143},"_44-远程访问配置",[1145],{"type":27,"value":1146},"4.4 远程访问配置",{"type":21,"tag":546,"props":1148,"children":1149},{},[1150],{"type":21,"tag":54,"props":1151,"children":1152},{},[1153],{"type":27,"value":1154},"提前设置容器 hostname（影响 TLS 证书 CN）：",{"type":21,"tag":182,"props":1156,"children":1158},{"code":1157,"language":655,"meta":7,"className":656,"style":7},"hostname: myejbca.test.local\n",[1159],{"type":21,"tag":141,"props":1160,"children":1161},{"__ignoreMap":7},[1162],{"type":21,"tag":192,"props":1163,"children":1164},{"class":194,"line":195},[1165,1170,1174],{"type":21,"tag":192,"props":1166,"children":1167},{"style":666},[1168],{"type":27,"value":1169},"hostname",{"type":21,"tag":192,"props":1171,"children":1172},{"style":672},[1173],{"type":27,"value":675},{"type":21,"tag":192,"props":1175,"children":1176},{"style":205},[1177],{"type":27,"value":1178},"myejbca.test.local\n",{"type":21,"tag":150,"props":1180,"children":1182},{"id":1181},"_45-管理证书信任",[1183],{"type":27,"value":1184},"4.5 管理证书信任",{"type":21,"tag":50,"props":1186,"children":1187},{},[1188],{"type":21,"tag":54,"props":1189,"children":1190},{},[1191,1193,1199],{"type":27,"value":1192},"下载超级管理员证书 ",{"type":21,"tag":141,"props":1194,"children":1196},{"className":1195},[],[1197],{"type":27,"value":1198},".p12",{"type":27,"value":1200}," 后需双击导入证书存储",{"type":21,"tag":150,"props":1202,"children":1204},{"id":1203},"_46-登录流程摘要",[1205],{"type":27,"value":1206},"4.6 登录流程摘要",{"type":21,"tag":546,"props":1208,"children":1209},{},[1210],{"type":21,"tag":54,"props":1211,"children":1212},{},[1213,1219,1221,1227],{"type":21,"tag":141,"props":1214,"children":1216},{"className":1215},[],[1217],{"type":27,"value":1218},"docker-compose logs -f",{"type":27,"value":1220},"查找容器日志中 ",{"type":21,"tag":141,"props":1222,"children":1224},{"className":1223},[],[1225],{"type":27,"value":1226},"SuperAdmin URL",{"type":27,"value":1228}," 和一次性密码：",{"type":21,"tag":182,"props":1230,"children":1232},{"code":1231,"language":185,"meta":7,"className":186,"style":7},"ejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *                                                                                                    *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *   URL:      https:\u002F\u002Fmyejbca.test.local:443\u002Fejbca\u002Fra\u002Fenrollwithusername.xhtml?username=superadmin *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *   Password: urAMy0He5c\u002FhHy+DYyDFNy4E                                                               *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *                                                                                                    *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) * Once the P12 is downloaded, use \"urAMy0He5c\u002FhHy+DYyDFNy4E\" to import it.                           *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *                                                                                                    *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) ******************************************************************************************************\n\n",[1233],{"type":21,"tag":141,"props":1234,"children":1235},{"__ignoreMap":7},[1236,1288,1357,1406,1449,1507,1550],{"type":21,"tag":192,"props":1237,"children":1238},{"class":194,"line":195},[1239,1243,1248,1253,1258,1263,1268,1273,1278,1283],{"type":21,"tag":192,"props":1240,"children":1241},{"style":199},[1242],{"type":27,"value":766},{"type":21,"tag":192,"props":1244,"children":1245},{"style":408},[1246],{"type":27,"value":1247},"    |",{"type":21,"tag":192,"props":1249,"children":1250},{"style":199},[1251],{"type":27,"value":1252}," 2025-08-05",{"type":21,"tag":192,"props":1254,"children":1255},{"style":205},[1256],{"type":27,"value":1257}," 09:11:31,656+0000",{"type":21,"tag":192,"props":1259,"children":1260},{"style":205},[1261],{"type":27,"value":1262}," INFO",{"type":21,"tag":192,"props":1264,"children":1265},{"style":672},[1266],{"type":27,"value":1267},"  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (",{"type":21,"tag":192,"props":1269,"children":1270},{"style":199},[1271],{"type":27,"value":1272},"process:1",{"type":21,"tag":192,"props":1274,"children":1275},{"style":672},[1276],{"type":27,"value":1277},") ",{"type":21,"tag":192,"props":1279,"children":1280},{"style":408},[1281],{"type":27,"value":1282},"*",{"type":21,"tag":192,"props":1284,"children":1285},{"style":408},[1286],{"type":27,"value":1287},"                                                                                                    *\n",{"type":21,"tag":192,"props":1289,"children":1290},{"class":194,"line":222},[1291,1295,1299,1303,1307,1311,1315,1319,1323,1327,1332,1337,1342,1347,1352],{"type":21,"tag":192,"props":1292,"children":1293},{"style":199},[1294],{"type":27,"value":766},{"type":21,"tag":192,"props":1296,"children":1297},{"style":408},[1298],{"type":27,"value":1247},{"type":21,"tag":192,"props":1300,"children":1301},{"style":199},[1302],{"type":27,"value":1252},{"type":21,"tag":192,"props":1304,"children":1305},{"style":205},[1306],{"type":27,"value":1257},{"type":21,"tag":192,"props":1308,"children":1309},{"style":205},[1310],{"type":27,"value":1262},{"type":21,"tag":192,"props":1312,"children":1313},{"style":672},[1314],{"type":27,"value":1267},{"type":21,"tag":192,"props":1316,"children":1317},{"style":199},[1318],{"type":27,"value":1272},{"type":21,"tag":192,"props":1320,"children":1321},{"style":672},[1322],{"type":27,"value":1277},{"type":21,"tag":192,"props":1324,"children":1325},{"style":408},[1326],{"type":27,"value":1282},{"type":21,"tag":192,"props":1328,"children":1329},{"style":672},[1330],{"type":27,"value":1331},"   URL:      https:\u002F\u002Fmyejbca.test.local:443\u002Fejbca\u002Fra\u002Fenrollwithusername.xhtml",{"type":21,"tag":192,"props":1333,"children":1334},{"style":408},[1335],{"type":27,"value":1336},"?",{"type":21,"tag":192,"props":1338,"children":1339},{"style":672},[1340],{"type":27,"value":1341},"username",{"type":21,"tag":192,"props":1343,"children":1344},{"style":408},[1345],{"type":27,"value":1346},"=",{"type":21,"tag":192,"props":1348,"children":1349},{"style":205},[1350],{"type":27,"value":1351},"superadmin",{"type":21,"tag":192,"props":1353,"children":1354},{"style":199},[1355],{"type":27,"value":1356}," *\n",{"type":21,"tag":192,"props":1358,"children":1359},{"class":194,"line":270},[1360,1364,1368,1372,1376,1380,1384,1388,1392,1396,1401],{"type":21,"tag":192,"props":1361,"children":1362},{"style":199},[1363],{"type":27,"value":766},{"type":21,"tag":192,"props":1365,"children":1366},{"style":408},[1367],{"type":27,"value":1247},{"type":21,"tag":192,"props":1369,"children":1370},{"style":199},[1371],{"type":27,"value":1252},{"type":21,"tag":192,"props":1373,"children":1374},{"style":205},[1375],{"type":27,"value":1257},{"type":21,"tag":192,"props":1377,"children":1378},{"style":205},[1379],{"type":27,"value":1262},{"type":21,"tag":192,"props":1381,"children":1382},{"style":672},[1383],{"type":27,"value":1267},{"type":21,"tag":192,"props":1385,"children":1386},{"style":199},[1387],{"type":27,"value":1272},{"type":21,"tag":192,"props":1389,"children":1390},{"style":672},[1391],{"type":27,"value":1277},{"type":21,"tag":192,"props":1393,"children":1394},{"style":408},[1395],{"type":27,"value":1282},{"type":21,"tag":192,"props":1397,"children":1398},{"style":672},[1399],{"type":27,"value":1400},"   Password: urAMy0He5c\u002FhHy+DYyDFNy4E                                                               ",{"type":21,"tag":192,"props":1402,"children":1403},{"style":408},[1404],{"type":27,"value":1405},"*\n",{"type":21,"tag":192,"props":1407,"children":1408},{"class":194,"line":279},[1409,1413,1417,1421,1425,1429,1433,1437,1441,1445],{"type":21,"tag":192,"props":1410,"children":1411},{"style":199},[1412],{"type":27,"value":766},{"type":21,"tag":192,"props":1414,"children":1415},{"style":408},[1416],{"type":27,"value":1247},{"type":21,"tag":192,"props":1418,"children":1419},{"style":199},[1420],{"type":27,"value":1252},{"type":21,"tag":192,"props":1422,"children":1423},{"style":205},[1424],{"type":27,"value":1257},{"type":21,"tag":192,"props":1426,"children":1427},{"style":205},[1428],{"type":27,"value":1262},{"type":21,"tag":192,"props":1430,"children":1431},{"style":672},[1432],{"type":27,"value":1267},{"type":21,"tag":192,"props":1434,"children":1435},{"style":199},[1436],{"type":27,"value":1272},{"type":21,"tag":192,"props":1438,"children":1439},{"style":672},[1440],{"type":27,"value":1277},{"type":21,"tag":192,"props":1442,"children":1443},{"style":408},[1444],{"type":27,"value":1282},{"type":21,"tag":192,"props":1446,"children":1447},{"style":408},[1448],{"type":27,"value":1287},{"type":21,"tag":192,"props":1450,"children":1451},{"class":194,"line":728},[1452,1456,1460,1464,1468,1472,1476,1480,1484,1488,1493,1498,1503],{"type":21,"tag":192,"props":1453,"children":1454},{"style":199},[1455],{"type":27,"value":766},{"type":21,"tag":192,"props":1457,"children":1458},{"style":408},[1459],{"type":27,"value":1247},{"type":21,"tag":192,"props":1461,"children":1462},{"style":199},[1463],{"type":27,"value":1252},{"type":21,"tag":192,"props":1465,"children":1466},{"style":205},[1467],{"type":27,"value":1257},{"type":21,"tag":192,"props":1469,"children":1470},{"style":205},[1471],{"type":27,"value":1262},{"type":21,"tag":192,"props":1473,"children":1474},{"style":672},[1475],{"type":27,"value":1267},{"type":21,"tag":192,"props":1477,"children":1478},{"style":199},[1479],{"type":27,"value":1272},{"type":21,"tag":192,"props":1481,"children":1482},{"style":672},[1483],{"type":27,"value":1277},{"type":21,"tag":192,"props":1485,"children":1486},{"style":408},[1487],{"type":27,"value":1282},{"type":21,"tag":192,"props":1489,"children":1490},{"style":672},[1491],{"type":27,"value":1492}," Once the P12 is downloaded, use ",{"type":21,"tag":192,"props":1494,"children":1495},{"style":205},[1496],{"type":27,"value":1497},"\"urAMy0He5c\u002FhHy+DYyDFNy4E\"",{"type":21,"tag":192,"props":1499,"children":1500},{"style":672},[1501],{"type":27,"value":1502}," to import it.                           ",{"type":21,"tag":192,"props":1504,"children":1505},{"style":408},[1506],{"type":27,"value":1405},{"type":21,"tag":192,"props":1508,"children":1509},{"class":194,"line":751},[1510,1514,1518,1522,1526,1530,1534,1538,1542,1546],{"type":21,"tag":192,"props":1511,"children":1512},{"style":199},[1513],{"type":27,"value":766},{"type":21,"tag":192,"props":1515,"children":1516},{"style":408},[1517],{"type":27,"value":1247},{"type":21,"tag":192,"props":1519,"children":1520},{"style":199},[1521],{"type":27,"value":1252},{"type":21,"tag":192,"props":1523,"children":1524},{"style":205},[1525],{"type":27,"value":1257},{"type":21,"tag":192,"props":1527,"children":1528},{"style":205},[1529],{"type":27,"value":1262},{"type":21,"tag":192,"props":1531,"children":1532},{"style":672},[1533],{"type":27,"value":1267},{"type":21,"tag":192,"props":1535,"children":1536},{"style":199},[1537],{"type":27,"value":1272},{"type":21,"tag":192,"props":1539,"children":1540},{"style":672},[1541],{"type":27,"value":1277},{"type":21,"tag":192,"props":1543,"children":1544},{"style":408},[1545],{"type":27,"value":1282},{"type":21,"tag":192,"props":1547,"children":1548},{"style":408},[1549],{"type":27,"value":1287},{"type":21,"tag":192,"props":1551,"children":1552},{"class":194,"line":774},[1553,1557,1561,1565,1569,1573,1577,1581,1585],{"type":21,"tag":192,"props":1554,"children":1555},{"style":199},[1556],{"type":27,"value":766},{"type":21,"tag":192,"props":1558,"children":1559},{"style":408},[1560],{"type":27,"value":1247},{"type":21,"tag":192,"props":1562,"children":1563},{"style":199},[1564],{"type":27,"value":1252},{"type":21,"tag":192,"props":1566,"children":1567},{"style":205},[1568],{"type":27,"value":1257},{"type":21,"tag":192,"props":1570,"children":1571},{"style":205},[1572],{"type":27,"value":1262},{"type":21,"tag":192,"props":1574,"children":1575},{"style":672},[1576],{"type":27,"value":1267},{"type":21,"tag":192,"props":1578,"children":1579},{"style":199},[1580],{"type":27,"value":1272},{"type":21,"tag":192,"props":1582,"children":1583},{"style":672},[1584],{"type":27,"value":1277},{"type":21,"tag":192,"props":1586,"children":1587},{"style":408},[1588],{"type":27,"value":1589},"******************************************************************************************************\n",{"type":21,"tag":546,"props":1591,"children":1592},{},[1593,1603,1614],{"type":21,"tag":54,"props":1594,"children":1595},{},[1596,1598],{"type":27,"value":1597},"访问领取 URL 填写密码 → 设置导出密码 → 下载 ",{"type":21,"tag":141,"props":1599,"children":1601},{"className":1600},[],[1602],{"type":27,"value":1198},{"type":21,"tag":54,"props":1604,"children":1605},{},[1606,1608],{"type":27,"value":1607},"导入浏览器后访问：",{"type":21,"tag":141,"props":1609,"children":1611},{"className":1610},[],[1612],{"type":27,"value":1613},"https:\u002F\u002Fmyejbca.test.local\u002Fejbca\u002Fadminweb",{"type":21,"tag":54,"props":1615,"children":1616},{},[1617],{"type":27,"value":1618},"若提示未提供客户端证书，检查是否导入成功、代理关闭、域名正确解析",{"type":21,"tag":531,"props":1620,"children":1621},{},[1622],{"type":21,"tag":36,"props":1623,"children":1624},{},[1625],{"type":27,"value":1626},"✅ 至此，EJBCA 部署 + 持久化 + 管理登录流程即告完成。",{"type":21,"tag":150,"props":1628,"children":1630},{"id":1629},"_47-重要提示请务必遵守以下要求",[1631],{"type":27,"value":1632},"4.7 重要提示（请务必遵守以下要求）",{"type":21,"tag":36,"props":1634,"children":1635},{},[1636,1638,1643,1645,1650,1652,1658],{"type":27,"value":1637},"✅ ",{"type":21,"tag":42,"props":1639,"children":1640},{},[1641],{"type":27,"value":1642},"必须",{"type":27,"value":1644}," 先将 ",{"type":21,"tag":141,"props":1646,"children":1648},{"className":1647},[],[1649],{"type":27,"value":789},{"type":27,"value":1651}," 添加到 ",{"type":21,"tag":141,"props":1653,"children":1655},{"className":1654},[],[1656],{"type":27,"value":1657},"hosts",{"type":27,"value":1659}," 文件，或搭建本地 DNS 服务器，否则浏览器可能无法解析域名。",{"type":21,"tag":36,"props":1661,"children":1662},{},[1663,1664,1669,1671,1676,1678,1683],{"type":27,"value":1637},{"type":21,"tag":42,"props":1665,"children":1666},{},[1667],{"type":27,"value":1668},"超级管理员证书算法默认是 DILITHIUM2",{"type":27,"value":1670},"（根据版本默认算法会不一样），但 ",{"type":21,"tag":42,"props":1672,"children":1673},{},[1674],{"type":27,"value":1675},"Windows 大概不能识别",{"type":27,"value":1677},"，建议改为 ",{"type":21,"tag":42,"props":1679,"children":1680},{},[1681],{"type":27,"value":1682},"RSA 4096",{"type":27,"value":1684},"，以确保兼容性。",{"type":21,"tag":36,"props":1686,"children":1687},{},[1688,1689,1694],{"type":27,"value":1637},{"type":21,"tag":42,"props":1690,"children":1691},{},[1692],{"type":27,"value":1693},"不能开代理",{"type":27,"value":1695},"，否则 EJBCA 可能无法正确处理客户端证书认证。",{"type":21,"tag":36,"props":1697,"children":1698},{},[1699,1700,1705,1707,1713],{"type":27,"value":1637},{"type":21,"tag":42,"props":1701,"children":1702},{},[1703],{"type":27,"value":1704},"确保 Windows\u002FmacOS\u002FLinux 证书存储正确导入",{"type":27,"value":1706},"，避免 ",{"type":21,"tag":141,"props":1708,"children":1710},{"className":1709},[],[1711],{"type":27,"value":1712},"No client certificate was presented",{"type":27,"value":1714}," 错误。",{"type":21,"tag":36,"props":1716,"children":1717},{},[1718,1719,1724,1726,1731],{"type":27,"value":1637},{"type":21,"tag":42,"props":1720,"children":1721},{},[1722],{"type":27,"value":1723},"第一次建议使用 chrome 浏览器无痕模式",{"type":27,"value":1725},"，避免缓存问题导致",{"type":21,"tag":141,"props":1727,"children":1729},{"className":1728},[],[1730],{"type":27,"value":1712},{"type":27,"value":1732},"。",{"type":21,"tag":65,"props":1734,"children":1735},{},[],{"type":21,"tag":29,"props":1737,"children":1739},{"id":1738},"_5-初始-ca-创建与证书层级搭建",[1740],{"type":27,"value":1741},"5. 初始 CA 创建与证书层级搭建",{"type":21,"tag":150,"props":1743,"children":1745},{"id":1744},"_51-进入证书-profile-管理",[1746],{"type":27,"value":1747},"5.1 进入证书 Profile 管理",{"type":21,"tag":50,"props":1749,"children":1750},{},[1751,1762],{"type":21,"tag":54,"props":1752,"children":1753},{},[1754,1756,1761],{"type":27,"value":1755},"登录 ",{"type":21,"tag":42,"props":1757,"children":1758},{},[1759],{"type":27,"value":1760},"EJBCA 管理控制台",{"type":27,"value":1732},{"type":21,"tag":54,"props":1763,"children":1764},{},[1765,1767,1772],{"type":27,"value":1766},"依次点击 ",{"type":21,"tag":42,"props":1768,"children":1769},{},[1770],{"type":27,"value":1771},"CA Functions → Certificate Profiles",{"type":27,"value":1773}," 进入管理页面。",{"type":21,"tag":150,"props":1775,"children":1777},{"id":1776},"_52-创建证书-profile",[1778],{"type":27,"value":1779},"5.2 创建证书 Profile",{"type":21,"tag":170,"props":1781,"children":1783},{"id":1782},"方法-1克隆现有-profile",[1784],{"type":27,"value":1785},"方法 1：克隆现有 Profile",{"type":21,"tag":50,"props":1787,"children":1788},{},[1789,1802],{"type":21,"tag":54,"props":1790,"children":1791},{},[1792,1794,1800],{"type":27,"value":1793},"在列表中找到合适的 Profile（如 ",{"type":21,"tag":141,"props":1795,"children":1797},{"className":1796},[],[1798],{"type":27,"value":1799},"ENDUSER",{"type":27,"value":1801},"）。",{"type":21,"tag":54,"props":1803,"children":1804},{},[1805,1807,1812],{"type":27,"value":1806},"点击 ",{"type":21,"tag":42,"props":1808,"children":1809},{},[1810],{"type":27,"value":1811},"Clone",{"type":27,"value":1813},"，输入新名称，保存。",{"type":21,"tag":170,"props":1815,"children":1817},{"id":1816},"方法-2手动创建-profile",[1818],{"type":27,"value":1819},"方法 2：手动创建 Profile",{"type":21,"tag":50,"props":1821,"children":1822},{},[1823,1834,1853],{"type":21,"tag":54,"props":1824,"children":1825},{},[1826,1827,1832],{"type":27,"value":1806},{"type":21,"tag":42,"props":1828,"children":1829},{},[1830],{"type":27,"value":1831},"Add",{"type":27,"value":1833},"，输入名称后进入编辑页面。",{"type":21,"tag":54,"props":1835,"children":1836},{},[1837,1839,1844,1846,1851],{"type":27,"value":1838},"根据实际需求设置 ",{"type":21,"tag":42,"props":1840,"children":1841},{},[1842],{"type":27,"value":1843},"Key Usage",{"type":27,"value":1845},"、",{"type":21,"tag":42,"props":1847,"children":1848},{},[1849],{"type":27,"value":1850},"Extended Key Usage",{"type":27,"value":1852},"、有效期、Subject DN 设置等。",{"type":21,"tag":54,"props":1854,"children":1855},{},[1856],{"type":27,"value":1857},"保存后返回列表查看。",{"type":21,"tag":150,"props":1859,"children":1861},{"id":1860},"_53-创建-crypto-token",[1862],{"type":27,"value":1863},"5.3 创建 Crypto Token",{"type":21,"tag":546,"props":1865,"children":1866},{},[1867,1878,1966],{"type":21,"tag":54,"props":1868,"children":1869},{},[1870,1872,1877],{"type":27,"value":1871},"进入 ",{"type":21,"tag":42,"props":1873,"children":1874},{},[1875],{"type":27,"value":1876},"CA Functions → Crypto Tokens",{"type":27,"value":1732},{"type":21,"tag":54,"props":1879,"children":1880},{},[1881,1882,1887,1889],{"type":27,"value":1806},{"type":21,"tag":42,"props":1883,"children":1884},{},[1885],{"type":27,"value":1886},"Create new",{"type":27,"value":1888}," 并填写：",{"type":21,"tag":50,"props":1890,"children":1891},{},[1892,1902,1919,1929,1946],{"type":21,"tag":54,"props":1893,"children":1894},{},[1895,1900],{"type":21,"tag":42,"props":1896,"children":1897},{},[1898],{"type":27,"value":1899},"Name",{"type":27,"value":1901},"：输入 Crypto Token 名称。",{"type":21,"tag":54,"props":1903,"children":1904},{},[1905,1910,1912,1918],{"type":21,"tag":42,"props":1906,"children":1907},{},[1908],{"type":27,"value":1909},"Type",{"type":27,"value":1911},"：选择 ",{"type":21,"tag":141,"props":1913,"children":1915},{"className":1914},[],[1916],{"type":27,"value":1917},"SOFT",{"type":27,"value":1732},{"type":21,"tag":54,"props":1920,"children":1921},{},[1922,1927],{"type":21,"tag":42,"props":1923,"children":1924},{},[1925],{"type":27,"value":1926},"Auto-activation",{"type":27,"value":1928},"：可选，勾选可自动激活。",{"type":21,"tag":54,"props":1930,"children":1931},{},[1932,1937,1939,1945],{"type":21,"tag":42,"props":1933,"children":1934},{},[1935],{"type":27,"value":1936},"Allow export of private keys",{"type":27,"value":1938},"：如需导出私钥，勾选 ",{"type":21,"tag":141,"props":1940,"children":1942},{"className":1941},[],[1943],{"type":27,"value":1944},"Allow",{"type":27,"value":1732},{"type":21,"tag":54,"props":1947,"children":1948},{},[1949,1954,1956,1960],{"type":21,"tag":42,"props":1950,"children":1951},{},[1952],{"type":27,"value":1953},"Authentication Code",{"type":27,"value":1955},"：输入认证码并重复确认。",{"type":21,"tag":1957,"props":1958,"children":1959},"br",{},[],{"type":21,"tag":141,"props":1961,"children":1963},{"className":1962},[],[1964],{"type":27,"value":1965},"dd if=\u002Fdev\u002Frandom bs=1 count=128 2>&1| sha256sum | awk '{print $1}",{"type":21,"tag":54,"props":1967,"children":1968},{},[1969,1971,1976],{"type":27,"value":1970},"保存并在列表中确保状态为 ",{"type":21,"tag":42,"props":1972,"children":1973},{},[1974],{"type":27,"value":1975},"Active",{"type":27,"value":1732},{"type":21,"tag":150,"props":1978,"children":1980},{"id":1979},"_54-生成密钥对",[1981],{"type":27,"value":1982},"5.4 生成密钥对",{"type":21,"tag":50,"props":1984,"children":1985},{},[1986,1997,2017,2028],{"type":21,"tag":54,"props":1987,"children":1988},{},[1989,1990,1995],{"type":27,"value":1871},{"type":21,"tag":42,"props":1991,"children":1992},{},[1993],{"type":27,"value":1994},"Crypto Token",{"type":27,"value":1996}," 详情页面。",{"type":21,"tag":54,"props":1998,"children":1999},{},[2000,2002,2008,2010,2016],{"type":27,"value":2001},"在 ",{"type":21,"tag":141,"props":2003,"children":2005},{"className":2004},[],[2006],{"type":27,"value":2007},"Crypto Token currently does not contain any key pairs.",{"type":27,"value":2009}," 处输入密钥名称（如 ",{"type":21,"tag":141,"props":2011,"children":2013},{"className":2012},[],[2014],{"type":27,"value":2015},"signKey",{"type":27,"value":1801},{"type":21,"tag":54,"props":2018,"children":2019},{},[2020,2022,2027],{"type":27,"value":2021},"选择密钥算法（如 ",{"type":21,"tag":141,"props":2023,"children":2025},{"className":2024},[],[2026],{"type":27,"value":1682},{"type":27,"value":1801},{"type":21,"tag":54,"props":2029,"children":2030},{},[2031,2032,2037],{"type":27,"value":1806},{"type":21,"tag":42,"props":2033,"children":2034},{},[2035],{"type":27,"value":2036},"Generate new key pair",{"type":27,"value":2038}," 生成密钥。",{"type":21,"tag":531,"props":2040,"children":2041},{},[2042],{"type":21,"tag":36,"props":2043,"children":2044},{},[2045,2050],{"type":21,"tag":42,"props":2046,"children":2047},{},[2048],{"type":27,"value":2049},"注意",{"type":27,"value":2051},"：默认 Profile 不能修改，需克隆后新建。",{"type":21,"tag":150,"props":2053,"children":2055},{"id":2054},"_55-创建-ca",[2056],{"type":27,"value":2057},"5.5 创建 CA",{"type":21,"tag":546,"props":2059,"children":2060},{},[2061,2072,2091,2130,2142,2162],{"type":21,"tag":54,"props":2062,"children":2063},{},[2064,2066,2071],{"type":27,"value":2065},"打开 ",{"type":21,"tag":42,"props":2067,"children":2068},{},[2069],{"type":27,"value":2070},"CA Functions → Certification Authorities",{"type":27,"value":1732},{"type":21,"tag":54,"props":2073,"children":2074},{},[2075,2077,2083,2085,2090],{"type":27,"value":2076},"在顶部列表中会看到默认的 ",{"type":21,"tag":141,"props":2078,"children":2080},{"className":2079},[],[2081],{"type":27,"value":2082},"ManagementCA (Active)",{"type":27,"value":2084},"；",{"type":21,"tag":42,"props":2086,"children":2087},{},[2088],{"type":27,"value":2089},"无需选中它",{"type":27,"value":1732},{"type":21,"tag":54,"props":2092,"children":2093},{},[2094,2096,2101,2103],{"type":27,"value":2095},"滚动到页面底部的 ",{"type":21,"tag":42,"props":2097,"children":2098},{},[2099],{"type":27,"value":2100},"Add CA",{"type":27,"value":2102}," 区域：\n",{"type":21,"tag":50,"props":2104,"children":2105},{},[2106,2118],{"type":21,"tag":54,"props":2107,"children":2108},{},[2109,2111,2117],{"type":27,"value":2110},"在文本框中输入新 CA 名称，例如 ",{"type":21,"tag":141,"props":2112,"children":2114},{"className":2113},[],[2115],{"type":27,"value":2116},"DemoCA",{"type":27,"value":1732},{"type":21,"tag":54,"props":2119,"children":2120},{},[2121,2123,2128],{"type":27,"value":2122},"点击右侧 ",{"type":21,"tag":42,"props":2124,"children":2125},{},[2126],{"type":27,"value":2127},"Create…",{"type":27,"value":2129}," 按钮，进入 CA 配置向导。",{"type":21,"tag":54,"props":2131,"children":2132},{},[2133,2134,2140],{"type":27,"value":2001},{"type":21,"tag":2135,"props":2136,"children":2137},"em",{},[2138],{"type":27,"value":2139},"Create CA",{"type":27,"value":2141}," 页面完成相关字段：",{"type":21,"tag":54,"props":2143,"children":2144},{},[2145,2147,2152,2154,2160],{"type":27,"value":2146},"点击最下方 ",{"type":21,"tag":42,"props":2148,"children":2149},{},[2150],{"type":27,"value":2151},"Create",{"type":27,"value":2153}," 保存。若配置正确，页面将跳转回 CA 列表并看到 ",{"type":21,"tag":141,"props":2155,"children":2157},{"className":2156},[],[2158],{"type":27,"value":2159},"DemoSubCA (Active)",{"type":27,"value":2161}," 状态。",{"type":21,"tag":54,"props":2163,"children":2164},{},[2165,2167,2172],{"type":27,"value":2166},"（可选）若要手动上传由根 CA 签发的证书，可在列表中选中新 CA，然后使用 ",{"type":21,"tag":42,"props":2168,"children":2169},{},[2170],{"type":27,"value":2171},"Import CA certificate…",{"type":27,"value":2173}," 功能上传链文件。",{"type":21,"tag":36,"props":2175,"children":2176},{},[2177],{"type":27,"value":2178},"到此，中间 CA 创建完成，后续即可用它签发终端实体证书。",{"type":21,"tag":150,"props":2180,"children":2182},{"id":2181},"_56-root-ca-创建简要步骤案例",[2183],{"type":27,"value":2184},"5.6 Root CA 创建简要步骤案例",{"type":21,"tag":170,"props":2186,"children":2188},{"id":2187},"_1️⃣-ca-类型与密钥配置",[2189],{"type":27,"value":2190},"1️⃣ CA 类型与密钥配置",{"type":21,"tag":2192,"props":2193,"children":2194},"table",{},[2195,2220],{"type":21,"tag":2196,"props":2197,"children":2198},"thead",{},[2199],{"type":21,"tag":2200,"props":2201,"children":2202},"tr",{},[2203,2212],{"type":21,"tag":2204,"props":2205,"children":2206},"th",{},[2207],{"type":21,"tag":42,"props":2208,"children":2209},{},[2210],{"type":27,"value":2211},"参数",{"type":21,"tag":2204,"props":2213,"children":2214},{},[2215],{"type":21,"tag":42,"props":2216,"children":2217},{},[2218],{"type":27,"value":2219},"说明",{"type":21,"tag":2221,"props":2222,"children":2223},"tbody",{},[2224,2247,2276,2298,2320,2342,2364],{"type":21,"tag":2200,"props":2225,"children":2226},{},[2227,2236],{"type":21,"tag":2228,"props":2229,"children":2230},"td",{},[2231],{"type":21,"tag":42,"props":2232,"children":2233},{},[2234],{"type":27,"value":2235},"CA Type",{"type":21,"tag":2228,"props":2237,"children":2238},{},[2239,2245],{"type":21,"tag":141,"props":2240,"children":2242},{"className":2241},[],[2243],{"type":27,"value":2244},"X.509 CA",{"type":27,"value":2246}," ✅ 标准 X.509 证书 CA。",{"type":21,"tag":2200,"props":2248,"children":2249},{},[2250,2257],{"type":21,"tag":2228,"props":2251,"children":2252},{},[2253],{"type":21,"tag":42,"props":2254,"children":2255},{},[2256],{"type":27,"value":1994},{"type":21,"tag":2228,"props":2258,"children":2259},{},[2260,2262,2267,2269,2275],{"type":27,"value":2261},"选择已创建的 ",{"type":21,"tag":141,"props":2263,"children":2265},{"className":2264},[],[2266],{"type":27,"value":1994},{"type":27,"value":2268}," ✅（如 ",{"type":21,"tag":141,"props":2270,"children":2272},{"className":2271},[],[2273],{"type":27,"value":2274},"demoCrypto",{"type":27,"value":1801},{"type":21,"tag":2200,"props":2277,"children":2278},{},[2279,2287],{"type":21,"tag":2228,"props":2280,"children":2281},{},[2282],{"type":21,"tag":42,"props":2283,"children":2284},{},[2285],{"type":27,"value":2286},"Signing Algorithm",{"type":21,"tag":2228,"props":2288,"children":2289},{},[2290,2296],{"type":21,"tag":141,"props":2291,"children":2293},{"className":2292},[],[2294],{"type":27,"value":2295},"SHA256WithRSA",{"type":27,"value":2297}," ✅ 更安全的签名算法。",{"type":21,"tag":2200,"props":2299,"children":2300},{},[2301,2309],{"type":21,"tag":2228,"props":2302,"children":2303},{},[2304],{"type":21,"tag":42,"props":2305,"children":2306},{},[2307],{"type":27,"value":2308},"Alternative Signing Algorithm",{"type":21,"tag":2228,"props":2310,"children":2311},{},[2312,2318],{"type":21,"tag":141,"props":2313,"children":2315},{"className":2314},[],[2316],{"type":27,"value":2317},"None",{"type":27,"value":2319}," ❌ 无需备用签名算法。",{"type":21,"tag":2200,"props":2321,"children":2322},{},[2323,2331],{"type":21,"tag":2228,"props":2324,"children":2325},{},[2326],{"type":21,"tag":42,"props":2327,"children":2328},{},[2329],{"type":27,"value":2330},"Key Sequence Format",{"type":21,"tag":2228,"props":2332,"children":2333},{},[2334,2340],{"type":21,"tag":141,"props":2335,"children":2337},{"className":2336},[],[2338],{"type":27,"value":2339},"Numeric (0-9)",{"type":27,"value":2341}," ✅ 用于 CA 证书序列号。",{"type":21,"tag":2200,"props":2343,"children":2344},{},[2345,2353],{"type":21,"tag":2228,"props":2346,"children":2347},{},[2348],{"type":21,"tag":42,"props":2349,"children":2350},{},[2351],{"type":27,"value":2352},"Key Sequence",{"type":21,"tag":2228,"props":2354,"children":2355},{},[2356,2362],{"type":21,"tag":141,"props":2357,"children":2359},{"className":2358},[],[2360],{"type":27,"value":2361},"00000",{"type":27,"value":2363}," ✅ 初始序列号，可修改。",{"type":21,"tag":2200,"props":2365,"children":2366},{},[2367,2375],{"type":21,"tag":2228,"props":2368,"children":2369},{},[2370],{"type":21,"tag":42,"props":2371,"children":2372},{},[2373],{"type":27,"value":2374},"Description",{"type":21,"tag":2228,"props":2376,"children":2377},{},[2378],{"type":27,"value":2379},"Root CA 说明，可填写用途、管理单位等 ✅",{"type":21,"tag":65,"props":2381,"children":2382},{},[],{"type":21,"tag":170,"props":2384,"children":2386},{"id":2385},"_2️⃣-证书策略directives",[2387],{"type":27,"value":2388},"2️⃣ 证书策略（Directives）",{"type":21,"tag":2192,"props":2390,"children":2391},{},[2392,2412],{"type":21,"tag":2196,"props":2393,"children":2394},{},[2395],{"type":21,"tag":2200,"props":2396,"children":2397},{},[2398,2405],{"type":21,"tag":2204,"props":2399,"children":2400},{},[2401],{"type":21,"tag":42,"props":2402,"children":2403},{},[2404],{"type":27,"value":2211},{"type":21,"tag":2204,"props":2406,"children":2407},{},[2408],{"type":21,"tag":42,"props":2409,"children":2410},{},[2411],{"type":27,"value":2219},{"type":21,"tag":2221,"props":2413,"children":2414},{},[2415,2431,2447,2471,2487,2503,2519],{"type":21,"tag":2200,"props":2416,"children":2417},{},[2418,2426],{"type":21,"tag":2228,"props":2419,"children":2420},{},[2421],{"type":21,"tag":42,"props":2422,"children":2423},{},[2424],{"type":27,"value":2425},"Enforce unique public keys",{"type":21,"tag":2228,"props":2427,"children":2428},{},[2429],{"type":27,"value":2430},"✅ 强制公钥唯一性，防止重复",{"type":21,"tag":2200,"props":2432,"children":2433},{},[2434,2442],{"type":21,"tag":2228,"props":2435,"children":2436},{},[2437],{"type":21,"tag":42,"props":2438,"children":2439},{},[2440],{"type":27,"value":2441},"Enforce key renewal",{"type":21,"tag":2228,"props":2443,"children":2444},{},[2445],{"type":27,"value":2446},"❌ Root CA 可不启用",{"type":21,"tag":2200,"props":2448,"children":2449},{},[2450,2458],{"type":21,"tag":2228,"props":2451,"children":2452},{},[2453],{"type":21,"tag":42,"props":2454,"children":2455},{},[2456],{"type":27,"value":2457},"Enforce unique DN",{"type":21,"tag":2228,"props":2459,"children":2460},{},[2461,2463,2469],{"type":27,"value":2462},"✅ 确保 ",{"type":21,"tag":141,"props":2464,"children":2466},{"className":2465},[],[2467],{"type":27,"value":2468},"DN",{"type":27,"value":2470}," 唯一（适用于小规模 CA）",{"type":21,"tag":2200,"props":2472,"children":2473},{},[2474,2482],{"type":21,"tag":2228,"props":2475,"children":2476},{},[2477],{"type":21,"tag":42,"props":2478,"children":2479},{},[2480],{"type":27,"value":2481},"Enforce unique Subject DN SerialNumber",{"type":21,"tag":2228,"props":2483,"children":2484},{},[2485],{"type":27,"value":2486},"❌ 仅适用于大规模 CA（20 个以下证书可不启用）",{"type":21,"tag":2200,"props":2488,"children":2489},{},[2490,2498],{"type":21,"tag":2228,"props":2491,"children":2492},{},[2493],{"type":21,"tag":42,"props":2494,"children":2495},{},[2496],{"type":27,"value":2497},"Use Certificate Request History",{"type":21,"tag":2228,"props":2499,"children":2500},{},[2501],{"type":27,"value":2502},"❌ 记录证书请求历史,Root CA 不启用",{"type":21,"tag":2200,"props":2504,"children":2505},{},[2506,2514],{"type":21,"tag":2228,"props":2507,"children":2508},{},[2509],{"type":21,"tag":42,"props":2510,"children":2511},{},[2512],{"type":27,"value":2513},"Use User Storage",{"type":21,"tag":2228,"props":2515,"children":2516},{},[2517],{"type":27,"value":2518},"✅ 存储用户信息",{"type":21,"tag":2200,"props":2520,"children":2521},{},[2522,2530],{"type":21,"tag":2228,"props":2523,"children":2524},{},[2525],{"type":21,"tag":42,"props":2526,"children":2527},{},[2528],{"type":27,"value":2529},"Use Certificate Storage",{"type":21,"tag":2228,"props":2531,"children":2532},{},[2533],{"type":27,"value":2534},"✅ 存储已颁发证书",{"type":21,"tag":65,"props":2536,"children":2537},{},[],{"type":21,"tag":170,"props":2539,"children":2541},{"id":2540},"_3️⃣-证书数据ca-certificate-data",[2542],{"type":27,"value":2543},"3️⃣ 证书数据（CA Certificate Data）",{"type":21,"tag":2192,"props":2545,"children":2546},{},[2547,2567],{"type":21,"tag":2196,"props":2548,"children":2549},{},[2550],{"type":21,"tag":2200,"props":2551,"children":2552},{},[2553,2560],{"type":21,"tag":2204,"props":2554,"children":2555},{},[2556],{"type":21,"tag":42,"props":2557,"children":2558},{},[2559],{"type":27,"value":2211},{"type":21,"tag":2204,"props":2561,"children":2562},{},[2563],{"type":21,"tag":42,"props":2564,"children":2565},{},[2566],{"type":27,"value":2219},{"type":21,"tag":2221,"props":2568,"children":2569},{},[2570,2592,2614,2636,2658,2674,2690,2706,2722,2744,2766,2782],{"type":21,"tag":2200,"props":2571,"children":2572},{},[2573,2581],{"type":21,"tag":2228,"props":2574,"children":2575},{},[2576],{"type":21,"tag":42,"props":2577,"children":2578},{},[2579],{"type":27,"value":2580},"Subject DN",{"type":21,"tag":2228,"props":2582,"children":2583},{},[2584,2590],{"type":21,"tag":141,"props":2585,"children":2587},{"className":2586},[],[2588],{"type":27,"value":2589},"CN=test EnterpriseIT Root CA",{"type":27,"value":2591}," ✅",{"type":21,"tag":2200,"props":2593,"children":2594},{},[2595,2603],{"type":21,"tag":2228,"props":2596,"children":2597},{},[2598],{"type":21,"tag":42,"props":2599,"children":2600},{},[2601],{"type":27,"value":2602},"Signed By",{"type":21,"tag":2228,"props":2604,"children":2605},{},[2606,2612],{"type":21,"tag":141,"props":2607,"children":2609},{"className":2608},[],[2610],{"type":27,"value":2611},"Self Signed",{"type":27,"value":2613}," ✅ Root CA 必须自签名",{"type":21,"tag":2200,"props":2615,"children":2616},{},[2617,2625],{"type":21,"tag":2228,"props":2618,"children":2619},{},[2620],{"type":21,"tag":42,"props":2621,"children":2622},{},[2623],{"type":27,"value":2624},"Certificate Profile",{"type":21,"tag":2228,"props":2626,"children":2627},{},[2628,2634],{"type":21,"tag":141,"props":2629,"children":2631},{"className":2630},[],[2632],{"type":27,"value":2633},"ITROOTCA_profile",{"type":27,"value":2635}," ✅ 选择克隆后的 ROOTCA，允许修改参数",{"type":21,"tag":2200,"props":2637,"children":2638},{},[2639,2647],{"type":21,"tag":2228,"props":2640,"children":2641},{},[2642],{"type":21,"tag":42,"props":2643,"children":2644},{},[2645],{"type":27,"value":2646},"Validity",{"type":21,"tag":2228,"props":2648,"children":2649},{},[2650,2656],{"type":21,"tag":141,"props":2651,"children":2653},{"className":2652},[],[2654],{"type":27,"value":2655},"20y",{"type":27,"value":2657}," ✅ 证书有效期 20 年",{"type":21,"tag":2200,"props":2659,"children":2660},{},[2661,2669],{"type":21,"tag":2228,"props":2662,"children":2663},{},[2664],{"type":21,"tag":42,"props":2665,"children":2666},{},[2667],{"type":27,"value":2668},"Subject Alternative Name",{"type":21,"tag":2228,"props":2670,"children":2671},{},[2672],{"type":27,"value":2673},"❌ Root CA 通常不需要",{"type":21,"tag":2200,"props":2675,"children":2676},{},[2677,2685],{"type":21,"tag":2228,"props":2678,"children":2679},{},[2680],{"type":21,"tag":42,"props":2681,"children":2682},{},[2683],{"type":27,"value":2684},"Certificate Policy OID",{"type":21,"tag":2228,"props":2686,"children":2687},{},[2688],{"type":27,"value":2689},"❌ 可选，默认留空",{"type":21,"tag":2200,"props":2691,"children":2692},{},[2693,2701],{"type":21,"tag":2228,"props":2694,"children":2695},{},[2696],{"type":21,"tag":42,"props":2697,"children":2698},{},[2699],{"type":27,"value":2700},"Use UTF-8 in policy notice text",{"type":21,"tag":2228,"props":2702,"children":2703},{},[2704],{"type":27,"value":2705},"✅ 确保国际字符支持",{"type":21,"tag":2200,"props":2707,"children":2708},{},[2709,2717],{"type":21,"tag":2228,"props":2710,"children":2711},{},[2712],{"type":21,"tag":42,"props":2713,"children":2714},{},[2715],{"type":27,"value":2716},"PrintableString encoding in DN",{"type":21,"tag":2228,"props":2718,"children":2719},{},[2720],{"type":27,"value":2721},"❌ 不勾选，避免影响国际化",{"type":21,"tag":2200,"props":2723,"children":2724},{},[2725,2733],{"type":21,"tag":2228,"props":2726,"children":2727},{},[2728],{"type":21,"tag":42,"props":2729,"children":2730},{},[2731],{"type":27,"value":2732},"LDAP DN order",{"type":21,"tag":2228,"props":2734,"children":2735},{},[2736,2737,2742],{"type":27,"value":2462},{"type":21,"tag":141,"props":2738,"children":2740},{"className":2739},[],[2741],{"type":27,"value":2468},{"type":27,"value":2743}," 按 LDAP 规范排列",{"type":21,"tag":2200,"props":2745,"children":2746},{},[2747,2755],{"type":21,"tag":2228,"props":2748,"children":2749},{},[2750],{"type":21,"tag":42,"props":2751,"children":2752},{},[2753],{"type":27,"value":2754},"Serial Number Octet Size",{"type":21,"tag":2228,"props":2756,"children":2757},{},[2758,2764],{"type":21,"tag":141,"props":2759,"children":2761},{"className":2760},[],[2762],{"type":27,"value":2763},"20",{"type":27,"value":2765}," ✅ 推荐 20 字节，确保唯一性",{"type":21,"tag":2200,"props":2767,"children":2768},{},[2769,2777],{"type":21,"tag":2228,"props":2770,"children":2771},{},[2772],{"type":21,"tag":42,"props":2773,"children":2774},{},[2775],{"type":27,"value":2776},"Name Constraints, Permitted",{"type":21,"tag":2228,"props":2778,"children":2779},{},[2780],{"type":27,"value":2781},"❌ Root CA 默认禁用，留空",{"type":21,"tag":2200,"props":2783,"children":2784},{},[2785,2793],{"type":21,"tag":2228,"props":2786,"children":2787},{},[2788],{"type":21,"tag":42,"props":2789,"children":2790},{},[2791],{"type":27,"value":2792},"Name Constraints, Excluded",{"type":21,"tag":2228,"props":2794,"children":2795},{},[2796],{"type":27,"value":2781},{"type":21,"tag":65,"props":2798,"children":2799},{},[],{"type":21,"tag":170,"props":2801,"children":2803},{"id":2802},"_4️⃣-crl-配置证书吊销列表",[2804],{"type":27,"value":2805},"4️⃣ CRL 配置（证书吊销列表）",{"type":21,"tag":2192,"props":2807,"children":2808},{},[2809,2829],{"type":21,"tag":2196,"props":2810,"children":2811},{},[2812],{"type":21,"tag":2200,"props":2813,"children":2814},{},[2815,2822],{"type":21,"tag":2204,"props":2816,"children":2817},{},[2818],{"type":21,"tag":42,"props":2819,"children":2820},{},[2821],{"type":27,"value":2211},{"type":21,"tag":2204,"props":2823,"children":2824},{},[2825],{"type":21,"tag":42,"props":2826,"children":2827},{},[2828],{"type":27,"value":2219},{"type":21,"tag":2221,"props":2830,"children":2831},{},[2832,2848,2872,2894,2910,2926,2942,2958,2987,3015,3037,3059,3075,3091],{"type":21,"tag":2200,"props":2833,"children":2834},{},[2835,2843],{"type":21,"tag":2228,"props":2836,"children":2837},{},[2838],{"type":21,"tag":42,"props":2839,"children":2840},{},[2841],{"type":27,"value":2842},"Microsoft CA Compatibility Mode",{"type":21,"tag":2228,"props":2844,"children":2845},{},[2846],{"type":27,"value":2847},"❌ Root CA 不启用，仅适用于 Windows 证书颁发机构（AD CS）。",{"type":21,"tag":2200,"props":2849,"children":2850},{},[2851,2859],{"type":21,"tag":2228,"props":2852,"children":2853},{},[2854],{"type":21,"tag":42,"props":2855,"children":2856},{},[2857],{"type":27,"value":2858},"Authority Key ID",{"type":21,"tag":2228,"props":2860,"children":2861},{},[2862,2864,2870],{"type":27,"value":2863},"✅ 启用，并标记 ",{"type":21,"tag":141,"props":2865,"children":2867},{"className":2866},[],[2868],{"type":27,"value":2869},"Critical",{"type":27,"value":2871},"，用于标识 CRL 发行者。建议 Root CA 和中间 CA 都启用。",{"type":21,"tag":2200,"props":2873,"children":2874},{},[2875,2883],{"type":21,"tag":2228,"props":2876,"children":2877},{},[2878],{"type":21,"tag":42,"props":2879,"children":2880},{},[2881],{"type":27,"value":2882},"CRL Number",{"type":21,"tag":2228,"props":2884,"children":2885},{},[2886,2887,2892],{"type":27,"value":2863},{"type":21,"tag":141,"props":2888,"children":2890},{"className":2889},[],[2891],{"type":27,"value":2869},{"type":27,"value":2893},"，确保 CRL 版本唯一。建议 Root CA 和中间 CA 启用。",{"type":21,"tag":2200,"props":2895,"children":2896},{},[2897,2905],{"type":21,"tag":2228,"props":2898,"children":2899},{},[2900],{"type":21,"tag":42,"props":2901,"children":2902},{},[2903],{"type":27,"value":2904},"Issuing Distribution Point on CRLs",{"type":21,"tag":2228,"props":2906,"children":2907},{},[2908],{"type":27,"value":2909},"❌ Root CA 可不启用，仅适用于分层 CRL 结构的大规模 CA。",{"type":21,"tag":2200,"props":2911,"children":2912},{},[2913,2921],{"type":21,"tag":2228,"props":2914,"children":2915},{},[2916],{"type":21,"tag":42,"props":2917,"children":2918},{},[2919],{"type":27,"value":2920},"CA issuer URI",{"type":21,"tag":2228,"props":2922,"children":2923},{},[2924],{"type":27,"value":2925},"❌ 留空，证书下载后期由用户自行提供接口。",{"type":21,"tag":2200,"props":2927,"children":2928},{},[2929,2937],{"type":21,"tag":2228,"props":2930,"children":2931},{},[2932],{"type":21,"tag":42,"props":2933,"children":2934},{},[2935],{"type":27,"value":2936},"Keep expired certificates on CRL",{"type":21,"tag":2228,"props":2938,"children":2939},{},[2940],{"type":27,"value":2941},"❌ Root CA 不启用，中间 CA 视情况决定，启用后即使证书过期仍会出现在 CRL 中。",{"type":21,"tag":2200,"props":2943,"children":2944},{},[2945,2953],{"type":21,"tag":2228,"props":2946,"children":2947},{},[2948],{"type":21,"tag":42,"props":2949,"children":2950},{},[2951],{"type":27,"value":2952},"Use CRL partitions",{"type":21,"tag":2228,"props":2954,"children":2955},{},[2956],{"type":27,"value":2957},"❌ Root CA 负载小，不需要。适用于大规模证书管理的 CA。",{"type":21,"tag":2200,"props":2959,"children":2960},{},[2961,2969],{"type":21,"tag":2228,"props":2962,"children":2963},{},[2964],{"type":21,"tag":42,"props":2965,"children":2966},{},[2967],{"type":27,"value":2968},"CRL Expire Period",{"type":21,"tag":2228,"props":2970,"children":2971},{},[2972,2978,2980,2985],{"type":21,"tag":141,"props":2973,"children":2975},{"className":2974},[],[2976],{"type":27,"value":2977},"30d",{"type":27,"value":2979}," ✅ Root CA 设长一些，如 ",{"type":21,"tag":141,"props":2981,"children":2983},{"className":2982},[],[2984],{"type":27,"value":2977},{"type":27,"value":2986},"，中间 CA 采用较短的 CRL 过期时间。",{"type":21,"tag":2200,"props":2988,"children":2989},{},[2990,2998],{"type":21,"tag":2228,"props":2991,"children":2992},{},[2993],{"type":21,"tag":42,"props":2994,"children":2995},{},[2996],{"type":27,"value":2997},"CRL Issue Interval",{"type":21,"tag":2228,"props":2999,"children":3000},{},[3001,3007,3009,3014],{"type":21,"tag":141,"props":3002,"children":3004},{"className":3003},[],[3005],{"type":27,"value":3006},"7d",{"type":27,"value":3008}," ✅ 定期更新 CRL，建议活跃 CA 采用 ",{"type":21,"tag":141,"props":3010,"children":3012},{"className":3011},[],[3013],{"type":27,"value":3006},{"type":27,"value":1732},{"type":21,"tag":2200,"props":3016,"children":3017},{},[3018,3026],{"type":21,"tag":2228,"props":3019,"children":3020},{},[3021],{"type":21,"tag":42,"props":3022,"children":3023},{},[3024],{"type":27,"value":3025},"CRL Overlap Time",{"type":21,"tag":2228,"props":3027,"children":3028},{},[3029,3035],{"type":21,"tag":141,"props":3030,"children":3032},{"className":3031},[],[3033],{"type":27,"value":3034},"12h",{"type":27,"value":3036}," ✅ 旧 CRL 与新 CRL 重叠 12h，防止证书验证失败。",{"type":21,"tag":2200,"props":3038,"children":3039},{},[3040,3048],{"type":21,"tag":2228,"props":3041,"children":3042},{},[3043],{"type":21,"tag":42,"props":3044,"children":3045},{},[3046],{"type":27,"value":3047},"Delta CRL Period",{"type":21,"tag":2228,"props":3049,"children":3050},{},[3051,3057],{"type":21,"tag":141,"props":3052,"children":3054},{"className":3053},[],[3055],{"type":27,"value":3056},"0m",{"type":27,"value":3058}," ❌ Root CA 不使用 Delta CRL，只有对实时性要求高的 CA 才需要启用。",{"type":21,"tag":2200,"props":3060,"children":3061},{},[3062,3070],{"type":21,"tag":2228,"props":3063,"children":3064},{},[3065],{"type":21,"tag":42,"props":3066,"children":3067},{},[3068],{"type":27,"value":3069},"Generate CRL Upon Revocation",{"type":21,"tag":2228,"props":3071,"children":3072},{},[3073],{"type":27,"value":3074},"❌ Root CA 不启用，中间 CA 需要时启用，证书撤销后立即生成新的 CRL。",{"type":21,"tag":2200,"props":3076,"children":3077},{},[3078,3086],{"type":21,"tag":2228,"props":3079,"children":3080},{},[3081],{"type":21,"tag":42,"props":3082,"children":3083},{},[3084],{"type":27,"value":3085},"Allow changing revocation reason",{"type":21,"tag":2228,"props":3087,"children":3088},{},[3089],{"type":27,"value":3090},"✅ 启用，允许修改证书撤销原因。适用于所有 CA。",{"type":21,"tag":2200,"props":3092,"children":3093},{},[3094,3102],{"type":21,"tag":2228,"props":3095,"children":3096},{},[3097],{"type":21,"tag":42,"props":3098,"children":3099},{},[3100],{"type":27,"value":3101},"Allow invalidity date",{"type":21,"tag":2228,"props":3103,"children":3104},{},[3105],{"type":27,"value":3106},"✅ 启用，允许设置证书失效日期。适用于所有 CA。",{"type":21,"tag":65,"props":3108,"children":3109},{},[],{"type":21,"tag":170,"props":3111,"children":3113},{"id":3112},"_5️⃣-审批设置",[3114],{"type":27,"value":3115},"5️⃣ 审批设置",{"type":21,"tag":2192,"props":3117,"children":3118},{},[3119,3139],{"type":21,"tag":2196,"props":3120,"children":3121},{},[3122],{"type":21,"tag":2200,"props":3123,"children":3124},{},[3125,3132],{"type":21,"tag":2204,"props":3126,"children":3127},{},[3128],{"type":21,"tag":42,"props":3129,"children":3130},{},[3131],{"type":27,"value":2211},{"type":21,"tag":2204,"props":3133,"children":3134},{},[3135],{"type":21,"tag":42,"props":3136,"children":3137},{},[3138],{"type":27,"value":2219},{"type":21,"tag":2221,"props":3140,"children":3141},{},[3142,3163,3184,3205],{"type":21,"tag":2200,"props":3143,"children":3144},{},[3145,3153],{"type":21,"tag":2228,"props":3146,"children":3147},{},[3148],{"type":21,"tag":42,"props":3149,"children":3150},{},[3151],{"type":27,"value":3152},"Add\u002FEdit End Entity",{"type":21,"tag":2228,"props":3154,"children":3155},{},[3156,3161],{"type":21,"tag":141,"props":3157,"children":3159},{"className":3158},[],[3160],{"type":27,"value":2317},{"type":27,"value":3162}," ❌ Root CA 不管理终端实体",{"type":21,"tag":2200,"props":3164,"children":3165},{},[3166,3174],{"type":21,"tag":2228,"props":3167,"children":3168},{},[3169],{"type":21,"tag":42,"props":3170,"children":3171},{},[3172],{"type":27,"value":3173},"Key Recovery",{"type":21,"tag":2228,"props":3175,"children":3176},{},[3177,3182],{"type":21,"tag":141,"props":3178,"children":3180},{"className":3179},[],[3181],{"type":27,"value":2317},{"type":27,"value":3183}," ❌ Root CA 不提供密钥恢复",{"type":21,"tag":2200,"props":3185,"children":3186},{},[3187,3195],{"type":21,"tag":2228,"props":3188,"children":3189},{},[3190],{"type":21,"tag":42,"props":3191,"children":3192},{},[3193],{"type":27,"value":3194},"Revocation",{"type":21,"tag":2228,"props":3196,"children":3197},{},[3198,3203],{"type":21,"tag":141,"props":3199,"children":3201},{"className":3200},[],[3202],{"type":27,"value":2317},{"type":27,"value":3204}," ❌ Root CA 很少撤销自身证书",{"type":21,"tag":2200,"props":3206,"children":3207},{},[3208,3216],{"type":21,"tag":2228,"props":3209,"children":3210},{},[3211],{"type":21,"tag":42,"props":3212,"children":3213},{},[3214],{"type":27,"value":3215},"CA Service Activation",{"type":21,"tag":2228,"props":3217,"children":3218},{},[3219,3224],{"type":21,"tag":141,"props":3220,"children":3222},{"className":3221},[],[3223],{"type":27,"value":2317},{"type":27,"value":3225}," ❌ Root CA 手动激活",{"type":21,"tag":65,"props":3227,"children":3228},{},[],{"type":21,"tag":170,"props":3230,"children":3232},{"id":3231},"_6️⃣-其他数据",[3233],{"type":27,"value":3234},"6️⃣ 其他数据",{"type":21,"tag":2192,"props":3236,"children":3237},{},[3238,3258],{"type":21,"tag":2196,"props":3239,"children":3240},{},[3241],{"type":21,"tag":2200,"props":3242,"children":3243},{},[3244,3251],{"type":21,"tag":2204,"props":3245,"children":3246},{},[3247],{"type":21,"tag":42,"props":3248,"children":3249},{},[3250],{"type":27,"value":2211},{"type":21,"tag":2204,"props":3252,"children":3253},{},[3254],{"type":21,"tag":42,"props":3255,"children":3256},{},[3257],{"type":27,"value":2219},{"type":21,"tag":2221,"props":3259,"children":3260},{},[3261,3283,3299,3321],{"type":21,"tag":2200,"props":3262,"children":3263},{},[3264,3272],{"type":21,"tag":2228,"props":3265,"children":3266},{},[3267],{"type":21,"tag":42,"props":3268,"children":3269},{},[3270],{"type":27,"value":3271},"Validators",{"type":21,"tag":2228,"props":3273,"children":3274},{},[3275,3281],{"type":21,"tag":141,"props":3276,"children":3278},{"className":3277},[],[3279],{"type":27,"value":3280},"Finish User",{"type":27,"value":3282}," ✅ 启用证书验证策略。",{"type":21,"tag":2200,"props":3284,"children":3285},{},[3286,3294],{"type":21,"tag":2228,"props":3287,"children":3288},{},[3289],{"type":21,"tag":42,"props":3290,"children":3291},{},[3292],{"type":27,"value":3293},"CMP RA Authentication Secret",{"type":21,"tag":2228,"props":3295,"children":3296},{},[3297],{"type":27,"value":3298},"❌ 留空，仅在使用 CMP 协议时需要配置。",{"type":21,"tag":2200,"props":3300,"children":3301},{},[3302,3310],{"type":21,"tag":2228,"props":3303,"children":3304},{},[3305],{"type":21,"tag":42,"props":3306,"children":3307},{},[3308],{"type":27,"value":3309},"Monitor if CA active (healthcheck)",{"type":21,"tag":2228,"props":3311,"children":3312},{},[3313,3319],{"type":21,"tag":141,"props":3314,"children":3316},{"className":3315},[],[3317],{"type":27,"value":3318},"Activate",{"type":27,"value":3320}," ✅ 启用 CA 运行监控，适用于所有 CA。",{"type":21,"tag":2200,"props":3322,"children":3323},{},[3324,3332],{"type":21,"tag":2228,"props":3325,"children":3326},{},[3327],{"type":21,"tag":42,"props":3328,"children":3329},{},[3330],{"type":27,"value":3331},"Request Processor",{"type":21,"tag":2228,"props":3333,"children":3334},{},[3335,3340],{"type":21,"tag":141,"props":3336,"children":3338},{"className":3337},[],[3339],{"type":27,"value":2317},{"type":27,"value":3341}," ❌ Root CA 通常不需要外部请求处理。",{"type":21,"tag":65,"props":3343,"children":3344},{},[],{"type":21,"tag":170,"props":3346,"children":3348},{"id":3347},"_7️⃣-外部签名-ca-创建或更新externally-signed-ca-creationrenewal",[3349],{"type":27,"value":3350},"7️⃣ 外部签名 CA 创建或更新（Externally signed CA creation\u002Frenewal）",{"type":21,"tag":2192,"props":3352,"children":3353},{},[3354,3374],{"type":21,"tag":2196,"props":3355,"children":3356},{},[3357],{"type":21,"tag":2200,"props":3358,"children":3359},{},[3360,3367],{"type":21,"tag":2204,"props":3361,"children":3362},{},[3363],{"type":21,"tag":42,"props":3364,"children":3365},{},[3366],{"type":27,"value":2211},{"type":21,"tag":2204,"props":3368,"children":3369},{},[3370],{"type":21,"tag":42,"props":3371,"children":3372},{},[3373],{"type":27,"value":2219},{"type":21,"tag":2221,"props":3375,"children":3376},{},[3377,3393],{"type":21,"tag":2200,"props":3378,"children":3379},{},[3380,3388],{"type":21,"tag":2228,"props":3381,"children":3382},{},[3383],{"type":21,"tag":42,"props":3384,"children":3385},{},[3386],{"type":27,"value":3387},"Renew CA",{"type":21,"tag":2228,"props":3389,"children":3390},{},[3391],{"type":27,"value":3392},"❌ 建议创建新的 Root CA，而不是重新生成密钥并重新签名现有 CA，以避免同名 Root CA 证书带来的问题。",{"type":21,"tag":2200,"props":3394,"children":3395},{},[3396,3404],{"type":21,"tag":2228,"props":3397,"children":3398},{},[3399],{"type":21,"tag":42,"props":3400,"children":3401},{},[3402],{"type":27,"value":3403},"CA Chain Certificates",{"type":21,"tag":2228,"props":3405,"children":3406},{},[3407],{"type":27,"value":3408},"✅ 仅当 CA 由外部 CA 签名时才需要上传证书链文件（PEM\u002FDER 格式）。如果 Root CA 已安装在本地，则不需要上传此文件。",{"type":21,"tag":65,"props":3410,"children":3411},{},[],{"type":21,"tag":170,"props":3413,"children":3415},{"id":3414},"_8️⃣-完成-ca-创建",[3416],{"type":27,"value":3417},"8️⃣ 完成 CA 创建",{"type":21,"tag":36,"props":3419,"children":3420},{},[3421,3423,3427],{"type":27,"value":3422},"检查所有参数，确认无误后，点击 ",{"type":21,"tag":42,"props":3424,"children":3425},{},[3426],{"type":27,"value":2151},{"type":27,"value":3428}," 生成 CA。",{"type":21,"tag":36,"props":3430,"children":3431},{},[3432],{"type":21,"tag":42,"props":3433,"children":3434},{},[3435],{"type":27,"value":3436},"① 下载并验证 Root CA 证书：",{"type":21,"tag":36,"props":3438,"children":3439},{},[3440],{"type":27,"value":3441},"使用以下 OpenSSL 命令验证证书格式和有效性：",{"type":21,"tag":182,"props":3443,"children":3447},{"code":3444,"language":3445,"meta":7,"className":3446,"style":7},"# 验证 PEM 格式证书\nopenssl x509 -in rootca.pem -text -noout\n\n# 验证 DER 格式证书\nopenssl x509 -in rootca.der -inform DER -text -noout\n\n# 检查证书 SHA256 指纹信息\nopenssl x509 -noout -fingerprint -sha256 -in rootca.pem\n\n# 验证证书的有效性（自签名证书验证）\nopenssl verify -CAfile rootca.pem rootca.pem\n","sh","language-sh shiki shiki-themes github-light github-dark monokai",[3448],{"type":21,"tag":141,"props":3449,"children":3450},{"__ignoreMap":7},[3451,3459,3492,3499,3507,3545,3552,3560,3595,3602,3610],{"type":21,"tag":192,"props":3452,"children":3453},{"class":194,"line":195},[3454],{"type":21,"tag":192,"props":3455,"children":3456},{"style":683},[3457],{"type":27,"value":3458},"# 验证 PEM 格式证书\n",{"type":21,"tag":192,"props":3460,"children":3461},{"class":194,"line":222},[3462,3467,3472,3477,3482,3487],{"type":21,"tag":192,"props":3463,"children":3464},{"style":199},[3465],{"type":27,"value":3466},"openssl",{"type":21,"tag":192,"props":3468,"children":3469},{"style":205},[3470],{"type":27,"value":3471}," x509",{"type":21,"tag":192,"props":3473,"children":3474},{"style":211},[3475],{"type":27,"value":3476}," -in",{"type":21,"tag":192,"props":3478,"children":3479},{"style":205},[3480],{"type":27,"value":3481}," rootca.pem",{"type":21,"tag":192,"props":3483,"children":3484},{"style":211},[3485],{"type":27,"value":3486}," -text",{"type":21,"tag":192,"props":3488,"children":3489},{"style":211},[3490],{"type":27,"value":3491}," -noout\n",{"type":21,"tag":192,"props":3493,"children":3494},{"class":194,"line":270},[3495],{"type":21,"tag":192,"props":3496,"children":3497},{"emptyLinePlaceholder":692},[3498],{"type":27,"value":695},{"type":21,"tag":192,"props":3500,"children":3501},{"class":194,"line":279},[3502],{"type":21,"tag":192,"props":3503,"children":3504},{"style":683},[3505],{"type":27,"value":3506},"# 验证 DER 格式证书\n",{"type":21,"tag":192,"props":3508,"children":3509},{"class":194,"line":728},[3510,3514,3518,3522,3527,3532,3537,3541],{"type":21,"tag":192,"props":3511,"children":3512},{"style":199},[3513],{"type":27,"value":3466},{"type":21,"tag":192,"props":3515,"children":3516},{"style":205},[3517],{"type":27,"value":3471},{"type":21,"tag":192,"props":3519,"children":3520},{"style":211},[3521],{"type":27,"value":3476},{"type":21,"tag":192,"props":3523,"children":3524},{"style":205},[3525],{"type":27,"value":3526}," rootca.der",{"type":21,"tag":192,"props":3528,"children":3529},{"style":211},[3530],{"type":27,"value":3531}," -inform",{"type":21,"tag":192,"props":3533,"children":3534},{"style":205},[3535],{"type":27,"value":3536}," DER",{"type":21,"tag":192,"props":3538,"children":3539},{"style":211},[3540],{"type":27,"value":3486},{"type":21,"tag":192,"props":3542,"children":3543},{"style":211},[3544],{"type":27,"value":3491},{"type":21,"tag":192,"props":3546,"children":3547},{"class":194,"line":751},[3548],{"type":21,"tag":192,"props":3549,"children":3550},{"emptyLinePlaceholder":692},[3551],{"type":27,"value":695},{"type":21,"tag":192,"props":3553,"children":3554},{"class":194,"line":774},[3555],{"type":21,"tag":192,"props":3556,"children":3557},{"style":683},[3558],{"type":27,"value":3559},"# 检查证书 SHA256 指纹信息\n",{"type":21,"tag":192,"props":3561,"children":3562},{"class":194,"line":797},[3563,3567,3571,3576,3581,3586,3590],{"type":21,"tag":192,"props":3564,"children":3565},{"style":199},[3566],{"type":27,"value":3466},{"type":21,"tag":192,"props":3568,"children":3569},{"style":205},[3570],{"type":27,"value":3471},{"type":21,"tag":192,"props":3572,"children":3573},{"style":211},[3574],{"type":27,"value":3575}," -noout",{"type":21,"tag":192,"props":3577,"children":3578},{"style":211},[3579],{"type":27,"value":3580}," -fingerprint",{"type":21,"tag":192,"props":3582,"children":3583},{"style":211},[3584],{"type":27,"value":3585}," -sha256",{"type":21,"tag":192,"props":3587,"children":3588},{"style":211},[3589],{"type":27,"value":3476},{"type":21,"tag":192,"props":3591,"children":3592},{"style":205},[3593],{"type":27,"value":3594}," rootca.pem\n",{"type":21,"tag":192,"props":3596,"children":3597},{"class":194,"line":805},[3598],{"type":21,"tag":192,"props":3599,"children":3600},{"emptyLinePlaceholder":692},[3601],{"type":27,"value":695},{"type":21,"tag":192,"props":3603,"children":3604},{"class":194,"line":823},[3605],{"type":21,"tag":192,"props":3606,"children":3607},{"style":683},[3608],{"type":27,"value":3609},"# 验证证书的有效性（自签名证书验证）\n",{"type":21,"tag":192,"props":3611,"children":3612},{"class":194,"line":842},[3613,3617,3622,3627,3631],{"type":21,"tag":192,"props":3614,"children":3615},{"style":199},[3616],{"type":27,"value":3466},{"type":21,"tag":192,"props":3618,"children":3619},{"style":205},[3620],{"type":27,"value":3621}," verify",{"type":21,"tag":192,"props":3623,"children":3624},{"style":211},[3625],{"type":27,"value":3626}," -CAfile",{"type":21,"tag":192,"props":3628,"children":3629},{"style":205},[3630],{"type":27,"value":3481},{"type":21,"tag":192,"props":3632,"children":3633},{"style":205},[3634],{"type":27,"value":3594},{"type":21,"tag":36,"props":3636,"children":3637},{},[3638],{"type":21,"tag":42,"props":3639,"children":3640},{},[3641],{"type":27,"value":3642},"② 部署并验证 CRL（证书吊销列表）：",{"type":21,"tag":36,"props":3644,"children":3645},{},[3646],{"type":27,"value":3647},"若配置了 CRL URL，执行：",{"type":21,"tag":182,"props":3649,"children":3651},{"code":3650,"language":3445,"meta":7,"className":3446,"style":7},"# 验证 CRL 文件\nopenssl crl -in rootca.crl -text -noout\n",[3652],{"type":21,"tag":141,"props":3653,"children":3654},{"__ignoreMap":7},[3655,3663],{"type":21,"tag":192,"props":3656,"children":3657},{"class":194,"line":195},[3658],{"type":21,"tag":192,"props":3659,"children":3660},{"style":683},[3661],{"type":27,"value":3662},"# 验证 CRL 文件\n",{"type":21,"tag":192,"props":3664,"children":3665},{"class":194,"line":222},[3666,3670,3675,3679,3684,3688],{"type":21,"tag":192,"props":3667,"children":3668},{"style":199},[3669],{"type":27,"value":3466},{"type":21,"tag":192,"props":3671,"children":3672},{"style":205},[3673],{"type":27,"value":3674}," crl",{"type":21,"tag":192,"props":3676,"children":3677},{"style":211},[3678],{"type":27,"value":3476},{"type":21,"tag":192,"props":3680,"children":3681},{"style":205},[3682],{"type":27,"value":3683}," rootca.crl",{"type":21,"tag":192,"props":3685,"children":3686},{"style":211},[3687],{"type":27,"value":3486},{"type":21,"tag":192,"props":3689,"children":3690},{"style":211},[3691],{"type":27,"value":3491},{"type":21,"tag":36,"props":3693,"children":3694},{},[3695],{"type":27,"value":3696},"确保 CRL 可通过 Web 正常访问。",{"type":21,"tag":36,"props":3698,"children":3699},{},[3700,3702,3707],{"type":27,"value":3701},"🚀 ",{"type":21,"tag":42,"props":3703,"children":3704},{},[3705],{"type":27,"value":3706},"Root CA 现在已成功创建，可用于签发中间 CA！",{"type":27,"value":3708}," 🎉",{"type":21,"tag":150,"props":3710,"children":3712},{"id":3711},"_57-中间-ca-创建简要步骤案例",[3713],{"type":27,"value":3714},"5.7 中间 CA 创建简要步骤案例",{"type":21,"tag":170,"props":3716,"children":3718},{"id":3717},"_1️⃣-ca-类型与密钥配置-1",[3719],{"type":27,"value":2190},{"type":21,"tag":2192,"props":3721,"children":3722},{},[3723,3737],{"type":21,"tag":2196,"props":3724,"children":3725},{},[3726],{"type":21,"tag":2200,"props":3727,"children":3728},{},[3729,3733],{"type":21,"tag":2204,"props":3730,"children":3731},{},[3732],{"type":27,"value":2211},{"type":21,"tag":2204,"props":3734,"children":3735},{},[3736],{"type":27,"value":2219},{"type":21,"tag":2221,"props":3738,"children":3739},{},[3740,3757,3776,3793,3810,3827,3845],{"type":21,"tag":2200,"props":3741,"children":3742},{},[3743,3747],{"type":21,"tag":2228,"props":3744,"children":3745},{},[3746],{"type":27,"value":2235},{"type":21,"tag":2228,"props":3748,"children":3749},{},[3750,3755],{"type":21,"tag":141,"props":3751,"children":3753},{"className":3752},[],[3754],{"type":27,"value":2244},{"type":27,"value":3756}," ✅ 标准 X.509 证书 CA",{"type":21,"tag":2200,"props":3758,"children":3759},{},[3760,3764],{"type":21,"tag":2228,"props":3761,"children":3762},{},[3763],{"type":27,"value":1994},{"type":21,"tag":2228,"props":3765,"children":3766},{},[3767,3769,3774],{"type":27,"value":3768},"选择已创建的 Crypto Token ✅（如 ",{"type":21,"tag":141,"props":3770,"children":3772},{"className":3771},[],[3773],{"type":27,"value":2274},{"type":27,"value":3775},"）",{"type":21,"tag":2200,"props":3777,"children":3778},{},[3779,3783],{"type":21,"tag":2228,"props":3780,"children":3781},{},[3782],{"type":27,"value":2286},{"type":21,"tag":2228,"props":3784,"children":3785},{},[3786,3791],{"type":21,"tag":141,"props":3787,"children":3789},{"className":3788},[],[3790],{"type":27,"value":2295},{"type":27,"value":3792}," ✅ 更安全的签名算法",{"type":21,"tag":2200,"props":3794,"children":3795},{},[3796,3800],{"type":21,"tag":2228,"props":3797,"children":3798},{},[3799],{"type":27,"value":2308},{"type":21,"tag":2228,"props":3801,"children":3802},{},[3803,3808],{"type":21,"tag":141,"props":3804,"children":3806},{"className":3805},[],[3807],{"type":27,"value":2317},{"type":27,"value":3809}," ❌ 无需备用签名算法",{"type":21,"tag":2200,"props":3811,"children":3812},{},[3813,3817],{"type":21,"tag":2228,"props":3814,"children":3815},{},[3816],{"type":27,"value":2330},{"type":21,"tag":2228,"props":3818,"children":3819},{},[3820,3825],{"type":21,"tag":141,"props":3821,"children":3823},{"className":3822},[],[3824],{"type":27,"value":2339},{"type":27,"value":3826}," ✅ 用于 CA 证书序列号",{"type":21,"tag":2200,"props":3828,"children":3829},{},[3830,3834],{"type":21,"tag":2228,"props":3831,"children":3832},{},[3833],{"type":27,"value":2352},{"type":21,"tag":2228,"props":3835,"children":3836},{},[3837,3843],{"type":21,"tag":141,"props":3838,"children":3840},{"className":3839},[],[3841],{"type":27,"value":3842},"00001",{"type":27,"value":3844}," ✅ 初始序列号，与 Root CA 区分",{"type":21,"tag":2200,"props":3846,"children":3847},{},[3848,3852],{"type":21,"tag":2228,"props":3849,"children":3850},{},[3851],{"type":27,"value":2374},{"type":21,"tag":2228,"props":3853,"children":3854},{},[3855],{"type":27,"value":3856},"中间 CA 说明，可填写用途、管理单位等 ✅",{"type":21,"tag":65,"props":3858,"children":3859},{},[],{"type":21,"tag":170,"props":3861,"children":3863},{"id":3862},"_2️⃣-证书策略directives-1",[3864],{"type":27,"value":2388},{"type":21,"tag":2192,"props":3866,"children":3867},{},[3868,3882],{"type":21,"tag":2196,"props":3869,"children":3870},{},[3871],{"type":21,"tag":2200,"props":3872,"children":3873},{},[3874,3878],{"type":21,"tag":2204,"props":3875,"children":3876},{},[3877],{"type":27,"value":2211},{"type":21,"tag":2204,"props":3879,"children":3880},{},[3881],{"type":27,"value":2219},{"type":21,"tag":2221,"props":3883,"children":3884},{},[3885,3896,3908,3920,3932,3944,3955],{"type":21,"tag":2200,"props":3886,"children":3887},{},[3888,3892],{"type":21,"tag":2228,"props":3889,"children":3890},{},[3891],{"type":27,"value":2425},{"type":21,"tag":2228,"props":3893,"children":3894},{},[3895],{"type":27,"value":2430},{"type":21,"tag":2200,"props":3897,"children":3898},{},[3899,3903],{"type":21,"tag":2228,"props":3900,"children":3901},{},[3902],{"type":27,"value":2441},{"type":21,"tag":2228,"props":3904,"children":3905},{},[3906],{"type":27,"value":3907},"✅ 中间 CA 建议启用，保证安全",{"type":21,"tag":2200,"props":3909,"children":3910},{},[3911,3915],{"type":21,"tag":2228,"props":3912,"children":3913},{},[3914],{"type":27,"value":2457},{"type":21,"tag":2228,"props":3916,"children":3917},{},[3918],{"type":27,"value":3919},"✅ 确保 DN 唯一",{"type":21,"tag":2200,"props":3921,"children":3922},{},[3923,3927],{"type":21,"tag":2228,"props":3924,"children":3925},{},[3926],{"type":27,"value":2481},{"type":21,"tag":2228,"props":3928,"children":3929},{},[3930],{"type":27,"value":3931},"❌ 规模小于 20 个证书时可不启用",{"type":21,"tag":2200,"props":3933,"children":3934},{},[3935,3939],{"type":21,"tag":2228,"props":3936,"children":3937},{},[3938],{"type":27,"value":2497},{"type":21,"tag":2228,"props":3940,"children":3941},{},[3942],{"type":27,"value":3943},"✅ 记录证书请求历史",{"type":21,"tag":2200,"props":3945,"children":3946},{},[3947,3951],{"type":21,"tag":2228,"props":3948,"children":3949},{},[3950],{"type":27,"value":2513},{"type":21,"tag":2228,"props":3952,"children":3953},{},[3954],{"type":27,"value":2518},{"type":21,"tag":2200,"props":3956,"children":3957},{},[3958,3962],{"type":21,"tag":2228,"props":3959,"children":3960},{},[3961],{"type":27,"value":2529},{"type":21,"tag":2228,"props":3963,"children":3964},{},[3965],{"type":27,"value":2534},{"type":21,"tag":65,"props":3967,"children":3968},{},[],{"type":21,"tag":170,"props":3970,"children":3972},{"id":3971},"_3️⃣-证书数据ca-certificate-data-1",[3973],{"type":27,"value":2543},{"type":21,"tag":2192,"props":3975,"children":3976},{},[3977,3991],{"type":21,"tag":2196,"props":3978,"children":3979},{},[3980],{"type":21,"tag":2200,"props":3981,"children":3982},{},[3983,3987],{"type":21,"tag":2204,"props":3984,"children":3985},{},[3986],{"type":27,"value":2211},{"type":21,"tag":2204,"props":3988,"children":3989},{},[3990],{"type":27,"value":2219},{"type":21,"tag":2221,"props":3992,"children":3993},{},[3994,4013,4031,4049,4067,4079,4091,4102,4113,4125,4142,4154],{"type":21,"tag":2200,"props":3995,"children":3996},{},[3997,4001],{"type":21,"tag":2228,"props":3998,"children":3999},{},[4000],{"type":27,"value":2580},{"type":21,"tag":2228,"props":4002,"children":4003},{},[4004,4006,4012],{"type":27,"value":4005},"例如 ",{"type":21,"tag":141,"props":4007,"children":4009},{"className":4008},[],[4010],{"type":27,"value":4011},"CN=test Intermediate CA",{"type":27,"value":2591},{"type":21,"tag":2200,"props":4014,"children":4015},{},[4016,4020],{"type":21,"tag":2228,"props":4017,"children":4018},{},[4019],{"type":27,"value":2602},{"type":21,"tag":2228,"props":4021,"children":4022},{},[4023,4029],{"type":21,"tag":141,"props":4024,"children":4026},{"className":4025},[],[4027],{"type":27,"value":4028},"test EnterpriseIT Root CA",{"type":27,"value":4030}," ✅ 中间 CA 必须由 Root CA 签名",{"type":21,"tag":2200,"props":4032,"children":4033},{},[4034,4038],{"type":21,"tag":2228,"props":4035,"children":4036},{},[4037],{"type":27,"value":2624},{"type":21,"tag":2228,"props":4039,"children":4040},{},[4041,4047],{"type":21,"tag":141,"props":4042,"children":4044},{"className":4043},[],[4045],{"type":27,"value":4046},"INTERMEDIATE_CA_profile",{"type":27,"value":4048}," ✅ 克隆后配置适合中间 CA",{"type":21,"tag":2200,"props":4050,"children":4051},{},[4052,4056],{"type":21,"tag":2228,"props":4053,"children":4054},{},[4055],{"type":27,"value":2646},{"type":21,"tag":2228,"props":4057,"children":4058},{},[4059,4065],{"type":21,"tag":141,"props":4060,"children":4062},{"className":4061},[],[4063],{"type":27,"value":4064},"10y",{"type":27,"value":4066}," ✅ 通常为 10 年，有效期小于 Root CA",{"type":21,"tag":2200,"props":4068,"children":4069},{},[4070,4074],{"type":21,"tag":2228,"props":4071,"children":4072},{},[4073],{"type":27,"value":2668},{"type":21,"tag":2228,"props":4075,"children":4076},{},[4077],{"type":27,"value":4078},"❌ 中间 CA 通常不需要",{"type":21,"tag":2200,"props":4080,"children":4081},{},[4082,4086],{"type":21,"tag":2228,"props":4083,"children":4084},{},[4085],{"type":27,"value":2684},{"type":21,"tag":2228,"props":4087,"children":4088},{},[4089],{"type":27,"value":4090},"❌ 默认留空，或按需填写",{"type":21,"tag":2200,"props":4092,"children":4093},{},[4094,4098],{"type":21,"tag":2228,"props":4095,"children":4096},{},[4097],{"type":27,"value":2700},{"type":21,"tag":2228,"props":4099,"children":4100},{},[4101],{"type":27,"value":2705},{"type":21,"tag":2200,"props":4103,"children":4104},{},[4105,4109],{"type":21,"tag":2228,"props":4106,"children":4107},{},[4108],{"type":27,"value":2716},{"type":21,"tag":2228,"props":4110,"children":4111},{},[4112],{"type":27,"value":2721},{"type":21,"tag":2200,"props":4114,"children":4115},{},[4116,4120],{"type":21,"tag":2228,"props":4117,"children":4118},{},[4119],{"type":27,"value":2732},{"type":21,"tag":2228,"props":4121,"children":4122},{},[4123],{"type":27,"value":4124},"✅ 按 LDAP 规范排列 DN",{"type":21,"tag":2200,"props":4126,"children":4127},{},[4128,4132],{"type":21,"tag":2228,"props":4129,"children":4130},{},[4131],{"type":27,"value":2754},{"type":21,"tag":2228,"props":4133,"children":4134},{},[4135,4140],{"type":21,"tag":141,"props":4136,"children":4138},{"className":4137},[],[4139],{"type":27,"value":2763},{"type":27,"value":4141}," ✅ 推荐 20 字节",{"type":21,"tag":2200,"props":4143,"children":4144},{},[4145,4149],{"type":21,"tag":2228,"props":4146,"children":4147},{},[4148],{"type":27,"value":2776},{"type":21,"tag":2228,"props":4150,"children":4151},{},[4152],{"type":27,"value":4153},"❌ 默认禁用，留空",{"type":21,"tag":2200,"props":4155,"children":4156},{},[4157,4161],{"type":21,"tag":2228,"props":4158,"children":4159},{},[4160],{"type":27,"value":2792},{"type":21,"tag":2228,"props":4162,"children":4163},{},[4164],{"type":27,"value":4153},{"type":21,"tag":65,"props":4166,"children":4167},{},[],{"type":21,"tag":170,"props":4169,"children":4171},{"id":4170},"_4️⃣-crl-配置证书吊销列表-1",[4172],{"type":27,"value":2805},{"type":21,"tag":2192,"props":4174,"children":4175},{},[4176,4190],{"type":21,"tag":2196,"props":4177,"children":4178},{},[4179],{"type":21,"tag":2200,"props":4180,"children":4181},{},[4182,4186],{"type":21,"tag":2204,"props":4183,"children":4184},{},[4185],{"type":27,"value":2211},{"type":21,"tag":2204,"props":4187,"children":4188},{},[4189],{"type":27,"value":2219},{"type":21,"tag":2221,"props":4191,"children":4192},{},[4193,4205,4217,4228,4240,4252,4264,4276,4293,4311,4328,4345,4357,4369],{"type":21,"tag":2200,"props":4194,"children":4195},{},[4196,4200],{"type":21,"tag":2228,"props":4197,"children":4198},{},[4199],{"type":27,"value":2842},{"type":21,"tag":2228,"props":4201,"children":4202},{},[4203],{"type":27,"value":4204},"❌ 一般不启用，仅用于 Windows AD 环境",{"type":21,"tag":2200,"props":4206,"children":4207},{},[4208,4212],{"type":21,"tag":2228,"props":4209,"children":4210},{},[4211],{"type":27,"value":2858},{"type":21,"tag":2228,"props":4213,"children":4214},{},[4215],{"type":27,"value":4216},"✅ 启用，并标记为 Critical",{"type":21,"tag":2200,"props":4218,"children":4219},{},[4220,4224],{"type":21,"tag":2228,"props":4221,"children":4222},{},[4223],{"type":27,"value":2882},{"type":21,"tag":2228,"props":4225,"children":4226},{},[4227],{"type":27,"value":4216},{"type":21,"tag":2200,"props":4229,"children":4230},{},[4231,4235],{"type":21,"tag":2228,"props":4232,"children":4233},{},[4234],{"type":27,"value":2904},{"type":21,"tag":2228,"props":4236,"children":4237},{},[4238],{"type":27,"value":4239},"❌ 通常不启用",{"type":21,"tag":2200,"props":4241,"children":4242},{},[4243,4247],{"type":21,"tag":2228,"props":4244,"children":4245},{},[4246],{"type":27,"value":2920},{"type":21,"tag":2228,"props":4248,"children":4249},{},[4250],{"type":27,"value":4251},"❌ 留空，或按需填写下载地址",{"type":21,"tag":2200,"props":4253,"children":4254},{},[4255,4259],{"type":21,"tag":2228,"props":4256,"children":4257},{},[4258],{"type":27,"value":2936},{"type":21,"tag":2228,"props":4260,"children":4261},{},[4262],{"type":27,"value":4263},"❌ 中间 CA 建议启用，保留过期证书，目前不启用，会导致吊销列表越来越大",{"type":21,"tag":2200,"props":4265,"children":4266},{},[4267,4271],{"type":21,"tag":2228,"props":4268,"children":4269},{},[4270],{"type":27,"value":2952},{"type":21,"tag":2228,"props":4272,"children":4273},{},[4274],{"type":27,"value":4275},"❌ 通常不需要",{"type":21,"tag":2200,"props":4277,"children":4278},{},[4279,4283],{"type":21,"tag":2228,"props":4280,"children":4281},{},[4282],{"type":27,"value":2968},{"type":21,"tag":2228,"props":4284,"children":4285},{},[4286,4291],{"type":21,"tag":141,"props":4287,"children":4289},{"className":4288},[],[4290],{"type":27,"value":3006},{"type":27,"value":4292}," ✅ 建议 7 天，确保及时更新",{"type":21,"tag":2200,"props":4294,"children":4295},{},[4296,4300],{"type":21,"tag":2228,"props":4297,"children":4298},{},[4299],{"type":27,"value":2997},{"type":21,"tag":2228,"props":4301,"children":4302},{},[4303,4309],{"type":21,"tag":141,"props":4304,"children":4306},{"className":4305},[],[4307],{"type":27,"value":4308},"1d",{"type":27,"value":4310}," ✅ 每天发布，确保及时更新",{"type":21,"tag":2200,"props":4312,"children":4313},{},[4314,4318],{"type":21,"tag":2228,"props":4315,"children":4316},{},[4317],{"type":27,"value":3025},{"type":21,"tag":2228,"props":4319,"children":4320},{},[4321,4326],{"type":21,"tag":141,"props":4322,"children":4324},{"className":4323},[],[4325],{"type":27,"value":3034},{"type":27,"value":4327}," ✅ 与旧 CRL 重叠 12 小时，确保平稳过渡",{"type":21,"tag":2200,"props":4329,"children":4330},{},[4331,4335],{"type":21,"tag":2228,"props":4332,"children":4333},{},[4334],{"type":27,"value":3047},{"type":21,"tag":2228,"props":4336,"children":4337},{},[4338,4343],{"type":21,"tag":141,"props":4339,"children":4341},{"className":4340},[],[4342],{"type":27,"value":3056},{"type":27,"value":4344}," ❌ 不使用 Delta CRL",{"type":21,"tag":2200,"props":4346,"children":4347},{},[4348,4352],{"type":21,"tag":2228,"props":4349,"children":4350},{},[4351],{"type":27,"value":3069},{"type":21,"tag":2228,"props":4353,"children":4354},{},[4355],{"type":27,"value":4356},"✅ 启用，证书撤销后立即更新",{"type":21,"tag":2200,"props":4358,"children":4359},{},[4360,4364],{"type":21,"tag":2228,"props":4361,"children":4362},{},[4363],{"type":27,"value":3085},{"type":21,"tag":2228,"props":4365,"children":4366},{},[4367],{"type":27,"value":4368},"✅ 允许修改证书撤销原因",{"type":21,"tag":2200,"props":4370,"children":4371},{},[4372,4376],{"type":21,"tag":2228,"props":4373,"children":4374},{},[4375],{"type":27,"value":3101},{"type":21,"tag":2228,"props":4377,"children":4378},{},[4379],{"type":27,"value":4380},"✅ 允许设置证书失效日期",{"type":21,"tag":65,"props":4382,"children":4383},{},[],{"type":21,"tag":170,"props":4385,"children":4387},{"id":4386},"_5️⃣-默认-ca-验证数据default-ca-defined-validation-data",[4388],{"type":27,"value":4389},"5️⃣ 默认 CA 验证数据（Default CA defined validation data）",{"type":21,"tag":2192,"props":4391,"children":4392},{},[4393,4407],{"type":21,"tag":2196,"props":4394,"children":4395},{},[4396],{"type":21,"tag":2200,"props":4397,"children":4398},{},[4399,4403],{"type":21,"tag":2204,"props":4400,"children":4401},{},[4402],{"type":27,"value":2211},{"type":21,"tag":2204,"props":4404,"children":4405},{},[4406],{"type":27,"value":2219},{"type":21,"tag":2221,"props":4408,"children":4409},{},[4410,4423,4436,4448,4461],{"type":21,"tag":2200,"props":4411,"children":4412},{},[4413,4418],{"type":21,"tag":2228,"props":4414,"children":4415},{},[4416],{"type":27,"value":4417},"Default CRL Distribution Point",{"type":21,"tag":2228,"props":4419,"children":4420},{},[4421],{"type":27,"value":4422},"❌ 默认留空或按需填写，用于 CRL 分发地址",{"type":21,"tag":2200,"props":4424,"children":4425},{},[4426,4431],{"type":21,"tag":2228,"props":4427,"children":4428},{},[4429],{"type":27,"value":4430},"Default CRL Issuer",{"type":21,"tag":2228,"props":4432,"children":4433},{},[4434],{"type":27,"value":4435},"❌ 默认留空，通常无需填写",{"type":21,"tag":2200,"props":4437,"children":4438},{},[4439,4444],{"type":21,"tag":2228,"props":4440,"children":4441},{},[4442],{"type":27,"value":4443},"Default Freshest CRL Distribution Point",{"type":21,"tag":2228,"props":4445,"children":4446},{},[4447],{"type":27,"value":4435},{"type":21,"tag":2200,"props":4449,"children":4450},{},[4451,4456],{"type":21,"tag":2228,"props":4452,"children":4453},{},[4454],{"type":27,"value":4455},"OCSP Service Default URI",{"type":21,"tag":2228,"props":4457,"children":4458},{},[4459],{"type":27,"value":4460},"❌ 默认留空，按需填写 OCSP 地址",{"type":21,"tag":2200,"props":4462,"children":4463},{},[4464,4469],{"type":21,"tag":2228,"props":4465,"children":4466},{},[4467],{"type":27,"value":4468},"CA Issuer Default URI",{"type":21,"tag":2228,"props":4470,"children":4471},{},[4472],{"type":27,"value":4473},"❌ 默认留空或后期提供接口",{"type":21,"tag":65,"props":4475,"children":4476},{},[],{"type":21,"tag":170,"props":4478,"children":4480},{"id":4479},"_6️⃣-审批设置与其他数据",[4481],{"type":27,"value":4482},"6️⃣ 审批设置与其他数据",{"type":21,"tag":36,"props":4484,"children":4485},{},[4486,4488,4493],{"type":27,"value":4487},"审批设置目前只有",{"type":21,"tag":141,"props":4489,"children":4491},{"className":4490},[],[4492],{"type":27,"value":2317},{"type":27,"value":4494},"选项，表示无需额外审批流程，如需开启需检查 EJBCA 的全局审批策略，Supervision Fuctions。",{"type":21,"tag":2192,"props":4496,"children":4497},{},[4498,4512],{"type":21,"tag":2196,"props":4499,"children":4500},{},[4501],{"type":21,"tag":2200,"props":4502,"children":4503},{},[4504,4508],{"type":21,"tag":2204,"props":4505,"children":4506},{},[4507],{"type":27,"value":2211},{"type":21,"tag":2204,"props":4509,"children":4510},{},[4511],{"type":27,"value":2219},{"type":21,"tag":2221,"props":4513,"children":4514},{},[4515,4532,4544,4561],{"type":21,"tag":2200,"props":4516,"children":4517},{},[4518,4522],{"type":21,"tag":2228,"props":4519,"children":4520},{},[4521],{"type":27,"value":3271},{"type":21,"tag":2228,"props":4523,"children":4524},{},[4525,4530],{"type":21,"tag":141,"props":4526,"children":4528},{"className":4527},[],[4529],{"type":27,"value":3280},{"type":27,"value":4531}," ✅ 启用证书验证策略",{"type":21,"tag":2200,"props":4533,"children":4534},{},[4535,4539],{"type":21,"tag":2228,"props":4536,"children":4537},{},[4538],{"type":27,"value":3293},{"type":21,"tag":2228,"props":4540,"children":4541},{},[4542],{"type":27,"value":4543},"❌ 留空，仅在使用 CMP 协议时需要配置",{"type":21,"tag":2200,"props":4545,"children":4546},{},[4547,4551],{"type":21,"tag":2228,"props":4548,"children":4549},{},[4550],{"type":27,"value":3309},{"type":21,"tag":2228,"props":4552,"children":4553},{},[4554,4559],{"type":21,"tag":141,"props":4555,"children":4557},{"className":4556},[],[4558],{"type":27,"value":3318},{"type":27,"value":4560}," ✅ 启用运行监控",{"type":21,"tag":2200,"props":4562,"children":4563},{},[4564,4568],{"type":21,"tag":2228,"props":4565,"children":4566},{},[4567],{"type":27,"value":3331},{"type":21,"tag":2228,"props":4569,"children":4570},{},[4571,4576],{"type":21,"tag":141,"props":4572,"children":4574},{"className":4573},[],[4575],{"type":27,"value":2317},{"type":27,"value":4577}," ❌ 一般不需外部请求处理",{"type":21,"tag":65,"props":4579,"children":4580},{},[],{"type":21,"tag":170,"props":4582,"children":4584},{"id":4583},"_7️⃣-完成中间-ca-创建",[4585],{"type":27,"value":4586},"7️⃣ 完成中间 CA 创建",{"type":21,"tag":36,"props":4588,"children":4589},{},[4590,4591,4595],{"type":27,"value":3422},{"type":21,"tag":42,"props":4592,"children":4593},{},[4594],{"type":27,"value":2151},{"type":27,"value":4596}," 生成 CA 请求文件 (CSR)。",{"type":21,"tag":36,"props":4598,"children":4599},{},[4600],{"type":27,"value":4601},"提交 CSR 给 Root CA 签名后，下载签名后的证书并验证：",{"type":21,"tag":182,"props":4603,"children":4605},{"code":4604,"language":3445,"meta":7,"className":3446,"style":7},"openssl x509 -in intermediate_ca.pem -text -noout\nopenssl verify -CAfile rootca.pem intermediate_ca.pem\n",[4606],{"type":21,"tag":141,"props":4607,"children":4608},{"__ignoreMap":7},[4609,4637],{"type":21,"tag":192,"props":4610,"children":4611},{"class":194,"line":195},[4612,4616,4620,4624,4629,4633],{"type":21,"tag":192,"props":4613,"children":4614},{"style":199},[4615],{"type":27,"value":3466},{"type":21,"tag":192,"props":4617,"children":4618},{"style":205},[4619],{"type":27,"value":3471},{"type":21,"tag":192,"props":4621,"children":4622},{"style":211},[4623],{"type":27,"value":3476},{"type":21,"tag":192,"props":4625,"children":4626},{"style":205},[4627],{"type":27,"value":4628}," intermediate_ca.pem",{"type":21,"tag":192,"props":4630,"children":4631},{"style":211},[4632],{"type":27,"value":3486},{"type":21,"tag":192,"props":4634,"children":4635},{"style":211},[4636],{"type":27,"value":3491},{"type":21,"tag":192,"props":4638,"children":4639},{"class":194,"line":222},[4640,4644,4648,4652,4656],{"type":21,"tag":192,"props":4641,"children":4642},{"style":199},[4643],{"type":27,"value":3466},{"type":21,"tag":192,"props":4645,"children":4646},{"style":205},[4647],{"type":27,"value":3621},{"type":21,"tag":192,"props":4649,"children":4650},{"style":211},[4651],{"type":27,"value":3626},{"type":21,"tag":192,"props":4653,"children":4654},{"style":205},[4655],{"type":27,"value":3481},{"type":21,"tag":192,"props":4657,"children":4658},{"style":205},[4659],{"type":27,"value":4660}," intermediate_ca.pem\n",{"type":21,"tag":36,"props":4662,"children":4663},{},[4664],{"type":27,"value":4665},"🚀 中间 CA 已成功创建，可用于签发终端实体证书！🎉",{"type":21,"tag":65,"props":4667,"children":4668},{},[],{"type":21,"tag":29,"props":4670,"children":4672},{"id":4671},"_6-ra-普通用户创建与权限配置",[4673],{"type":27,"value":4674},"6. RA 普通用户创建与权限配置",{"type":21,"tag":150,"props":4676,"children":4678},{"id":4677},"_61-创建-ra-角色role",[4679],{"type":27,"value":4680},"6.1 创建 RA 角色（Role）",{"type":21,"tag":546,"props":4682,"children":4683},{},[4684,4702,4759,4798,4839,4870],{"type":21,"tag":54,"props":4685,"children":4686},{},[4687,4692,4694],{"type":21,"tag":42,"props":4688,"children":4689},{},[4690],{"type":27,"value":4691},"进入 RA 管理界面",{"type":27,"value":4693},"（RA Web），选择菜单：",{"type":21,"tag":182,"props":4695,"children":4697},{"code":4696},"Role Management →Roles →Create New Role\n",[4698],{"type":21,"tag":141,"props":4699,"children":4700},{"__ignoreMap":7},[4701],{"type":27,"value":4696},{"type":21,"tag":54,"props":4703,"children":4704},{},[4705,4710,4711],{"type":21,"tag":42,"props":4706,"children":4707},{},[4708],{"type":27,"value":4709},"填写角色信息",{"type":27,"value":651},{"type":21,"tag":2192,"props":4712,"children":4713},{},[4714,4730],{"type":21,"tag":2196,"props":4715,"children":4716},{},[4717],{"type":21,"tag":2200,"props":4718,"children":4719},{},[4720,4725],{"type":21,"tag":2204,"props":4721,"children":4722},{},[4723],{"type":27,"value":4724},"字段",{"type":21,"tag":2204,"props":4726,"children":4727},{},[4728],{"type":27,"value":4729},"推荐填写值",{"type":21,"tag":2221,"props":4731,"children":4732},{},[4733,4746],{"type":21,"tag":2200,"props":4734,"children":4735},{},[4736,4741],{"type":21,"tag":2228,"props":4737,"children":4738},{},[4739],{"type":27,"value":4740},"Namespace",{"type":21,"tag":2228,"props":4742,"children":4743},{},[4744],{"type":27,"value":4745},"No namespace",{"type":21,"tag":2200,"props":4747,"children":4748},{},[4749,4754],{"type":21,"tag":2228,"props":4750,"children":4751},{},[4752],{"type":27,"value":4753},"Role name",{"type":21,"tag":2228,"props":4755,"children":4756},{},[4757],{"type":27,"value":4758},"test RA Users",{"type":21,"tag":54,"props":4760,"children":4761},{},[4762,4767,4768],{"type":21,"tag":42,"props":4763,"children":4764},{},[4765],{"type":27,"value":4766},"设置 Certificate Authorities 权限",{"type":27,"value":651},{"type":21,"tag":50,"props":4769,"children":4770},{},[4771],{"type":21,"tag":54,"props":4772,"children":4773},{},[4774,4776,4782,4784,4790,4792,4797],{"type":27,"value":4775},"从Available列表选择对应CA（如",{"type":21,"tag":141,"props":4777,"children":4779},{"className":4778},[],[4780],{"type":27,"value":4781}," Intermediate CA",{"type":27,"value":4783},",",{"type":21,"tag":141,"props":4785,"children":4787},{"className":4786},[],[4788],{"type":27,"value":4789}," Root CA",{"type":27,"value":4791},"），点击",{"type":21,"tag":141,"props":4793,"children":4795},{"className":4794},[],[4796],{"type":27,"value":1831},{"type":27,"value":1732},{"type":21,"tag":54,"props":4799,"children":4800},{},[4801,4806,4808],{"type":21,"tag":42,"props":4802,"children":4803},{},[4804],{"type":27,"value":4805},"设置 End Entity 权限（permissions）",{"type":27,"value":4807},"（推荐配置）：",{"type":21,"tag":50,"props":4809,"children":4810},{},[4811,4816,4834],{"type":21,"tag":54,"props":4812,"children":4813},{},[4814],{"type":27,"value":4815},"✅ Create end entities",{"type":21,"tag":54,"props":4817,"children":4818},{},[4819,4821],{"type":27,"value":4820},"✅ Create certificates\n",{"type":21,"tag":50,"props":4822,"children":4823},{},[4824,4829],{"type":21,"tag":54,"props":4825,"children":4826},{},[4827],{"type":27,"value":4828},"✅ ...by using username and password",{"type":21,"tag":54,"props":4830,"children":4831},{},[4832],{"type":27,"value":4833},"✅ ...by using a request ID",{"type":21,"tag":54,"props":4835,"children":4836},{},[4837],{"type":27,"value":4838},"✅ View end entities and certificates",{"type":21,"tag":54,"props":4840,"children":4841},{},[4842,4847,4848],{"type":21,"tag":42,"props":4843,"children":4844},{},[4845],{"type":27,"value":4846},"设置 End Entity Profiles 权限",{"type":27,"value":651},{"type":21,"tag":50,"props":4849,"children":4850},{},[4851],{"type":21,"tag":54,"props":4852,"children":4853},{},[4854,4856,4862,4864,4869],{"type":27,"value":4855},"从 Available 列表选择",{"type":21,"tag":141,"props":4857,"children":4859},{"className":4858},[],[4860],{"type":27,"value":4861},"EMPTY",{"type":27,"value":4863},"，点击",{"type":21,"tag":141,"props":4865,"children":4867},{"className":4866},[],[4868],{"type":27,"value":1831},{"type":27,"value":1732},{"type":21,"tag":54,"props":4871,"children":4872},{},[4873,4875,4880],{"type":27,"value":4874},"点击",{"type":21,"tag":141,"props":4876,"children":4878},{"className":4877},[],[4879],{"type":27,"value":1831},{"type":27,"value":4881},"保存创建好的角色。",{"type":21,"tag":150,"props":4883,"children":4885},{"id":4884},"_62-创建-ra-普通用户-end-entity",[4886],{"type":27,"value":4887},"6.2 创建 RA 普通用户 (End Entity)",{"type":21,"tag":546,"props":4889,"children":4890},{},[4891,4909,5090],{"type":21,"tag":54,"props":4892,"children":4893},{},[4894,4899,4901],{"type":21,"tag":42,"props":4895,"children":4896},{},[4897],{"type":27,"value":4898},"进入 EJBCA Admin Web 界面",{"type":27,"value":4900},"，选择：",{"type":21,"tag":182,"props":4902,"children":4904},{"code":4903},"RA Functions → Add End Entity\n",[4905],{"type":21,"tag":141,"props":4906,"children":4907},{"__ignoreMap":7},[4908],{"type":27,"value":4903},{"type":21,"tag":54,"props":4910,"children":4911},{},[4912,4914],{"type":27,"value":4913},"填写用户详细信息：",{"type":21,"tag":2192,"props":4915,"children":4916},{},[4917,4931],{"type":21,"tag":2196,"props":4918,"children":4919},{},[4920],{"type":21,"tag":2200,"props":4921,"children":4922},{},[4923,4927],{"type":21,"tag":2204,"props":4924,"children":4925},{},[4926],{"type":27,"value":4724},{"type":21,"tag":2204,"props":4928,"children":4929},{},[4930],{"type":27,"value":4729},{"type":21,"tag":2221,"props":4932,"children":4933},{},[4934,4946,4959,4972,4984,4997,5015,5028,5041,5053,5064,5077],{"type":21,"tag":2200,"props":4935,"children":4936},{},[4937,4942],{"type":21,"tag":2228,"props":4938,"children":4939},{},[4940],{"type":27,"value":4941},"End Entity Profile",{"type":21,"tag":2228,"props":4943,"children":4944},{},[4945],{"type":27,"value":4861},{"type":21,"tag":2200,"props":4947,"children":4948},{},[4949,4954],{"type":21,"tag":2228,"props":4950,"children":4951},{},[4952],{"type":27,"value":4953},"Username",{"type":21,"tag":2228,"props":4955,"children":4956},{},[4957],{"type":27,"value":4958},"test_signuser",{"type":21,"tag":2200,"props":4960,"children":4961},{},[4962,4967],{"type":21,"tag":2228,"props":4963,"children":4964},{},[4965],{"type":27,"value":4966},"Password",{"type":21,"tag":2228,"props":4968,"children":4969},{},[4970],{"type":27,"value":4971},"123",{"type":21,"tag":2200,"props":4973,"children":4974},{},[4975,4980],{"type":21,"tag":2228,"props":4976,"children":4977},{},[4978],{"type":27,"value":4979},"Confirm Password",{"type":21,"tag":2228,"props":4981,"children":4982},{},[4983],{"type":27,"value":4971},{"type":21,"tag":2200,"props":4985,"children":4986},{},[4987,4992],{"type":21,"tag":2228,"props":4988,"children":4989},{},[4990],{"type":27,"value":4991},"Batch generation",{"type":21,"tag":2228,"props":4993,"children":4994},{},[4995],{"type":27,"value":4996},"不勾选",{"type":21,"tag":2200,"props":4998,"children":4999},{},[5000,5005],{"type":21,"tag":2228,"props":5001,"children":5002},{},[5003],{"type":27,"value":5004},"E-mail",{"type":21,"tag":2228,"props":5006,"children":5007},{},[5008],{"type":21,"tag":5009,"props":5010,"children":5012},"a",{"href":5011},"mailto:cert-user@example.com",[5013],{"type":27,"value":5014},"cert-user@example.com",{"type":21,"tag":2200,"props":5016,"children":5017},{},[5018,5023],{"type":21,"tag":2228,"props":5019,"children":5020},{},[5021],{"type":27,"value":5022},"CN",{"type":21,"tag":2228,"props":5024,"children":5025},{},[5026],{"type":27,"value":5027},"test RA user S1",{"type":21,"tag":2200,"props":5029,"children":5030},{},[5031,5036],{"type":21,"tag":2228,"props":5032,"children":5033},{},[5034],{"type":27,"value":5035},"O",{"type":21,"tag":2228,"props":5037,"children":5038},{},[5039],{"type":27,"value":5040},"test",{"type":21,"tag":2200,"props":5042,"children":5043},{},[5044,5049],{"type":21,"tag":2228,"props":5045,"children":5046},{},[5047],{"type":27,"value":5048},"C",{"type":21,"tag":2228,"props":5050,"children":5051},{},[5052],{"type":27,"value":5022},{"type":21,"tag":2200,"props":5054,"children":5055},{},[5056,5060],{"type":21,"tag":2228,"props":5057,"children":5058},{},[5059],{"type":27,"value":2624},{"type":21,"tag":2228,"props":5061,"children":5062},{},[5063],{"type":27,"value":1799},{"type":21,"tag":2200,"props":5065,"children":5066},{},[5067,5072],{"type":21,"tag":2228,"props":5068,"children":5069},{},[5070],{"type":27,"value":5071},"CA",{"type":21,"tag":2228,"props":5073,"children":5074},{},[5075],{"type":27,"value":5076},"test Intermediate CA",{"type":21,"tag":2200,"props":5078,"children":5079},{},[5080,5085],{"type":21,"tag":2228,"props":5081,"children":5082},{},[5083],{"type":27,"value":5084},"Token",{"type":21,"tag":2228,"props":5086,"children":5087},{},[5088],{"type":27,"value":5089},"P12 file",{"type":21,"tag":54,"props":5091,"children":5092},{},[5093,5094,5099],{"type":27,"value":4874},{"type":21,"tag":141,"props":5095,"children":5097},{"className":5096},[],[5098],{"type":27,"value":1831},{"type":27,"value":5100},"，完成 End Entity 创建。",{"type":21,"tag":150,"props":5102,"children":5104},{"id":5103},"_63-用户证书下载",[5105],{"type":27,"value":5106},"6.3 用户证书下载",{"type":21,"tag":546,"props":5108,"children":5109},{},[5110,5129,5157],{"type":21,"tag":54,"props":5111,"children":5112},{},[5113,5115,5120,5121],{"type":27,"value":5114},"用户进入",{"type":21,"tag":42,"props":5116,"children":5117},{},[5118],{"type":27,"value":5119},"RA Web 界面",{"type":27,"value":4900},{"type":21,"tag":182,"props":5122,"children":5124},{"code":5123},"Enroll → Use Username\n",[5125],{"type":21,"tag":141,"props":5126,"children":5127},{"__ignoreMap":7},[5128],{"type":27,"value":5123},{"type":21,"tag":54,"props":5130,"children":5131},{},[5132,5134],{"type":27,"value":5133},"使用刚创建的用户名和密码登录：",{"type":21,"tag":50,"props":5135,"children":5136},{},[5137,5147],{"type":21,"tag":54,"props":5138,"children":5139},{},[5140,5142],{"type":27,"value":5141},"Username: ",{"type":21,"tag":141,"props":5143,"children":5145},{"className":5144},[],[5146],{"type":27,"value":4958},{"type":21,"tag":54,"props":5148,"children":5149},{},[5150,5152],{"type":27,"value":5151},"Password: ",{"type":21,"tag":141,"props":5153,"children":5155},{"className":5154},[],[5156],{"type":27,"value":4971},{"type":21,"tag":54,"props":5158,"children":5159},{},[5160,5162],{"type":27,"value":5161},"登录后选择密钥算法：",{"type":21,"tag":50,"props":5163,"children":5164},{},[5165],{"type":21,"tag":54,"props":5166,"children":5167},{},[5168,5170,5175,5177,5182],{"type":27,"value":5169},"选择",{"type":21,"tag":141,"props":5171,"children":5173},{"className":5172},[],[5174],{"type":27,"value":1682},{"type":27,"value":5176},"算法，生成并下载",{"type":21,"tag":141,"props":5178,"children":5180},{"className":5179},[],[5181],{"type":27,"value":1198},{"type":27,"value":5183},"用户证书。",{"type":21,"tag":150,"props":5185,"children":5187},{"id":5186},"_64-将用户加入-ra-角色",[5188],{"type":27,"value":5189},"6.4 将用户加入 RA 角色",{"type":21,"tag":546,"props":5191,"children":5192},{},[5193,5206,5211,5224,5323,5334],{"type":21,"tag":54,"props":5194,"children":5195},{},[5196,5198],{"type":27,"value":5197},"进入 RA Web 界面，选择菜单：",{"type":21,"tag":182,"props":5199,"children":5201},{"code":5200},"Search → End Entities\n",[5202],{"type":21,"tag":141,"props":5203,"children":5204},{"__ignoreMap":7},[5205],{"type":27,"value":5200},{"type":21,"tag":54,"props":5207,"children":5208},{},[5209],{"type":27,"value":5210},"查找并复制刚才创建证书的 CN 。",{"type":21,"tag":54,"props":5212,"children":5213},{},[5214,5216],{"type":27,"value":5215},"进入 RA 管理界面，选择菜单：",{"type":21,"tag":182,"props":5217,"children":5219},{"code":5218},"Role Management → Roles → Members → Add Role Member\n",[5220],{"type":21,"tag":141,"props":5221,"children":5222},{"__ignoreMap":7},[5223],{"type":27,"value":5218},{"type":21,"tag":54,"props":5225,"children":5226},{},[5227,5229],{"type":27,"value":5228},"填写 Role Member 信息：",{"type":21,"tag":2192,"props":5230,"children":5231},{},[5232,5246],{"type":21,"tag":2196,"props":5233,"children":5234},{},[5235],{"type":21,"tag":2200,"props":5236,"children":5237},{},[5238,5242],{"type":21,"tag":2204,"props":5239,"children":5240},{},[5241],{"type":27,"value":4724},{"type":21,"tag":2204,"props":5243,"children":5244},{},[5245],{"type":27,"value":4729},{"type":21,"tag":2221,"props":5247,"children":5248},{},[5249,5261,5274,5285,5298,5311],{"type":21,"tag":2200,"props":5250,"children":5251},{},[5252,5257],{"type":21,"tag":2228,"props":5253,"children":5254},{},[5255],{"type":27,"value":5256},"Role",{"type":21,"tag":2228,"props":5258,"children":5259},{},[5260],{"type":27,"value":4758},{"type":21,"tag":2200,"props":5262,"children":5263},{},[5264,5269],{"type":21,"tag":2228,"props":5265,"children":5266},{},[5267],{"type":27,"value":5268},"Token Type",{"type":21,"tag":2228,"props":5270,"children":5271},{},[5272],{"type":27,"value":5273},"Certificate",{"type":21,"tag":2200,"props":5275,"children":5276},{},[5277,5281],{"type":21,"tag":2228,"props":5278,"children":5279},{},[5280],{"type":27,"value":5071},{"type":21,"tag":2228,"props":5282,"children":5283},{},[5284],{"type":27,"value":5076},{"type":21,"tag":2200,"props":5286,"children":5287},{},[5288,5293],{"type":21,"tag":2228,"props":5289,"children":5290},{},[5291],{"type":27,"value":5292},"Match with",{"type":21,"tag":2228,"props":5294,"children":5295},{},[5296],{"type":27,"value":5297},"CN Common Name",{"type":21,"tag":2200,"props":5299,"children":5300},{},[5301,5306],{"type":21,"tag":2228,"props":5302,"children":5303},{},[5304],{"type":27,"value":5305},"Match Value",{"type":21,"tag":2228,"props":5307,"children":5308},{},[5309],{"type":27,"value":5310},"粘贴刚复制的证书 CN",{"type":21,"tag":2200,"props":5312,"children":5313},{},[5314,5318],{"type":21,"tag":2228,"props":5315,"children":5316},{},[5317],{"type":27,"value":2374},{"type":21,"tag":2228,"props":5319,"children":5320},{},[5321],{"type":27,"value":5322},"RA 普通用户",{"type":21,"tag":54,"props":5324,"children":5325},{},[5326,5327,5332],{"type":27,"value":4874},{"type":21,"tag":141,"props":5328,"children":5330},{"className":5329},[],[5331],{"type":27,"value":1831},{"type":27,"value":5333},"，完成角色成员添加。",{"type":21,"tag":54,"props":5335,"children":5336},{},[5337,5342,5344],{"type":21,"tag":42,"props":5338,"children":5339},{},[5340],{"type":27,"value":5341},"重启 EJBCA 服务",{"type":27,"value":5343},"，使权限生效（推荐）：",{"type":21,"tag":182,"props":5345,"children":5347},{"code":5346,"language":435,"meta":7,"className":436,"style":7},"docker restart ejbca\n",[5348],{"type":21,"tag":141,"props":5349,"children":5350},{"__ignoreMap":7},[5351],{"type":21,"tag":192,"props":5352,"children":5353},{"class":194,"line":195},[5354,5358,5362],{"type":21,"tag":192,"props":5355,"children":5356},{"style":199},[5357],{"type":27,"value":400},{"type":21,"tag":192,"props":5359,"children":5360},{"style":205},[5361],{"type":27,"value":331},{"type":21,"tag":192,"props":5363,"children":5364},{"style":205},[5365],{"type":27,"value":5366}," ejbca\n",{"type":21,"tag":150,"props":5368,"children":5370},{"id":5369},"_65-用户登录-ra-界面",[5371],{"type":27,"value":5372},"6.5 用户登录 RA 界面",{"type":21,"tag":546,"props":5374,"children":5375},{},[5376,5393,5398],{"type":21,"tag":54,"props":5377,"children":5378},{},[5379,5384,5386,5391],{"type":21,"tag":42,"props":5380,"children":5381},{},[5382],{"type":27,"value":5383},"非管理员角色",{"type":27,"value":5385},"将下载的",{"type":21,"tag":141,"props":5387,"children":5389},{"className":5388},[],[5390],{"type":27,"value":1198},{"type":27,"value":5392},"证书导入浏览器。",{"type":21,"tag":54,"props":5394,"children":5395},{},[5396],{"type":27,"value":5397},"访问 RA Web 界面，自动认证并登录。",{"type":21,"tag":54,"props":5399,"children":5400},{},[5401],{"type":27,"value":5402},"用户即可执行授权内的 RA 操作（如创建和查看证书等）。",{"type":21,"tag":150,"props":5404,"children":5406},{"id":5405},"_66-重要提示请务必遵守以下要求",[5407],{"type":27,"value":5408},"6.6 重要提示（请务必遵守以下要求）",{"type":21,"tag":36,"props":5410,"children":5411},{},[5412,5413,5418,5419,5425],{"type":27,"value":1637},{"type":21,"tag":42,"props":5414,"children":5415},{},[5416],{"type":27,"value":5417},"第一次建议使用 chrome 浏览器无痕模式快速启动验证",{"type":27,"value":1725},{"type":21,"tag":141,"props":5420,"children":5422},{"className":5421},[],[5423],{"type":27,"value":5424},"No OAuth providers configured. Please log in using a valid certificate.",{"type":27,"value":1732},{"type":21,"tag":36,"props":5427,"children":5428},{},[5429,5430,5435,5437,5443,5445,5450],{"type":27,"value":1637},{"type":21,"tag":42,"props":5431,"children":5432},{},[5433],{"type":27,"value":5434},"访问时候 使用 https 访问",{"type":27,"value":5436},"，",{"type":21,"tag":141,"props":5438,"children":5440},{"className":5439},[],[5441],{"type":27,"value":5442},"https:\u002F\u002F192.168.xxx.xxx\u002Fejbca\u002Fra\u002F",{"type":27,"value":5444},",避免出现",{"type":21,"tag":141,"props":5446,"children":5448},{"className":5447},[],[5449],{"type":27,"value":5424},{"type":27,"value":1732},{"type":21,"tag":65,"props":5452,"children":5453},{},[],{"type":21,"tag":29,"props":5455,"children":5457},{"id":5456},"_7-证书模板设置说明",[5458],{"type":27,"value":5459},"7. 证书模板设置说明",{"type":21,"tag":36,"props":5461,"children":5462},{},[5463],{"type":27,"value":5464},"本节用于解释 EJBCA 中终端证书模板（Certificate Profile）设置项的具体含义及推荐用途，适用于 HTTPS\u002FWeb\u002F设备\u002F客户端等常见终端证书签发需求。",{"type":21,"tag":65,"props":5466,"children":5467},{},[],{"type":21,"tag":150,"props":5469,"children":5471},{"id":5470},"_71-基本信息",[5472],{"type":27,"value":5473},"7.1 基本信息",{"type":21,"tag":2192,"props":5475,"children":5476},{},[5477,5493],{"type":21,"tag":2196,"props":5478,"children":5479},{},[5480],{"type":21,"tag":2200,"props":5481,"children":5482},{},[5483,5488],{"type":21,"tag":2204,"props":5484,"children":5485},{},[5486],{"type":27,"value":5487},"配置项",{"type":21,"tag":2204,"props":5489,"children":5490},{},[5491],{"type":27,"value":5492},"描述",{"type":21,"tag":2221,"props":5494,"children":5495},{},[5496,5512,5528,5544,5560,5576,5592,5608,5624,5640,5656],{"type":21,"tag":2200,"props":5497,"children":5498},{},[5499,5507],{"type":21,"tag":2228,"props":5500,"children":5501},{},[5502],{"type":21,"tag":42,"props":5503,"children":5504},{},[5505],{"type":27,"value":5506},"Certificate Profile ID",{"type":21,"tag":2228,"props":5508,"children":5509},{},[5510],{"type":27,"value":5511},"模板在数据库中的唯一标识，仅供系统内部识别",{"type":21,"tag":2200,"props":5513,"children":5514},{},[5515,5523],{"type":21,"tag":2228,"props":5516,"children":5517},{},[5518],{"type":21,"tag":42,"props":5519,"children":5520},{},[5521],{"type":27,"value":5522},"类型",{"type":21,"tag":2228,"props":5524,"children":5525},{},[5526],{"type":27,"value":5527},"可用终端实体，子 CA，根 CA",{"type":21,"tag":2200,"props":5529,"children":5530},{},[5531,5539],{"type":21,"tag":2228,"props":5532,"children":5533},{},[5534],{"type":21,"tag":42,"props":5535,"children":5536},{},[5537],{"type":27,"value":5538},"Available Key Algorithms",{"type":21,"tag":2228,"props":5540,"children":5541},{},[5542],{"type":27,"value":5543},"可用密钥算法，如 RSA、ECDSA、Ed25519、 DILITHIUM 等",{"type":21,"tag":2200,"props":5545,"children":5546},{},[5547,5555],{"type":21,"tag":2228,"props":5548,"children":5549},{},[5550],{"type":21,"tag":42,"props":5551,"children":5552},{},[5553],{"type":27,"value":5554},"Available ECDSA curves",{"type":21,"tag":2228,"props":5556,"children":5557},{},[5558],{"type":27,"value":5559},"ECDSA 可选曲线，当前未启用任何曲线",{"type":21,"tag":2200,"props":5561,"children":5562},{},[5563,5571],{"type":21,"tag":2228,"props":5564,"children":5565},{},[5566],{"type":21,"tag":42,"props":5567,"children":5568},{},[5569],{"type":27,"value":5570},"可用位长度",{"type":21,"tag":2228,"props":5572,"children":5573},{},[5574],{"type":27,"value":5575},"支持的密钥位数（针对 RSA），如 2048、4096 等",{"type":21,"tag":2200,"props":5577,"children":5578},{},[5579,5587],{"type":21,"tag":2228,"props":5580,"children":5581},{},[5582],{"type":21,"tag":42,"props":5583,"children":5584},{},[5585],{"type":27,"value":5586},"签名算法",{"type":21,"tag":2228,"props":5588,"children":5589},{},[5590],{"type":27,"value":5591},"用于签发证书时的签名哈希算法，如 SHA3-256withRSA",{"type":21,"tag":2200,"props":5593,"children":5594},{},[5595,5603],{"type":21,"tag":2228,"props":5596,"children":5597},{},[5598],{"type":21,"tag":42,"props":5599,"children":5600},{},[5601],{"type":27,"value":5602},"Alternative Signature",{"type":21,"tag":2228,"props":5604,"children":5605},{},[5606],{"type":27,"value":5607},"是否启用替代签名算法，如 ECDSA, EdDSA 等",{"type":21,"tag":2200,"props":5609,"children":5610},{},[5611,5619],{"type":21,"tag":2228,"props":5612,"children":5613},{},[5614],{"type":21,"tag":42,"props":5615,"children":5616},{},[5617],{"type":27,"value":5618},"有效期 or end date of the certificate",{"type":21,"tag":2228,"props":5620,"children":5621},{},[5622],{"type":27,"value":5623},"默认有效期，如 \"2y\" 表示 2 年",{"type":21,"tag":2200,"props":5625,"children":5626},{},[5627,5635],{"type":21,"tag":2228,"props":5628,"children":5629},{},[5630],{"type":21,"tag":42,"props":5631,"children":5632},{},[5633],{"type":27,"value":5634},"Validity Offset",{"type":21,"tag":2228,"props":5636,"children":5637},{},[5638],{"type":27,"value":5639},"签发日期的偏移量，允许向前或向后设定起始时间",{"type":21,"tag":2200,"props":5641,"children":5642},{},[5643,5651],{"type":21,"tag":2228,"props":5644,"children":5645},{},[5646],{"type":21,"tag":42,"props":5647,"children":5648},{},[5649],{"type":27,"value":5650},"Expiration Restrictions",{"type":21,"tag":2228,"props":5652,"children":5653},{},[5654],{"type":27,"value":5655},"限制最大到期时间，用于合规控制",{"type":21,"tag":2200,"props":5657,"children":5658},{},[5659,5667],{"type":21,"tag":2228,"props":5660,"children":5661},{},[5662],{"type":21,"tag":42,"props":5663,"children":5664},{},[5665],{"type":27,"value":5666},"Profile Description",{"type":21,"tag":2228,"props":5668,"children":5669},{},[5670],{"type":27,"value":5671},"证书模板说明，用于备注用途（如“终端设备证书”）",{"type":21,"tag":65,"props":5673,"children":5674},{},[],{"type":21,"tag":150,"props":5676,"children":5678},{"id":5677},"_72-权限控制permissions",[5679],{"type":27,"value":5680},"7.2 权限控制（Permissions）",{"type":21,"tag":2192,"props":5682,"children":5683},{},[5684,5703],{"type":21,"tag":2196,"props":5685,"children":5686},{},[5687],{"type":21,"tag":2200,"props":5688,"children":5689},{},[5690,5694,5698],{"type":21,"tag":2204,"props":5691,"children":5692},{},[5693],{"type":27,"value":5487},{"type":21,"tag":2204,"props":5695,"children":5696},{},[5697],{"type":27,"value":5492},{"type":21,"tag":2204,"props":5699,"children":5700},{},[5701],{"type":27,"value":5702},"推荐设置",{"type":21,"tag":2221,"props":5704,"children":5705},{},[5706,5724,5742,5760,5778,5796,5814,5832,5850,5867],{"type":21,"tag":2200,"props":5707,"children":5708},{},[5709,5714,5719],{"type":21,"tag":2228,"props":5710,"children":5711},{},[5712],{"type":27,"value":5713},"Allow Validity Override",{"type":21,"tag":2228,"props":5715,"children":5716},{},[5717],{"type":27,"value":5718},"允许在签发证书时覆盖默认有效期",{"type":21,"tag":2228,"props":5720,"children":5721},{},[5722],{"type":27,"value":5723},"✅，如需手动调整有效期时使用",{"type":21,"tag":2200,"props":5725,"children":5726},{},[5727,5732,5737],{"type":21,"tag":2228,"props":5728,"children":5729},{},[5730],{"type":27,"value":5731},"Allow Expired Validity End Date",{"type":21,"tag":2228,"props":5733,"children":5734},{},[5735],{"type":27,"value":5736},"允许设置一个已过期的结束时间（用于测试或审计）",{"type":21,"tag":2228,"props":5738,"children":5739},{},[5740],{"type":27,"value":5741},"✅（调试用）",{"type":21,"tag":2200,"props":5743,"children":5744},{},[5745,5750,5755],{"type":21,"tag":2228,"props":5746,"children":5747},{},[5748],{"type":27,"value":5749},"Allow Extension Override",{"type":21,"tag":2228,"props":5751,"children":5752},{},[5753],{"type":27,"value":5754},"允许 CSR 中的扩展字段覆盖模板中预定义的扩展",{"type":21,"tag":2228,"props":5756,"children":5757},{},[5758],{"type":27,"value":5759},"❌，若开启会破坏模板统一性，可能引入风险",{"type":21,"tag":2200,"props":5761,"children":5762},{},[5763,5768,5773],{"type":21,"tag":2228,"props":5764,"children":5765},{},[5766],{"type":27,"value":5767},"Allow certificate serial number override",{"type":21,"tag":2228,"props":5769,"children":5770},{},[5771],{"type":27,"value":5772},"允许在签发时自定义证书序列号",{"type":21,"tag":2228,"props":5774,"children":5775},{},[5776],{"type":27,"value":5777},"❌，仅特定需求下开启（如证书克隆、替换）",{"type":21,"tag":2200,"props":5779,"children":5780},{},[5781,5786,5791],{"type":21,"tag":2228,"props":5782,"children":5783},{},[5784],{"type":27,"value":5785},"Allow Subject DN Override by CSR",{"type":21,"tag":2228,"props":5787,"children":5788},{},[5789],{"type":27,"value":5790},"允许 CSR 中的主题信息（如 CN\u002FO）覆盖模板配置",{"type":21,"tag":2228,"props":5792,"children":5793},{},[5794],{"type":27,"value":5795},"✅，适用于自动化签发流程",{"type":21,"tag":2200,"props":5797,"children":5798},{},[5799,5804,5809],{"type":21,"tag":2228,"props":5800,"children":5801},{},[5802],{"type":27,"value":5803},"Allow Subject DN Override by End Entity Information",{"type":21,"tag":2228,"props":5805,"children":5806},{},[5807],{"type":27,"value":5808},"允许通过终端实体信息（用户输入）指定 Subject 字段",{"type":21,"tag":2228,"props":5810,"children":5811},{},[5812],{"type":27,"value":5813},"✅，灵活性高，推荐开启",{"type":21,"tag":2200,"props":5815,"children":5816},{},[5817,5822,5827],{"type":21,"tag":2228,"props":5818,"children":5819},{},[5820],{"type":27,"value":5821},"Allow Key Usage Override",{"type":21,"tag":2228,"props":5823,"children":5824},{},[5825],{"type":27,"value":5826},"允许 CSR 中设置 keyUsage 字段覆盖模板配置",{"type":21,"tag":2228,"props":5828,"children":5829},{},[5830],{"type":27,"value":5831},"❌，开启会造成用途不一致，影响安全性",{"type":21,"tag":2200,"props":5833,"children":5834},{},[5835,5840,5845],{"type":21,"tag":2228,"props":5836,"children":5837},{},[5838],{"type":27,"value":5839},"Allow Backdated Revocation",{"type":21,"tag":2228,"props":5841,"children":5842},{},[5843],{"type":27,"value":5844},"允许将吊销时间设置为历史时间，用于追溯性撤销",{"type":21,"tag":2228,"props":5846,"children":5847},{},[5848],{"type":27,"value":5849},"✅，部分审计\u002F合规场景下需要",{"type":21,"tag":2200,"props":5851,"children":5852},{},[5853,5857,5862],{"type":21,"tag":2228,"props":5854,"children":5855},{},[5856],{"type":27,"value":2529},{"type":21,"tag":2228,"props":5858,"children":5859},{},[5860],{"type":27,"value":5861},"启用证书在数据库中存储（必须开启，除非特殊离线用途）",{"type":21,"tag":2228,"props":5863,"children":5864},{},[5865],{"type":27,"value":5866},"✅",{"type":21,"tag":2200,"props":5868,"children":5869},{},[5870,5875,5880],{"type":21,"tag":2228,"props":5871,"children":5872},{},[5873],{"type":27,"value":5874},"Store Certificate Data",{"type":21,"tag":2228,"props":5876,"children":5877},{},[5878],{"type":27,"value":5879},"存储证书完整原文数据（配合 OCSP\u002FCRL 使用）",{"type":21,"tag":2228,"props":5881,"children":5882},{},[5883],{"type":27,"value":5884},"✅，建议与存储功能一同开启",{"type":21,"tag":36,"props":5886,"children":5887},{},[5888,5890],{"type":27,"value":5889},"✅ 建议：",{"type":21,"tag":42,"props":5891,"children":5892},{},[5893],{"type":27,"value":5894},"在生产环境中保持模板统一性，除非明确需要，否则尽量关闭 Override 类权限项，避免 CSR\u002FEnd Entity 越权操作。",{"type":21,"tag":65,"props":5896,"children":5897},{},[],{"type":21,"tag":150,"props":5899,"children":5901},{"id":5900},"_73-x509v3-扩展-基础信息",[5902],{"type":27,"value":5903},"7.3 X.509v3 扩展 - 基础信息",{"type":21,"tag":2192,"props":5905,"children":5906},{},[5907,5926],{"type":21,"tag":2196,"props":5908,"children":5909},{},[5910],{"type":21,"tag":2200,"props":5911,"children":5912},{},[5913,5918,5922],{"type":21,"tag":2204,"props":5914,"children":5915},{},[5916],{"type":27,"value":5917},"扩展项",{"type":21,"tag":2204,"props":5919,"children":5920},{},[5921],{"type":27,"value":5492},{"type":21,"tag":2204,"props":5923,"children":5924},{},[5925],{"type":27,"value":5702},{"type":21,"tag":2221,"props":5927,"children":5928},{},[5929,5947,5965],{"type":21,"tag":2200,"props":5930,"children":5931},{},[5932,5937,5942],{"type":21,"tag":2228,"props":5933,"children":5934},{},[5935],{"type":27,"value":5936},"基本约束（Basic Constraints）",{"type":21,"tag":2228,"props":5938,"children":5939},{},[5940],{"type":27,"value":5941},"限制是否为 CA 证书（终端证书应设为 FALSE）",{"type":21,"tag":2228,"props":5943,"children":5944},{},[5945],{"type":27,"value":5946},"✅ 使用，关键",{"type":21,"tag":2200,"props":5948,"children":5949},{},[5950,5955,5960],{"type":21,"tag":2228,"props":5951,"children":5952},{},[5953],{"type":27,"value":5954},"CA 密钥标识符",{"type":21,"tag":2228,"props":5956,"children":5957},{},[5958],{"type":27,"value":5959},"标识签发 CA 的信息",{"type":21,"tag":2228,"props":5961,"children":5962},{},[5963],{"type":27,"value":5964},"✅ 使用",{"type":21,"tag":2200,"props":5966,"children":5967},{},[5968,5973,5978],{"type":21,"tag":2228,"props":5969,"children":5970},{},[5971],{"type":27,"value":5972},"主题密钥标识符",{"type":21,"tag":2228,"props":5974,"children":5975},{},[5976],{"type":27,"value":5977},"生成此证书的唯一标识",{"type":21,"tag":2228,"props":5979,"children":5980},{},[5981],{"type":27,"value":5964},{"type":21,"tag":65,"props":5983,"children":5984},{},[],{"type":21,"tag":150,"props":5986,"children":5988},{"id":5987},"_74-x509v3-扩展-密钥用途key-usage",[5989],{"type":27,"value":5990},"7.4 X.509v3 扩展 - 密钥用途（Key Usage）",{"type":21,"tag":2192,"props":5992,"children":5993},{},[5994,6009],{"type":21,"tag":2196,"props":5995,"children":5996},{},[5997],{"type":21,"tag":2200,"props":5998,"children":5999},{},[6000,6005],{"type":21,"tag":2204,"props":6001,"children":6002},{},[6003],{"type":27,"value":6004},"项目",{"type":21,"tag":2204,"props":6006,"children":6007},{},[6008],{"type":27,"value":5492},{"type":21,"tag":2221,"props":6010,"children":6011},{},[6012,6025,6038,6051,6064,6077,6090,6103,6116,6129],{"type":21,"tag":2200,"props":6013,"children":6014},{},[6015,6020],{"type":21,"tag":2228,"props":6016,"children":6017},{},[6018],{"type":27,"value":6019},"数字签名 (digitalSignature)",{"type":21,"tag":2228,"props":6021,"children":6022},{},[6023],{"type":27,"value":6024},"用于验证签名，如身份认证、代码签名",{"type":21,"tag":2200,"props":6026,"children":6027},{},[6028,6033],{"type":21,"tag":2228,"props":6029,"children":6030},{},[6031],{"type":27,"value":6032},"不可抵赖 (nonRepudiation)",{"type":21,"tag":2228,"props":6034,"children":6035},{},[6036],{"type":27,"value":6037},"表明签名不可否认（法律场景）",{"type":21,"tag":2200,"props":6039,"children":6040},{},[6041,6046],{"type":21,"tag":2228,"props":6042,"children":6043},{},[6044],{"type":27,"value":6045},"数据加密 (dataEncipherment)",{"type":21,"tag":2228,"props":6047,"children":6048},{},[6049],{"type":27,"value":6050},"用于加密非密钥数据",{"type":21,"tag":2200,"props":6052,"children":6053},{},[6054,6059],{"type":21,"tag":2228,"props":6055,"children":6056},{},[6057],{"type":27,"value":6058},"密钥加密 (keyEncipherment)",{"type":21,"tag":2228,"props":6060,"children":6061},{},[6062],{"type":27,"value":6063},"用于加密密钥材料，如对称密钥",{"type":21,"tag":2200,"props":6065,"children":6066},{},[6067,6072],{"type":21,"tag":2228,"props":6068,"children":6069},{},[6070],{"type":27,"value":6071},"密钥协议 (keyAgreement)",{"type":21,"tag":2228,"props":6073,"children":6074},{},[6075],{"type":27,"value":6076},"支持密钥协商协议（如 DH）",{"type":21,"tag":2200,"props":6078,"children":6079},{},[6080,6085],{"type":21,"tag":2228,"props":6081,"children":6082},{},[6083],{"type":27,"value":6084},"CRL 签名 (cRLSign)",{"type":21,"tag":2228,"props":6086,"children":6087},{},[6088],{"type":27,"value":6089},"用于签署吊销列表（CA 用）",{"type":21,"tag":2200,"props":6091,"children":6092},{},[6093,6098],{"type":21,"tag":2228,"props":6094,"children":6095},{},[6096],{"type":27,"value":6097},"密钥证书签名 (keyCertSign)",{"type":21,"tag":2228,"props":6099,"children":6100},{},[6101],{"type":27,"value":6102},"用于签署证书（CA 用）",{"type":21,"tag":2200,"props":6104,"children":6105},{},[6106,6111],{"type":21,"tag":2228,"props":6107,"children":6108},{},[6109],{"type":27,"value":6110},"只用于加密 (encipherOnly)",{"type":21,"tag":2228,"props":6112,"children":6113},{},[6114],{"type":27,"value":6115},"与密钥协议联合使用（仅加密）",{"type":21,"tag":2200,"props":6117,"children":6118},{},[6119,6124],{"type":21,"tag":2228,"props":6120,"children":6121},{},[6122],{"type":27,"value":6123},"只用于解密 (decipherOnly)",{"type":21,"tag":2228,"props":6125,"children":6126},{},[6127],{"type":27,"value":6128},"与密钥协议联合使用（仅解密）",{"type":21,"tag":2200,"props":6130,"children":6131},{},[6132,6137],{"type":21,"tag":2228,"props":6133,"children":6134},{},[6135],{"type":27,"value":6136},"Forbid encryption usage for ECC keys",{"type":21,"tag":2228,"props":6138,"children":6139},{},[6140],{"type":27,"value":6141},"禁止 ECC 密钥用于加密",{"type":21,"tag":150,"props":6143,"children":6145},{"id":6144},"_75-x509v3-扩展-扩展密钥用途extended-key-usage",[6146],{"type":27,"value":6147},"7.5 X.509v3 扩展 - 扩展密钥用途（Extended Key Usage）",{"type":21,"tag":2192,"props":6149,"children":6150},{},[6151,6166],{"type":21,"tag":2196,"props":6152,"children":6153},{},[6154],{"type":21,"tag":2200,"props":6155,"children":6156},{},[6157,6162],{"type":21,"tag":2204,"props":6158,"children":6159},{},[6160],{"type":27,"value":6161},"扩展用途",{"type":21,"tag":2204,"props":6163,"children":6164},{},[6165],{"type":27,"value":5492},{"type":21,"tag":2221,"props":6167,"children":6168},{},[6169,6182,6195,6208,6221,6234,6247,6260,6273,6286,6299,6312,6325,6338,6351,6364,6377,6390,6403,6416,6429,6442,6455,6468,6481,6494,6507,6520,6533,6546,6559,6572,6585],{"type":21,"tag":2200,"props":6170,"children":6171},{},[6172,6177],{"type":21,"tag":2228,"props":6173,"children":6174},{},[6175],{"type":27,"value":6176},"TLS client",{"type":21,"tag":2228,"props":6178,"children":6179},{},[6180],{"type":27,"value":6181},"用于客户端 TLS 认证",{"type":21,"tag":2200,"props":6183,"children":6184},{},[6185,6190],{"type":21,"tag":2228,"props":6186,"children":6187},{},[6188],{"type":27,"value":6189},"TLS server",{"type":21,"tag":2228,"props":6191,"children":6192},{},[6193],{"type":27,"value":6194},"用于服务器 TLS 认证",{"type":21,"tag":2200,"props":6196,"children":6197},{},[6198,6203],{"type":21,"tag":2228,"props":6199,"children":6200},{},[6201],{"type":27,"value":6202},"EAP over LAN (EAPOL)",{"type":21,"tag":2228,"props":6204,"children":6205},{},[6206],{"type":27,"value":6207},"企业网身份认证",{"type":21,"tag":2200,"props":6209,"children":6210},{},[6211,6216],{"type":21,"tag":2228,"props":6212,"children":6213},{},[6214],{"type":27,"value":6215},"EAP over PPP",{"type":21,"tag":2228,"props":6217,"children":6218},{},[6219],{"type":27,"value":6220},"点对点协议身份认证",{"type":21,"tag":2200,"props":6222,"children":6223},{},[6224,6229],{"type":21,"tag":2228,"props":6225,"children":6226},{},[6227],{"type":27,"value":6228},"ETSI TSL Signing",{"type":21,"tag":2228,"props":6230,"children":6231},{},[6232],{"type":27,"value":6233},"用于 ETSI TSL 签名场景",{"type":21,"tag":2200,"props":6235,"children":6236},{},[6237,6242],{"type":21,"tag":2228,"props":6238,"children":6239},{},[6240],{"type":27,"value":6241},"ICAO Deviation List Signing",{"type":21,"tag":2228,"props":6243,"children":6244},{},[6245],{"type":27,"value":6246},"ICAO 签名用途之一",{"type":21,"tag":2200,"props":6248,"children":6249},{},[6250,6255],{"type":21,"tag":2228,"props":6251,"children":6252},{},[6253],{"type":27,"value":6254},"ICAO Master List Signing",{"type":21,"tag":2228,"props":6256,"children":6257},{},[6258],{"type":27,"value":6259},"ICAO 主列表签名",{"type":21,"tag":2200,"props":6261,"children":6262},{},[6263,6268],{"type":21,"tag":2228,"props":6264,"children":6265},{},[6266],{"type":27,"value":6267},"Intel AMT management",{"type":21,"tag":2228,"props":6269,"children":6270},{},[6271],{"type":27,"value":6272},"Intel 管理认证专用",{"type":21,"tag":2200,"props":6274,"children":6275},{},[6276,6281],{"type":21,"tag":2228,"props":6277,"children":6278},{},[6279],{"type":27,"value":6280},"Internet Key Exchange for IPsec",{"type":21,"tag":2228,"props":6282,"children":6283},{},[6284],{"type":27,"value":6285},"IPsec 密钥交换",{"type":21,"tag":2200,"props":6287,"children":6288},{},[6289,6294],{"type":21,"tag":2228,"props":6290,"children":6291},{},[6292],{"type":27,"value":6293},"Kerberos Client Authentication",{"type":21,"tag":2228,"props":6295,"children":6296},{},[6297],{"type":27,"value":6298},"Kerberos 客户端认证",{"type":21,"tag":2200,"props":6300,"children":6301},{},[6302,6307],{"type":21,"tag":2228,"props":6303,"children":6304},{},[6305],{"type":27,"value":6306},"Kerberos KDC",{"type":21,"tag":2228,"props":6308,"children":6309},{},[6310],{"type":27,"value":6311},"Kerberos 密钥中心",{"type":21,"tag":2200,"props":6313,"children":6314},{},[6315,6320],{"type":21,"tag":2228,"props":6316,"children":6317},{},[6318],{"type":27,"value":6319},"MS CA Key Exchange",{"type":21,"tag":2228,"props":6321,"children":6322},{},[6323],{"type":27,"value":6324},"Microsoft CA 密钥交换用途",{"type":21,"tag":2200,"props":6326,"children":6327},{},[6328,6333],{"type":21,"tag":2228,"props":6329,"children":6330},{},[6331],{"type":27,"value":6332},"MS Commercial Code Signing",{"type":21,"tag":2228,"props":6334,"children":6335},{},[6336],{"type":27,"value":6337},"Microsoft 商业代码签名",{"type":21,"tag":2200,"props":6339,"children":6340},{},[6341,6346],{"type":21,"tag":2228,"props":6342,"children":6343},{},[6344],{"type":27,"value":6345},"MS Document Signing",{"type":21,"tag":2228,"props":6347,"children":6348},{},[6349],{"type":27,"value":6350},"Microsoft 文档签名",{"type":21,"tag":2200,"props":6352,"children":6353},{},[6354,6359],{"type":21,"tag":2228,"props":6355,"children":6356},{},[6357],{"type":27,"value":6358},"MS EFS Recovery",{"type":21,"tag":2228,"props":6360,"children":6361},{},[6362],{"type":27,"value":6363},"Microsoft EFS 恢复用途",{"type":21,"tag":2200,"props":6365,"children":6366},{},[6367,6372],{"type":21,"tag":2228,"props":6368,"children":6369},{},[6370],{"type":27,"value":6371},"MS Encrypted File System",{"type":21,"tag":2228,"props":6373,"children":6374},{},[6375],{"type":27,"value":6376},"Microsoft 加密文件系统用途",{"type":21,"tag":2200,"props":6378,"children":6379},{},[6380,6385],{"type":21,"tag":2228,"props":6381,"children":6382},{},[6383],{"type":27,"value":6384},"MS Individual Code Signing",{"type":21,"tag":2228,"props":6386,"children":6387},{},[6388],{"type":27,"value":6389},"Microsoft 个人代码签名",{"type":21,"tag":2200,"props":6391,"children":6392},{},[6393,6398],{"type":21,"tag":2228,"props":6394,"children":6395},{},[6396],{"type":27,"value":6397},"MS 智能卡登录",{"type":21,"tag":2228,"props":6399,"children":6400},{},[6401],{"type":27,"value":6402},"Microsoft 智能卡登录验证",{"type":21,"tag":2200,"props":6404,"children":6405},{},[6406,6411],{"type":21,"tag":2228,"props":6407,"children":6408},{},[6409],{"type":27,"value":6410},"OCSP 签发者",{"type":21,"tag":2228,"props":6412,"children":6413},{},[6414],{"type":27,"value":6415},"在线证书状态协议（OCSP）签名证书用途",{"type":21,"tag":2200,"props":6417,"children":6418},{},[6419,6424],{"type":21,"tag":2228,"props":6420,"children":6421},{},[6422],{"type":27,"value":6423},"PDF Signing",{"type":21,"tag":2228,"props":6425,"children":6426},{},[6427],{"type":27,"value":6428},"用于 PDF 文件签名",{"type":21,"tag":2200,"props":6430,"children":6431},{},[6432,6437],{"type":21,"tag":2228,"props":6433,"children":6434},{},[6435],{"type":27,"value":6436},"PIV Card Authentication",{"type":21,"tag":2228,"props":6438,"children":6439},{},[6440],{"type":27,"value":6441},"PIV 卡身份认证",{"type":21,"tag":2200,"props":6443,"children":6444},{},[6445,6450],{"type":21,"tag":2228,"props":6446,"children":6447},{},[6448],{"type":27,"value":6449},"RFC9336 Document Signing",{"type":21,"tag":2228,"props":6451,"children":6452},{},[6453],{"type":27,"value":6454},"符合 RFC9336 的文档签名用途",{"type":21,"tag":2200,"props":6456,"children":6457},{},[6458,6463],{"type":21,"tag":2228,"props":6459,"children":6460},{},[6461],{"type":27,"value":6462},"SCVP Client",{"type":21,"tag":2228,"props":6464,"children":6465},{},[6466],{"type":27,"value":6467},"简化证书验证协议客户端",{"type":21,"tag":2200,"props":6469,"children":6470},{},[6471,6476],{"type":21,"tag":2228,"props":6472,"children":6473},{},[6474],{"type":27,"value":6475},"SCVP Server",{"type":21,"tag":2228,"props":6477,"children":6478},{},[6479],{"type":27,"value":6480},"简化证书验证协议服务端",{"type":21,"tag":2200,"props":6482,"children":6483},{},[6484,6489],{"type":21,"tag":2228,"props":6485,"children":6486},{},[6487],{"type":27,"value":6488},"SIP Domain",{"type":21,"tag":2228,"props":6490,"children":6491},{},[6492],{"type":27,"value":6493},"用于 VoIP\u002FSIP 域名认证用途",{"type":21,"tag":2200,"props":6495,"children":6496},{},[6497,6502],{"type":21,"tag":2228,"props":6498,"children":6499},{},[6500],{"type":27,"value":6501},"SSH Client",{"type":21,"tag":2228,"props":6503,"children":6504},{},[6505],{"type":27,"value":6506},"用于 SSH 客户端认证",{"type":21,"tag":2200,"props":6508,"children":6509},{},[6510,6515],{"type":21,"tag":2228,"props":6511,"children":6512},{},[6513],{"type":27,"value":6514},"SSH Server",{"type":21,"tag":2228,"props":6516,"children":6517},{},[6518],{"type":27,"value":6519},"用于 SSH 服务器认证",{"type":21,"tag":2200,"props":6521,"children":6522},{},[6523,6528],{"type":21,"tag":2228,"props":6524,"children":6525},{},[6526],{"type":27,"value":6527},"代码签名 (codeSigning)",{"type":21,"tag":2228,"props":6529,"children":6530},{},[6531],{"type":27,"value":6532},"用于软件\u002F驱动程序签名",{"type":21,"tag":2200,"props":6534,"children":6535},{},[6536,6541],{"type":21,"tag":2228,"props":6537,"children":6538},{},[6539],{"type":27,"value":6540},"任意扩展的密钥用途",{"type":21,"tag":2228,"props":6542,"children":6543},{},[6544],{"type":27,"value":6545},"任意通用用途扩展支持",{"type":21,"tag":2200,"props":6547,"children":6548},{},[6549,6554],{"type":21,"tag":2228,"props":6550,"children":6551},{},[6552],{"type":27,"value":6553},"安全 Email (emailProtection)",{"type":21,"tag":2228,"props":6555,"children":6556},{},[6557],{"type":27,"value":6558},"S\u002FMIME 邮件签名\u002F加密用途",{"type":21,"tag":2200,"props":6560,"children":6561},{},[6562,6567],{"type":21,"tag":2228,"props":6563,"children":6564},{},[6565],{"type":27,"value":6566},"客户身份验证 (clientAuth)",{"type":21,"tag":2228,"props":6568,"children":6569},{},[6570],{"type":27,"value":6571},"用于 TLS 客户端身份认证",{"type":21,"tag":2200,"props":6573,"children":6574},{},[6575,6580],{"type":21,"tag":2228,"props":6576,"children":6577},{},[6578],{"type":27,"value":6579},"时间戳 (timeStamping)",{"type":21,"tag":2228,"props":6581,"children":6582},{},[6583],{"type":27,"value":6584},"时间戳服务签名用途",{"type":21,"tag":2200,"props":6586,"children":6587},{},[6588,6593],{"type":21,"tag":2228,"props":6589,"children":6590},{},[6591],{"type":27,"value":6592},"服务器验证 (serverAuth)",{"type":21,"tag":2228,"props":6594,"children":6595},{},[6596],{"type":27,"value":6597},"用于服务器身份验证（HTTPS 等）",{"type":21,"tag":150,"props":6599,"children":6601},{"id":6600},"_76-名称扩展",[6602],{"type":27,"value":6603},"7.6 名称扩展",{"type":21,"tag":2192,"props":6605,"children":6606},{},[6607,6626],{"type":21,"tag":2196,"props":6608,"children":6609},{},[6610],{"type":21,"tag":2200,"props":6611,"children":6612},{},[6613,6617,6621],{"type":21,"tag":2204,"props":6614,"children":6615},{},[6616],{"type":27,"value":6004},{"type":21,"tag":2204,"props":6618,"children":6619},{},[6620],{"type":27,"value":5492},{"type":21,"tag":2204,"props":6622,"children":6623},{},[6624],{"type":27,"value":6625},"建议",{"type":21,"tag":2221,"props":6627,"children":6628},{},[6629,6646,6664],{"type":21,"tag":2200,"props":6630,"children":6631},{},[6632,6637,6642],{"type":21,"tag":2228,"props":6633,"children":6634},{},[6635],{"type":27,"value":6636},"主题别名（Subject Alt Name）",{"type":21,"tag":2228,"props":6638,"children":6639},{},[6640],{"type":27,"value":6641},"支持 IP\u002FDNS\u002FUEmail 作为证书标识",{"type":21,"tag":2228,"props":6643,"children":6644},{},[6645],{"type":27,"value":5964},{"type":21,"tag":2200,"props":6647,"children":6648},{},[6649,6654,6659],{"type":21,"tag":2228,"props":6650,"children":6651},{},[6652],{"type":27,"value":6653},"Issuer Alternative Name",{"type":21,"tag":2228,"props":6655,"children":6656},{},[6657],{"type":27,"value":6658},"可添加额外的 CA 名称信息",{"type":21,"tag":2228,"props":6660,"children":6661},{},[6662],{"type":27,"value":6663},"可选",{"type":21,"tag":2200,"props":6665,"children":6666},{},[6667,6672,6677],{"type":21,"tag":2228,"props":6668,"children":6669},{},[6670],{"type":27,"value":6671},"Name Constraints",{"type":21,"tag":2228,"props":6673,"children":6674},{},[6675],{"type":27,"value":6676},"限定主题中可用的命名空间",{"type":21,"tag":2228,"props":6678,"children":6679},{},[6680],{"type":27,"value":6681},"可选（高安全场景使用）",{"type":21,"tag":150,"props":6683,"children":6685},{"id":6684},"_77-验证扩展validation-data",[6686],{"type":27,"value":6687},"7.7 验证扩展（Validation Data）",{"type":21,"tag":2192,"props":6689,"children":6690},{},[6691,6710],{"type":21,"tag":2196,"props":6692,"children":6693},{},[6694],{"type":21,"tag":2200,"props":6695,"children":6696},{},[6697,6701,6705],{"type":21,"tag":2204,"props":6698,"children":6699},{},[6700],{"type":27,"value":6004},{"type":21,"tag":2204,"props":6702,"children":6703},{},[6704],{"type":27,"value":5492},{"type":21,"tag":2204,"props":6706,"children":6707},{},[6708],{"type":27,"value":6709},"推荐",{"type":21,"tag":2221,"props":6711,"children":6712},{},[6713,6730,6748],{"type":21,"tag":2200,"props":6714,"children":6715},{},[6716,6721,6726],{"type":21,"tag":2228,"props":6717,"children":6718},{},[6719],{"type":27,"value":6720},"CRL 发布点",{"type":21,"tag":2228,"props":6722,"children":6723},{},[6724],{"type":27,"value":6725},"证书吊销列表地址",{"type":21,"tag":2228,"props":6727,"children":6728},{},[6729],{"type":27,"value":5946},{"type":21,"tag":2200,"props":6731,"children":6732},{},[6733,6738,6743],{"type":21,"tag":2228,"props":6734,"children":6735},{},[6736],{"type":27,"value":6737},"Delta CRL（Freshest CRL）",{"type":21,"tag":2228,"props":6739,"children":6740},{},[6741],{"type":27,"value":6742},"增量吊销列表",{"type":21,"tag":2228,"props":6744,"children":6745},{},[6746],{"type":27,"value":6747},"按需开启",{"type":21,"tag":2200,"props":6749,"children":6750},{},[6751,6756,6761],{"type":21,"tag":2228,"props":6752,"children":6753},{},[6754],{"type":27,"value":6755},"Authority Information Access (AIA)",{"type":21,"tag":2228,"props":6757,"children":6758},{},[6759],{"type":27,"value":6760},"提供 OCSP\u002FCA 信息",{"type":21,"tag":2228,"props":6762,"children":6763},{},[6764],{"type":27,"value":5866},{"type":21,"tag":65,"props":6766,"children":6767},{},[],{"type":21,"tag":150,"props":6769,"children":6771},{"id":6770},"_78-私钥使用期限制",[6772],{"type":27,"value":6773},"7.8 私钥使用期限制",{"type":21,"tag":2192,"props":6775,"children":6776},{},[6777,6791],{"type":21,"tag":2196,"props":6778,"children":6779},{},[6780],{"type":21,"tag":2200,"props":6781,"children":6782},{},[6783,6787],{"type":21,"tag":2204,"props":6784,"children":6785},{},[6786],{"type":27,"value":6004},{"type":21,"tag":2204,"props":6788,"children":6789},{},[6790],{"type":27,"value":5492},{"type":21,"tag":2221,"props":6792,"children":6793},{},[6794,6807],{"type":21,"tag":2200,"props":6795,"children":6796},{},[6797,6802],{"type":21,"tag":2228,"props":6798,"children":6799},{},[6800],{"type":27,"value":6801},"Start Offset",{"type":21,"tag":2228,"props":6803,"children":6804},{},[6805],{"type":27,"value":6806},"私钥可用的起始偏移时间",{"type":21,"tag":2200,"props":6808,"children":6809},{},[6810,6815],{"type":21,"tag":2228,"props":6811,"children":6812},{},[6813],{"type":27,"value":6814},"Period Length",{"type":21,"tag":2228,"props":6816,"children":6817},{},[6818],{"type":27,"value":6819},"私钥的可使用周期（独立于证书有效期）",{"type":21,"tag":65,"props":6821,"children":6822},{},[],{"type":21,"tag":150,"props":6824,"children":6826},{"id":6825},"_79-etsi-合规扩展一般用于合规性要求高的-pki-环境",[6827],{"type":27,"value":6828},"7.9 🇪🇺 ETSI 合规扩展（一般用于合规性要求高的 PKI 环境）",{"type":21,"tag":2192,"props":6830,"children":6831},{},[6832,6846],{"type":21,"tag":2196,"props":6833,"children":6834},{},[6835],{"type":21,"tag":2200,"props":6836,"children":6837},{},[6838,6842],{"type":21,"tag":2204,"props":6839,"children":6840},{},[6841],{"type":27,"value":6004},{"type":21,"tag":2204,"props":6843,"children":6844},{},[6845],{"type":27,"value":5492},{"type":21,"tag":2221,"props":6847,"children":6848},{},[6849,6862],{"type":21,"tag":2200,"props":6850,"children":6851},{},[6852,6857],{"type":21,"tag":2228,"props":6853,"children":6854},{},[6855],{"type":27,"value":6856},"资质证书声明",{"type":21,"tag":2228,"props":6858,"children":6859},{},[6860],{"type":27,"value":6861},"用于标识法律或合规用途证书",{"type":21,"tag":2200,"props":6863,"children":6864},{},[6865,6870],{"type":21,"tag":2228,"props":6866,"children":6867},{},[6868],{"type":27,"value":6869},"Assured validity",{"type":21,"tag":2228,"props":6871,"children":6872},{},[6873],{"type":27,"value":6874},"确保短期证书的有效性",{"type":21,"tag":65,"props":6876,"children":6877},{},[],{"type":21,"tag":150,"props":6879,"children":6881},{"id":6880},"_710-其他扩展other-extensions",[6882],{"type":27,"value":6883},"7.10 其他扩展（Other Extensions）",{"type":21,"tag":2192,"props":6885,"children":6886},{},[6887,6903],{"type":21,"tag":2196,"props":6888,"children":6889},{},[6890],{"type":21,"tag":2200,"props":6891,"children":6892},{},[6893,6898],{"type":21,"tag":2204,"props":6894,"children":6895},{},[6896],{"type":27,"value":6897},"扩展",{"type":21,"tag":2204,"props":6899,"children":6900},{},[6901],{"type":27,"value":6902},"用途",{"type":21,"tag":2221,"props":6904,"children":6905},{},[6906,6919,6932],{"type":21,"tag":2200,"props":6907,"children":6908},{},[6909,6914],{"type":21,"tag":2228,"props":6910,"children":6911},{},[6912],{"type":27,"value":6913},"OCSP No Check",{"type":21,"tag":2228,"props":6915,"children":6916},{},[6917],{"type":27,"value":6918},"禁用 OCSP 检查（通常仅对 OCSP responder 有用）",{"type":21,"tag":2200,"props":6920,"children":6921},{},[6922,6927],{"type":21,"tag":2228,"props":6923,"children":6924},{},[6925],{"type":27,"value":6926},"Microsoft 模板值",{"type":21,"tag":2228,"props":6928,"children":6929},{},[6930],{"type":27,"value":6931},"用于 Windows AD 集成的特殊扩展",{"type":21,"tag":2200,"props":6933,"children":6934},{},[6935,6940],{"type":21,"tag":2228,"props":6936,"children":6937},{},[6938],{"type":27,"value":6939},"CA\u002FB Forum OID",{"type":21,"tag":2228,"props":6941,"children":6942},{},[6943],{"type":27,"value":6944},"用于 CA\u002FB 合规的组织标识扩展",{"type":21,"tag":65,"props":6946,"children":6947},{},[],{"type":21,"tag":150,"props":6949,"children":6951},{"id":6950},"_711-审批设置-附加字段",[6952],{"type":27,"value":6953},"7.11 审批设置 & 附加字段",{"type":21,"tag":2192,"props":6955,"children":6956},{},[6957,6971],{"type":21,"tag":2196,"props":6958,"children":6959},{},[6960],{"type":21,"tag":2200,"props":6961,"children":6962},{},[6963,6967],{"type":21,"tag":2204,"props":6964,"children":6965},{},[6966],{"type":27,"value":5487},{"type":21,"tag":2204,"props":6968,"children":6969},{},[6970],{"type":27,"value":2219},{"type":21,"tag":2221,"props":6972,"children":6973},{},[6974,6987,7000,7013,7026],{"type":21,"tag":2200,"props":6975,"children":6976},{},[6977,6982],{"type":21,"tag":2228,"props":6978,"children":6979},{},[6980],{"type":27,"value":6981},"添加\u002F编辑终端实体",{"type":21,"tag":2228,"props":6983,"children":6984},{},[6985],{"type":27,"value":6986},"绑定的审批流程",{"type":21,"tag":2200,"props":6988,"children":6989},{},[6990,6995],{"type":21,"tag":2228,"props":6991,"children":6992},{},[6993],{"type":27,"value":6994},"密钥恢复",{"type":21,"tag":2228,"props":6996,"children":6997},{},[6998],{"type":27,"value":6999},"是否支持密钥找回（如用于备份恢复）",{"type":21,"tag":2200,"props":7001,"children":7002},{},[7003,7008],{"type":21,"tag":2228,"props":7004,"children":7005},{},[7006],{"type":27,"value":7007},"撤销审批",{"type":21,"tag":2228,"props":7009,"children":7010},{},[7011],{"type":27,"value":7012},"吊销时是否需审批",{"type":21,"tag":2200,"props":7014,"children":7015},{},[7016,7021],{"type":21,"tag":2228,"props":7017,"children":7018},{},[7019],{"type":27,"value":7020},"CN 后缀",{"type":21,"tag":2228,"props":7022,"children":7023},{},[7024],{"type":27,"value":7025},"在 Subject CN 后自动添加字符串",{"type":21,"tag":2200,"props":7027,"children":7028},{},[7029,7034],{"type":21,"tag":2228,"props":7030,"children":7031},{},[7032],{"type":27,"value":7033},"主题字段子集限制",{"type":21,"tag":2228,"props":7035,"children":7036},{},[7037],{"type":27,"value":7038},"限制允许使用的 Subject 字段",{"type":21,"tag":65,"props":7040,"children":7041},{},[],{"type":21,"tag":150,"props":7043,"children":7045},{"id":7044},"_712-ca-发布设置",[7046],{"type":27,"value":7047},"7.12 CA & 发布设置",{"type":21,"tag":2192,"props":7049,"children":7050},{},[7051,7065],{"type":21,"tag":2196,"props":7052,"children":7053},{},[7054],{"type":21,"tag":2200,"props":7055,"children":7056},{},[7057,7061],{"type":21,"tag":2204,"props":7058,"children":7059},{},[7060],{"type":27,"value":6004},{"type":21,"tag":2204,"props":7062,"children":7063},{},[7064],{"type":27,"value":2219},{"type":21,"tag":2221,"props":7066,"children":7067},{},[7068,7081,7094,7107],{"type":21,"tag":2200,"props":7069,"children":7070},{},[7071,7076],{"type":21,"tag":2228,"props":7072,"children":7073},{},[7074],{"type":27,"value":7075},"可用的 CA",{"type":21,"tag":2228,"props":7077,"children":7078},{},[7079],{"type":27,"value":7080},"允许哪些 CA 使用此证书模板",{"type":21,"tag":2200,"props":7082,"children":7083},{},[7084,7089],{"type":21,"tag":2228,"props":7085,"children":7086},{},[7087],{"type":27,"value":7088},"发布器（Publisher）",{"type":21,"tag":2228,"props":7090,"children":7091},{},[7092],{"type":27,"value":7093},"可配置发布至 LDAP、数据库或外部服务",{"type":21,"tag":2200,"props":7095,"children":7096},{},[7097,7102],{"type":21,"tag":2228,"props":7098,"children":7099},{},[7100],{"type":27,"value":7101},"单证书限制",{"type":21,"tag":2228,"props":7103,"children":7104},{},[7105],{"type":27,"value":7106},"是否启用一个 End Entity 只能有一张有效证书",{"type":21,"tag":2200,"props":7108,"children":7109},{},[7110,7115],{"type":21,"tag":2228,"props":7111,"children":7112},{},[7113],{"type":27,"value":7114},"Account Binding Namespace",{"type":21,"tag":2228,"props":7116,"children":7117},{},[7118],{"type":27,"value":7119},"用于设备账户绑定场景（如 IoT）",{"type":21,"tag":65,"props":7121,"children":7122},{},[],{"type":21,"tag":36,"props":7124,"children":7125},{},[7126],{"type":27,"value":7127},"如需配置 \"代码签名证书\" 模板，请在此基础上调整 keyUsage 与 extendedKeyUsage 字段即可。",{"type":21,"tag":531,"props":7129,"children":7130},{},[7131],{"type":21,"tag":36,"props":7132,"children":7133},{},[7134],{"type":27,"value":7135},"📌 建议对不同应用（如：VPN、HTTPS、代码签名、客户端认证）创建不同模板，便于管理和合规控制。",{"type":21,"tag":65,"props":7137,"children":7138},{},[],{"type":21,"tag":29,"props":7140,"children":7142},{"id":7141},"_8-审批配置与管理",[7143],{"type":27,"value":7144},"8. 审批配置与管理",{"type":21,"tag":150,"props":7146,"children":7148},{"id":7147},"_81-创建-approval-profile审批配置",[7149],{"type":27,"value":7150},"8.1 创建 Approval Profile（审批配置）",{"type":21,"tag":546,"props":7152,"children":7153},{},[7154],{"type":21,"tag":54,"props":7155,"children":7156},{},[7157],{"type":27,"value":7158},"进入：",{"type":21,"tag":182,"props":7160,"children":7162},{"code":7161},"监察员功能 → Approval Profiles\n",[7163],{"type":21,"tag":141,"props":7164,"children":7165},{"__ignoreMap":7},[7166],{"type":27,"value":7161},{"type":21,"tag":546,"props":7168,"children":7169},{},[7170,7189],{"type":21,"tag":54,"props":7171,"children":7172},{},[7173,7175,7180,7182,7188],{"type":27,"value":7174},"在底部输入名称（如 ",{"type":21,"tag":141,"props":7176,"children":7178},{"className":7177},[],[7179],{"type":27,"value":5040},{"type":27,"value":7181},"）→ 点击 ",{"type":21,"tag":141,"props":7183,"children":7185},{"className":7184},[],[7186],{"type":27,"value":7187},"添加",{"type":27,"value":1732},{"type":21,"tag":54,"props":7190,"children":7191},{},[7192,7194,7200],{"type":27,"value":7193},"在列表中点击 ",{"type":21,"tag":141,"props":7195,"children":7197},{"className":7196},[],[7198],{"type":27,"value":7199},"编辑",{"type":27,"value":7201}," 进入详细设置。",{"type":21,"tag":150,"props":7203,"children":7205},{"id":7204},"_82-基本参数设置",[7206],{"type":27,"value":7207},"8.2 基本参数设置",{"type":21,"tag":2192,"props":7209,"children":7210},{},[7211,7226],{"type":21,"tag":2196,"props":7212,"children":7213},{},[7214],{"type":21,"tag":2200,"props":7215,"children":7216},{},[7217,7221],{"type":21,"tag":2204,"props":7218,"children":7219},{},[7220],{"type":27,"value":4724},{"type":21,"tag":2204,"props":7222,"children":7223},{},[7224],{"type":27,"value":7225},"建议\u002F示例",{"type":21,"tag":2221,"props":7227,"children":7228},{},[7229,7242,7261,7279,7298],{"type":21,"tag":2200,"props":7230,"children":7231},{},[7232,7237],{"type":21,"tag":2228,"props":7233,"children":7234},{},[7235],{"type":27,"value":7236},"Approval Profile Type",{"type":21,"tag":2228,"props":7238,"children":7239},{},[7240],{"type":27,"value":7241},"Accumulative Approval（累计）；跨部门可用 Partitioned Approval（分区）",{"type":21,"tag":2200,"props":7243,"children":7244},{},[7245,7250],{"type":21,"tag":2228,"props":7246,"children":7247},{},[7248],{"type":27,"value":7249},"Request Expiration Period",{"type":21,"tag":2228,"props":7251,"children":7252},{},[7253,7259],{"type":21,"tag":141,"props":7254,"children":7256},{"className":7255},[],[7257],{"type":27,"value":7258},"8h",{"type":27,"value":7260},"（超时未批作废）",{"type":21,"tag":2200,"props":7262,"children":7263},{},[7264,7269],{"type":21,"tag":2228,"props":7265,"children":7266},{},[7267],{"type":27,"value":7268},"Approval Expiration Period",{"type":21,"tag":2228,"props":7270,"children":7271},{},[7272,7277],{"type":21,"tag":141,"props":7273,"children":7275},{"className":7274},[],[7276],{"type":27,"value":7258},{"type":27,"value":7278},"（结果过期需重批）",{"type":21,"tag":2200,"props":7280,"children":7281},{},[7282,7287],{"type":21,"tag":2228,"props":7283,"children":7284},{},[7285],{"type":27,"value":7286},"Max Extension Time",{"type":21,"tag":2228,"props":7288,"children":7289},{},[7290,7296],{"type":21,"tag":141,"props":7291,"children":7293},{"className":7292},[],[7294],{"type":27,"value":7295},"0d",{"type":27,"value":7297},"（不允许延长）",{"type":21,"tag":2200,"props":7299,"children":7300},{},[7301,7306],{"type":21,"tag":2228,"props":7302,"children":7303},{},[7304],{"type":27,"value":7305},"Allow Self Approved Request Editing",{"type":21,"tag":2228,"props":7307,"children":7308},{},[7309],{"type":27,"value":7310},"不勾选（生产禁用自批）",{"type":21,"tag":150,"props":7312,"children":7314},{"id":7313},"_83-审批步骤approval-steps",[7315],{"type":27,"value":7316},"8.3 审批步骤（Approval Steps）",{"type":21,"tag":546,"props":7318,"children":7319},{},[7320,7361],{"type":21,"tag":54,"props":7321,"children":7322},{},[7323,7325,7331,7332],{"type":27,"value":7324},"设置 ",{"type":21,"tag":141,"props":7326,"children":7328},{"className":7327},[],[7329],{"type":27,"value":7330},"Number of Required Approvals",{"type":27,"value":651},{"type":21,"tag":50,"props":7333,"children":7334},{},[7335,7348],{"type":21,"tag":54,"props":7336,"children":7337},{},[7338,7340,7346],{"type":27,"value":7339},"开发\u002F测试：",{"type":21,"tag":141,"props":7341,"children":7343},{"className":7342},[],[7344],{"type":27,"value":7345},"1",{"type":27,"value":7347},"（1-of-1）。",{"type":21,"tag":54,"props":7349,"children":7350},{},[7351,7353,7359],{"type":27,"value":7352},"生产\u002F敏感操作：",{"type":21,"tag":141,"props":7354,"children":7356},{"className":7355},[],[7357],{"type":27,"value":7358},"2",{"type":27,"value":7360},"（2-of-2）或分区审批。",{"type":21,"tag":54,"props":7362,"children":7363},{},[7364,7366],{"type":27,"value":7365},"通知邮件：",{"type":21,"tag":50,"props":7367,"children":7368},{},[7369,7385,7401,7414],{"type":21,"tag":54,"props":7370,"children":7371},{},[7372,7378,7379],{"type":21,"tag":141,"props":7373,"children":7375},{"className":7374},[],[7376],{"type":27,"value":7377},"Notification message email recipient",{"type":27,"value":651},{"type":21,"tag":141,"props":7380,"children":7382},{"className":7381},[],[7383],{"type":27,"value":7384},"approval-admin-group@example.org supervisor@example.org",{"type":21,"tag":54,"props":7386,"children":7387},{},[7388,7394,7395],{"type":21,"tag":141,"props":7389,"children":7391},{"className":7390},[],[7392],{"type":27,"value":7393},"Notification message email sender",{"type":27,"value":651},{"type":21,"tag":141,"props":7396,"children":7398},{"className":7397},[],[7399],{"type":27,"value":7400},"no-reply@192.168.xxx.xx",{"type":21,"tag":54,"props":7402,"children":7403},{},[7404,7406],{"type":27,"value":7405},"主题模板示例：",{"type":21,"tag":182,"props":7407,"children":7409},{"code":7408},"[AR-${approvalRequest.ID}-${approvalRequest.STEP_ID}-${approvalRequest.PARTITION_ID}] Approval Request\n",[7410],{"type":21,"tag":141,"props":7411,"children":7412},{"__ignoreMap":7},[7413],{"type":27,"value":7408},{"type":21,"tag":54,"props":7415,"children":7416},{},[7417,7419,7425,7426,7432,7433,7439],{"type":27,"value":7418},"正文可引用变量：",{"type":21,"tag":141,"props":7420,"children":7422},{"className":7421},[],[7423],{"type":27,"value":7424},"${approvalRequest.TYPE}",{"type":27,"value":1845},{"type":21,"tag":141,"props":7427,"children":7429},{"className":7428},[],[7430],{"type":27,"value":7431},"${approvalRequest.REQUESTOR}",{"type":27,"value":1845},{"type":21,"tag":141,"props":7434,"children":7436},{"className":7435},[],[7437],{"type":27,"value":7438},"${approvalRequest.WORKFLOWSTATE}",{"type":27,"value":7440}," 等。",{"type":21,"tag":150,"props":7442,"children":7444},{"id":7443},"_84-绑定到具体动作",[7445],{"type":27,"value":7446},"8.4 绑定到具体动作",{"type":21,"tag":36,"props":7448,"children":7449},{},[7450],{"type":21,"tag":42,"props":7451,"children":7452},{},[7453],{"type":27,"value":7454},"End Entity Profile：",{"type":21,"tag":182,"props":7456,"children":7458},{"code":7457},"CA Functions → End Entity Profiles → \u003CProfile> → Approval Settings → 勾选需要审批的操作（如Add\u002FEdit End Entity） → 选择上面创建的 Approval Profile → Save\n",[7459],{"type":21,"tag":141,"props":7460,"children":7461},{"__ignoreMap":7},[7462],{"type":27,"value":7457},{"type":21,"tag":36,"props":7464,"children":7465},{},[7466,7468,7473,7474,7479],{"type":27,"value":7467},"常用勾选：",{"type":21,"tag":141,"props":7469,"children":7471},{"className":7470},[],[7472],{"type":27,"value":3152},{"type":27,"value":1845},{"type":21,"tag":141,"props":7475,"children":7477},{"className":7476},[],[7478],{"type":27,"value":3173},{"type":27,"value":7480},"（若启用）。",{"type":21,"tag":36,"props":7482,"children":7483},{},[7484],{"type":21,"tag":42,"props":7485,"children":7486},{},[7487],{"type":27,"value":7488},"Certificate Profile：",{"type":21,"tag":182,"props":7490,"children":7492},{"code":7491},"CA Functions → Certificate Profiles → \u003CProfile> → Approval Settings → 勾选相关操作 → 选择 Approval Profile → Save\n",[7493],{"type":21,"tag":141,"props":7494,"children":7495},{"__ignoreMap":7},[7496],{"type":27,"value":7491},{"type":21,"tag":36,"props":7498,"children":7499},{},[7500,7505,7507,7513],{"type":21,"tag":42,"props":7501,"children":7502},{},[7503],{"type":27,"value":7504},"管理员敏感动作：",{"type":27,"value":7506}," 中间 CA 变更、吊销等建议使用 ",{"type":21,"tag":141,"props":7508,"children":7510},{"className":7509},[],[7511],{"type":27,"value":7512},"2-of-2",{"type":27,"value":7514}," 或分区审批。",{"type":21,"tag":150,"props":7516,"children":7518},{"id":7517},"_85-测试与验证",[7519],{"type":27,"value":7520},"8.5 测试与验证",{"type":21,"tag":546,"props":7522,"children":7523},{},[7524,7529,7542],{"type":21,"tag":54,"props":7525,"children":7526},{},[7527],{"type":27,"value":7528},"用一个普通 RA 账号在 RA Web 发起一次需要审批的操作（如创建 End Entity）。",{"type":21,"tag":54,"props":7530,"children":7531},{},[7532,7534,7540],{"type":27,"value":7533},"到 ",{"type":21,"tag":141,"props":7535,"children":7537},{"className":7536},[],[7538],{"type":27,"value":7539},"监察员功能 → Approvals",{"type":27,"value":7541}," 查看待审批队列，使用另一个审批员账号完成审批。",{"type":21,"tag":54,"props":7543,"children":7544},{},[7545],{"type":27,"value":7546},"确认操作自动执行，且邮件通知正常到达。",{"type":21,"tag":150,"props":7548,"children":7550},{"id":7549},"_86-常见问题",[7551],{"type":27,"value":7552},"8.6 常见问题",{"type":21,"tag":50,"props":7554,"children":7555},{},[7556,7566,7582,7598],{"type":21,"tag":54,"props":7557,"children":7558},{},[7559,7564],{"type":21,"tag":42,"props":7560,"children":7561},{},[7562],{"type":27,"value":7563},"邮件收不到",{"type":27,"value":7565},"：检查 SMTP 配置、防火墙、收件人拼写；查看容器日志。",{"type":21,"tag":54,"props":7567,"children":7568},{},[7569,7574,7575,7580],{"type":21,"tag":42,"props":7570,"children":7571},{},[7572],{"type":27,"value":7573},"一直待审批",{"type":27,"value":651},{"type":21,"tag":141,"props":7576,"children":7578},{"className":7577},[],[7579],{"type":27,"value":7330},{"type":27,"value":7581}," 设置过高或审批人不具备权限。",{"type":21,"tag":54,"props":7583,"children":7584},{},[7585,7590,7592,7596],{"type":21,"tag":42,"props":7586,"children":7587},{},[7588],{"type":27,"value":7589},"能自批",{"type":27,"value":7591},"：误勾选了 ",{"type":21,"tag":2135,"props":7593,"children":7594},{},[7595],{"type":27,"value":7305},{"type":27,"value":7597},"；生产应关闭。",{"type":21,"tag":54,"props":7599,"children":7600},{},[7601,7606,7607,7613,7615,7621],{"type":21,"tag":42,"props":7602,"children":7603},{},[7604],{"type":27,"value":7605},"过期作废",{"type":27,"value":651},{"type":21,"tag":141,"props":7608,"children":7610},{"className":7609},[],[7611],{"type":27,"value":7612},"Request\u002FApproval Expiration",{"type":27,"value":7614}," 设置过短；可调到 ",{"type":21,"tag":141,"props":7616,"children":7618},{"className":7617},[],[7619],{"type":27,"value":7620},"8–24h",{"type":27,"value":1732},{"type":21,"tag":65,"props":7623,"children":7624},{},[],{"type":21,"tag":29,"props":7626,"children":7628},{"id":7627},"_9-终端实体模板设置",[7629],{"type":27,"value":7630},"9. 终端实体模板设置",{"type":21,"tag":531,"props":7632,"children":7633},{},[7634],{"type":21,"tag":36,"props":7635,"children":7636},{},[7637,7639,7644],{"type":27,"value":7638},"位置：",{"type":21,"tag":42,"props":7640,"children":7641},{},[7642],{"type":27,"value":7643},"RA Functions → End Entity Profiles",{"type":27,"value":7645},"。终端实体模板（End Entity Profile）决定了“能填哪些字段”“哪些必填\u002F可改”“默认使用哪个证书模板\u002FCA\u002FToken”。",{"type":21,"tag":150,"props":7647,"children":7649},{"id":7648},"_91-新建与进入",[7650],{"type":27,"value":7651},"9.1 新建与进入",{"type":21,"tag":546,"props":7653,"children":7654},{},[7655],{"type":21,"tag":54,"props":7656,"children":7657},{},[7658],{"type":27,"value":7158},{"type":21,"tag":182,"props":7660,"children":7662},{"code":7661},"RA Functions → End Entity Profiles\n",[7663],{"type":21,"tag":141,"props":7664,"children":7665},{"__ignoreMap":7},[7666],{"type":27,"value":7661},{"type":21,"tag":546,"props":7668,"children":7669},{},[7670,7688],{"type":21,"tag":54,"props":7671,"children":7672},{},[7673,7675,7680,7682,7687],{"type":27,"value":7674},"在底部输入模板名（如 ",{"type":21,"tag":141,"props":7676,"children":7678},{"className":7677},[],[7679],{"type":27,"value":5040},{"type":27,"value":7681},"）→ ",{"type":21,"tag":42,"props":7683,"children":7684},{},[7685],{"type":27,"value":7686},"添加模板",{"type":27,"value":1732},{"type":21,"tag":54,"props":7689,"children":7690},{},[7691,7693,7698],{"type":27,"value":7692},"在列表中选中该模板 → ",{"type":21,"tag":42,"props":7694,"children":7695},{},[7696],{"type":27,"value":7697},"编辑终端实体模板",{"type":27,"value":1732},{"type":21,"tag":150,"props":7700,"children":7702},{"id":7701},"_92-基本信息用户名密码邮箱",[7703],{"type":27,"value":7704},"9.2 基本信息（用户名\u002F密码\u002F邮箱）",{"type":21,"tag":531,"props":7706,"children":7707},{},[7708],{"type":21,"tag":36,"props":7709,"children":7710},{},[7711,7716,7718,7723,7725,7730,7732,7737],{"type":21,"tag":42,"props":7712,"children":7713},{},[7714],{"type":27,"value":7715},"是否必须提前填？",{"type":27,"value":7717}," 通常 ",{"type":21,"tag":42,"props":7719,"children":7720},{},[7721],{"type":27,"value":7722},"不需要",{"type":27,"value":7724}," 在模板里写死具体“用户名\u002F密码”。模板里只定义“规则与方式”，具体的 ",{"type":21,"tag":42,"props":7726,"children":7727},{},[7728],{"type":27,"value":7729},"Username\u002FPassword\u002FEnrollment Code",{"type":27,"value":7731}," 在",{"type":21,"tag":42,"props":7733,"children":7734},{},[7735],{"type":27,"value":7736},"创建 End Entity 或申请时",{"type":27,"value":7738},"填写即可。",{"type":21,"tag":36,"props":7740,"children":7741},{},[7742],{"type":21,"tag":42,"props":7743,"children":7744},{},[7745],{"type":27,"value":7746},"推荐做法",{"type":21,"tag":50,"props":7748,"children":7749},{},[7750,7766,7791,7801,7819,7828],{"type":21,"tag":54,"props":7751,"children":7752},{},[7753,7757,7758,7764],{"type":21,"tag":42,"props":7754,"children":7755},{},[7756],{"type":27,"value":4953},{"type":27,"value":1911},{"type":21,"tag":141,"props":7759,"children":7761},{"className":7760},[],[7762],{"type":27,"value":7763},"Auto-generated",{"type":27,"value":7765},"（批量\u002F自动化最方便），或在创建 End Entity 时手动指定。",{"type":21,"tag":54,"props":7767,"children":7768},{},[7769,7774,7776,7782,7784,7789],{"type":21,"tag":42,"props":7770,"children":7771},{},[7772],{"type":27,"value":7773},"Password (or Enrollment Code)",{"type":27,"value":7775},"：勾选 ",{"type":21,"tag":141,"props":7777,"children":7779},{"className":7778},[],[7780],{"type":27,"value":7781},"Required",{"type":27,"value":7783},"，作为一次性 ",{"type":21,"tag":42,"props":7785,"children":7786},{},[7787],{"type":27,"value":7788},"Enrollment Code",{"type":27,"value":7790}," 使用；具体值在创建 End Entity 或 RA 端申请时再填。",{"type":21,"tag":54,"props":7792,"children":7793},{},[7794,7799],{"type":21,"tag":42,"props":7795,"children":7796},{},[7797],{"type":27,"value":7798},"Minimum password strength \u002F length",{"type":27,"value":7800},"：保持策略（如长度 ≥ 8），但不在模板里填具体密码。",{"type":21,"tag":54,"props":7802,"children":7803},{},[7804,7809,7811,7817],{"type":21,"tag":42,"props":7805,"children":7806},{},[7807],{"type":27,"value":7808},"Maximum number of failed login attempts",{"type":27,"value":7810},"：按需限制；可勾 ",{"type":21,"tag":141,"props":7812,"children":7814},{"className":7813},[],[7815],{"type":27,"value":7816},"Modifiable",{"type":27,"value":7818}," 便于临时调整。",{"type":21,"tag":54,"props":7820,"children":7821},{},[7822,7826],{"type":21,"tag":42,"props":7823,"children":7824},{},[7825],{"type":27,"value":4991},{"type":27,"value":7827},"：一般关闭；避免明文存储 Enrollment Code。",{"type":21,"tag":54,"props":7829,"children":7830},{},[7831,7835,7837,7843],{"type":21,"tag":42,"props":7832,"children":7833},{},[7834],{"type":27,"value":5004},{"type":27,"value":7836},"：按业务是否 ",{"type":21,"tag":141,"props":7838,"children":7840},{"className":7839},[],[7841],{"type":27,"value":7842},"Required\u002FModifiable",{"type":27,"value":7844},"，便于通知与标识。",{"type":21,"tag":36,"props":7846,"children":7847},{},[7848],{"type":21,"tag":42,"props":7849,"children":7850},{},[7851],{"type":27,"value":7852},"不同申请路径对 Username\u002FPassword 的影响",{"type":21,"tag":50,"props":7854,"children":7855},{},[7856,7881,7905],{"type":21,"tag":54,"props":7857,"children":7858},{},[7859,7864,7866,7871,7873,7879],{"type":21,"tag":42,"props":7860,"children":7861},{},[7862],{"type":27,"value":7863},"RA Web → Enroll → Use Username",{"type":27,"value":7865},"：创建 End Entity 时需要指定 ",{"type":21,"tag":141,"props":7867,"children":7869},{"className":7868},[],[7870],{"type":27,"value":4953},{"type":27,"value":7872}," 与 ",{"type":21,"tag":141,"props":7874,"children":7876},{"className":7875},[],[7877],{"type":27,"value":7878},"Password\u002FEnrollment Code",{"type":27,"value":7880},"，用户用该账号登录领取证书。",{"type":21,"tag":54,"props":7882,"children":7883},{},[7884,7889,7891,7897,7898,7903],{"type":21,"tag":42,"props":7885,"children":7886},{},[7887],{"type":27,"value":7888},"RA Web → Enroll → Use Request ID",{"type":27,"value":7890},"：由系统分配 ",{"type":21,"tag":141,"props":7892,"children":7894},{"className":7893},[],[7895],{"type":27,"value":7896},"Request ID",{"type":27,"value":5436},{"type":21,"tag":141,"props":7899,"children":7901},{"className":7900},[],[7902],{"type":27,"value":7878},{"type":27,"value":7904}," 在创建时设置，申请人用 ID+Code 领取。",{"type":21,"tag":54,"props":7906,"children":7907},{},[7908,7913,7914,7920,7922,7927],{"type":21,"tag":42,"props":7909,"children":7910},{},[7911],{"type":27,"value":7912},"User Generated（CSR 提交）",{"type":27,"value":651},{"type":21,"tag":141,"props":7915,"children":7917},{"className":7916},[],[7918],{"type":27,"value":7919},"Token=User Generated",{"type":27,"value":7921},"；保留 ",{"type":21,"tag":141,"props":7923,"children":7925},{"className":7924},[],[7926],{"type":27,"value":7781},{"type":27,"value":7928}," 以生成一次性代码，申请人用 CSR+Code 完成签发。",{"type":21,"tag":36,"props":7930,"children":7931},{},[7932],{"type":21,"tag":42,"props":7933,"children":7934},{},[7935],{"type":27,"value":7936},"Directives（指令）",{"type":21,"tag":50,"props":7938,"children":7939},{},[7940,7951,7969],{"type":21,"tag":54,"props":7941,"children":7942},{},[7943,7949],{"type":21,"tag":141,"props":7944,"children":7946},{"className":7945},[],[7947],{"type":27,"value":7948},"Reverse Subject DN and Subject Alt Name Checks",{"type":27,"value":7950},"：不勾也可以。",{"type":21,"tag":54,"props":7952,"children":7953},{},[7954,7960,7962,7967],{"type":21,"tag":141,"props":7955,"children":7957},{"className":7956},[],[7958],{"type":27,"value":7959},"Allow merge DN for all interfaces",{"type":27,"value":7961},"：通常 ",{"type":21,"tag":42,"props":7963,"children":7964},{},[7965],{"type":27,"value":7966},"不勾",{"type":27,"value":7968},"，仅在多接口需要聚合 DN 时启用。",{"type":21,"tag":54,"props":7970,"children":7971},{},[7972,7978],{"type":21,"tag":141,"props":7973,"children":7975},{"className":7974},[],[7976],{"type":27,"value":7977},"Allow multi-value RDNs",{"type":27,"value":7979},"：仅特殊需求启用（默认关闭更安全）。",{"type":21,"tag":150,"props":7981,"children":7983},{"id":7982},"_93-主体-dn-属性subject-dn-attributes需要自己添加",[7984,7986],{"type":27,"value":7985},"9.3 主体 DN 属性（Subject DN Attributes）—",{"type":21,"tag":42,"props":7987,"children":7988},{},[7989],{"type":27,"value":7990},"需要自己添加",{"type":21,"tag":531,"props":7992,"children":7993},{},[7994],{"type":21,"tag":36,"props":7995,"children":7996},{},[7997,7999,8004],{"type":27,"value":7998},"左侧是“可选属性”，右侧是“已选属性”。把需要的字段添加到右侧，并为每个字段设置 ",{"type":21,"tag":42,"props":8000,"children":8001},{},[8002],{"type":27,"value":8003},"Required \u002F Modifiable \u002F Validation",{"type":27,"value":1732},{"type":21,"tag":36,"props":8006,"children":8007},{},[8008],{"type":21,"tag":42,"props":8009,"children":8010},{},[8011],{"type":27,"value":8012},"常见推荐（客户端\u002F通用）：",{"type":21,"tag":2192,"props":8014,"children":8015},{},[8016,8030],{"type":21,"tag":2196,"props":8017,"children":8018},{},[8019],{"type":21,"tag":2200,"props":8020,"children":8021},{},[8022,8026],{"type":21,"tag":2204,"props":8023,"children":8024},{},[8025],{"type":27,"value":4724},{"type":21,"tag":2204,"props":8027,"children":8028},{},[8029],{"type":27,"value":6625},{"type":21,"tag":2221,"props":8031,"children":8032},{},[8033,8060,8081,8112],{"type":21,"tag":2200,"props":8034,"children":8035},{},[8036,8045],{"type":21,"tag":2228,"props":8037,"children":8038},{},[8039],{"type":21,"tag":141,"props":8040,"children":8042},{"className":8041},[],[8043],{"type":27,"value":8044},"CN, Common name",{"type":21,"tag":2228,"props":8046,"children":8047},{},[8048,8052,8053,8058],{"type":21,"tag":42,"props":8049,"children":8050},{},[8051],{"type":27,"value":7781},{"type":27,"value":2084},{"type":21,"tag":141,"props":8054,"children":8056},{"className":8055},[],[8057],{"type":27,"value":7816},{"type":27,"value":8059}," 由 RA 决定",{"type":21,"tag":2200,"props":8061,"children":8062},{},[8063,8072],{"type":21,"tag":2228,"props":8064,"children":8065},{},[8066],{"type":21,"tag":141,"props":8067,"children":8069},{"className":8068},[],[8070],{"type":27,"value":8071},"emailAddress, E-mail address in DN",{"type":21,"tag":2228,"props":8073,"children":8074},{},[8075,8077],{"type":27,"value":8076},"选配；如需与邮件系统绑定可 ",{"type":21,"tag":42,"props":8078,"children":8079},{},[8080],{"type":27,"value":7781},{"type":21,"tag":2200,"props":8082,"children":8083},{},[8084,8101],{"type":21,"tag":2228,"props":8085,"children":8086},{},[8087,8093,8095],{"type":21,"tag":141,"props":8088,"children":8090},{"className":8089},[],[8091],{"type":27,"value":8092},"O, Organization",{"type":27,"value":8094}," \u002F ",{"type":21,"tag":141,"props":8096,"children":8098},{"className":8097},[],[8099],{"type":27,"value":8100},"OU, Org. Unit",{"type":21,"tag":2228,"props":8102,"children":8103},{},[8104,8106,8110],{"type":27,"value":8105},"视业务；建议 ",{"type":21,"tag":42,"props":8107,"children":8108},{},[8109],{"type":27,"value":7816},{"type":27,"value":8111}," 关闭以避免乱填",{"type":21,"tag":2200,"props":8113,"children":8114},{},[8115,8124],{"type":21,"tag":2228,"props":8116,"children":8117},{},[8118],{"type":21,"tag":141,"props":8119,"children":8121},{"className":8120},[],[8122],{"type":27,"value":8123},"C, Country",{"type":21,"tag":2228,"props":8125,"children":8126},{},[8127,8129,8134],{"type":27,"value":8128},"固定为 ",{"type":21,"tag":141,"props":8130,"children":8132},{"className":8131},[],[8133],{"type":27,"value":5022},{"type":27,"value":8135}," 或所在国家；通常不允许修改",{"type":21,"tag":531,"props":8137,"children":8138},{},[8139],{"type":21,"tag":36,"props":8140,"children":8141},{},[8142,8144,8149],{"type":27,"value":8143},"若需要更严格的校验，可在 ",{"type":21,"tag":42,"props":8145,"children":8146},{},[8147],{"type":27,"value":8148},"Validation",{"type":27,"value":8150}," 指定正则\u002F格式规则。",{"type":21,"tag":150,"props":8152,"children":8154},{"id":8153},"_94-其他主体属性other-subject-attributes需要自己添加",[8155,8157],{"type":27,"value":8156},"9.4 其他主体属性（Other Subject Attributes）—",{"type":21,"tag":42,"props":8158,"children":8159},{},[8160],{"type":27,"value":7990},{"type":21,"tag":36,"props":8162,"children":8163},{},[8164,8169],{"type":21,"tag":42,"props":8165,"children":8166},{},[8167],{"type":27,"value":8168},"Subject Alternative Name（SAN）",{"type":27,"value":651},{"type":21,"tag":50,"props":8171,"children":8172},{},[8173,8186,8206],{"type":21,"tag":54,"props":8174,"children":8175},{},[8176,8178,8184],{"type":27,"value":8177},"客户端证书：",{"type":21,"tag":141,"props":8179,"children":8181},{"className":8180},[],[8182],{"type":27,"value":8183},"RFC 822 Name (e-mail address)",{"type":27,"value":8185},"（与账户邮箱一致）",{"type":21,"tag":54,"props":8187,"children":8188},{},[8189,8191,8197,8198,8204],{"type":27,"value":8190},"服务器证书：",{"type":21,"tag":141,"props":8192,"children":8194},{"className":8193},[],[8195],{"type":27,"value":8196},"DNS Name",{"type":27,"value":1845},{"type":21,"tag":141,"props":8199,"children":8201},{"className":8200},[],[8202],{"type":27,"value":8203},"IP Address",{"type":27,"value":8205},"（按域名\u002FIP 添加）",{"type":21,"tag":54,"props":8207,"children":8208},{},[8209,8211,8217],{"type":27,"value":8210},"设备证书：",{"type":21,"tag":141,"props":8212,"children":8214},{"className":8213},[],[8215],{"type":27,"value":8216},"OtherName",{"type":27,"value":8218},"（写入设备 ID\u002FOID）",{"type":21,"tag":36,"props":8220,"children":8221},{},[8222,8227],{"type":21,"tag":42,"props":8223,"children":8224},{},[8225],{"type":27,"value":8226},"Subject Directory Attributes",{"type":27,"value":8228},"（可选）：",{"type":21,"tag":50,"props":8230,"children":8231},{},[8232],{"type":21,"tag":54,"props":8233,"children":8234},{},[8235,8237,8243],{"type":27,"value":8236},"仅在需要存档\u002F合规时使用，例如 ",{"type":21,"tag":141,"props":8238,"children":8240},{"className":8239},[],[8241],{"type":27,"value":8242},"Date of birth (YYYYMMDD)",{"type":27,"value":8244}," 等；默认不建议开启过多目录属性。",{"type":21,"tag":531,"props":8246,"children":8247},{},[8248],{"type":21,"tag":36,"props":8249,"children":8250},{},[8251,8253,8258,8260,8264,8266,8271],{"type":27,"value":8252},"添加方法：在 ",{"type":21,"tag":42,"props":8254,"children":8255},{},[8256],{"type":27,"value":8257},"Other Subject Attributes",{"type":27,"value":8259}," 区域选择条目 → ",{"type":21,"tag":42,"props":8261,"children":8262},{},[8263],{"type":27,"value":7187},{"type":27,"value":8265}," 到右侧；如界面支持，可设置 ",{"type":21,"tag":141,"props":8267,"children":8269},{"className":8268},[],[8270],{"type":27,"value":7842},{"type":27,"value":1732},{"type":21,"tag":150,"props":8273,"children":8275},{"id":8274},"_95-主要证书数据main-certificate-data",[8276],{"type":27,"value":8277},"9.5 主要证书数据（Main Certificate Data）",{"type":21,"tag":2192,"props":8279,"children":8280},{},[8281,8296],{"type":21,"tag":2196,"props":8282,"children":8283},{},[8284],{"type":21,"tag":2200,"props":8285,"children":8286},{},[8287,8291],{"type":21,"tag":2204,"props":8288,"children":8289},{},[8290],{"type":27,"value":4724},{"type":21,"tag":2204,"props":8292,"children":8293},{},[8294],{"type":27,"value":8295},"建议\u002F说明",{"type":21,"tag":2221,"props":8297,"children":8298},{},[8299,8328,8344,8371],{"type":21,"tag":2200,"props":8300,"children":8301},{},[8302,8310],{"type":21,"tag":2228,"props":8303,"children":8304},{},[8305],{"type":21,"tag":42,"props":8306,"children":8307},{},[8308],{"type":27,"value":8309},"Default Certificate Profile",{"type":21,"tag":2228,"props":8311,"children":8312},{},[8313,8315,8320,8321,8327],{"type":27,"value":8314},"选择目标证书模板（如 ",{"type":21,"tag":141,"props":8316,"children":8318},{"className":8317},[],[8319],{"type":27,"value":1799},{"type":27,"value":8094},{"type":21,"tag":141,"props":8322,"children":8324},{"className":8323},[],[8325],{"type":27,"value":8326},"SERVER",{"type":27,"value":3775},{"type":21,"tag":2200,"props":8329,"children":8330},{},[8331,8339],{"type":21,"tag":2228,"props":8332,"children":8333},{},[8334],{"type":21,"tag":42,"props":8335,"children":8336},{},[8337],{"type":27,"value":8338},"Available Certificate Profiles",{"type":21,"tag":2228,"props":8340,"children":8341},{},[8342],{"type":27,"value":8343},"仅勾选允许使用的模板，避免误选",{"type":21,"tag":2200,"props":8345,"children":8346},{},[8347,8361],{"type":21,"tag":2228,"props":8348,"children":8349},{},[8350,8355,8356],{"type":21,"tag":42,"props":8351,"children":8352},{},[8353],{"type":27,"value":8354},"Default CA",{"type":27,"value":8094},{"type":21,"tag":42,"props":8357,"children":8358},{},[8359],{"type":27,"value":8360},"Available CAs",{"type":21,"tag":2228,"props":8362,"children":8363},{},[8364,8366],{"type":27,"value":8365},"指定可签发的 CA；",{"type":21,"tag":42,"props":8367,"children":8368},{},[8369],{"type":27,"value":8370},"注意：修改可用 CA 会影响角色对此 Profile 的访问",{"type":21,"tag":2200,"props":8372,"children":8373},{},[8374,8388],{"type":21,"tag":2228,"props":8375,"children":8376},{},[8377,8382,8383],{"type":21,"tag":42,"props":8378,"children":8379},{},[8380],{"type":27,"value":8381},"Default Token",{"type":27,"value":8094},{"type":21,"tag":42,"props":8384,"children":8385},{},[8386],{"type":27,"value":8387},"Available Tokens",{"type":21,"tag":2228,"props":8389,"children":8390},{},[8391,8396,8398,8404],{"type":21,"tag":141,"props":8392,"children":8394},{"className":8393},[],[8395],{"type":27,"value":5089},{"type":27,"value":8397},"（RA 直接下载 p12）或 ",{"type":21,"tag":141,"props":8399,"children":8401},{"className":8400},[],[8402],{"type":27,"value":8403},"User Generated",{"type":27,"value":8405},"（用户自带 CSR）",{"type":21,"tag":150,"props":8407,"children":8409},{"id":8408},"_96-其他证书数据other-certificate-data",[8410],{"type":27,"value":8411},"9.6 其他证书数据（Other Certificate Data）",{"type":21,"tag":50,"props":8413,"children":8414},{},[8415,8426,8448,8459],{"type":21,"tag":54,"props":8416,"children":8417},{},[8418,8424],{"type":21,"tag":141,"props":8419,"children":8421},{"className":8420},[],[8422],{"type":27,"value":8423},"Custom certificate serial number",{"type":27,"value":8425},"：默认关闭",{"type":21,"tag":54,"props":8427,"children":8428},{},[8429,8435,8437,8441,8443],{"type":21,"tag":141,"props":8430,"children":8432},{"className":8431},[],[8433],{"type":27,"value":8434},"Certificate Validity Start\u002FEnd Time",{"type":27,"value":8436},"：默认由 ",{"type":21,"tag":42,"props":8438,"children":8439},{},[8440],{"type":27,"value":2624},{"type":27,"value":8442}," 控制；如需临时证书可开启并 ",{"type":21,"tag":141,"props":8444,"children":8446},{"className":8445},[],[8447],{"type":27,"value":7816},{"type":21,"tag":54,"props":8449,"children":8450},{},[8451,8457],{"type":21,"tag":141,"props":8452,"children":8454},{"className":8453},[],[8455],{"type":27,"value":8456},"Name Constraints (Permitted\u002FExcluded)",{"type":27,"value":8458},"：一般用于中间 CA；终端实体模板通常不启用",{"type":21,"tag":54,"props":8460,"children":8461},{},[8462,8468,8469,8475,8476,8482],{"type":21,"tag":141,"props":8463,"children":8465},{"className":8464},[],[8466],{"type":27,"value":8467},"Custom certificate extension data",{"type":27,"value":8094},{"type":21,"tag":141,"props":8470,"children":8472},{"className":8471},[],[8473],{"type":27,"value":8474},"ETSI PSD2 QC Statement",{"type":27,"value":8094},{"type":21,"tag":141,"props":8477,"children":8479},{"className":8478},[],[8480],{"type":27,"value":8481},"CA\u002FB Forum Organization Identifier",{"type":27,"value":8483},"：按合规需要开启",{"type":21,"tag":150,"props":8485,"children":8487},{"id":8486},"_97-其他数据与限制other-data-restrictions",[8488],{"type":27,"value":8489},"9.7 其他数据与限制（Other Data \u002F Restrictions）",{"type":21,"tag":2192,"props":8491,"children":8492},{},[8493,8507],{"type":21,"tag":2196,"props":8494,"children":8495},{},[8496],{"type":21,"tag":2200,"props":8497,"children":8498},{},[8499,8503],{"type":21,"tag":2204,"props":8500,"children":8501},{},[8502],{"type":27,"value":4724},{"type":21,"tag":2204,"props":8504,"children":8505},{},[8506],{"type":27,"value":6625},{"type":21,"tag":2221,"props":8508,"children":8509},{},[8510,8532,8562,8586,8603],{"type":21,"tag":2200,"props":8511,"children":8512},{},[8513,8522],{"type":21,"tag":2228,"props":8514,"children":8515},{},[8516],{"type":21,"tag":141,"props":8517,"children":8519},{"className":8518},[],[8520],{"type":27,"value":8521},"Number of allowed requests",{"type":21,"tag":2228,"props":8523,"children":8524},{},[8525,8530],{"type":21,"tag":141,"props":8526,"children":8528},{"className":8527},[],[8529],{"type":27,"value":7345},{"type":27,"value":8531},"（防多次重复签发）",{"type":21,"tag":2200,"props":8533,"children":8534},{},[8535,8544],{"type":21,"tag":2228,"props":8536,"children":8537},{},[8538],{"type":21,"tag":141,"props":8539,"children":8541},{"className":8540},[],[8542],{"type":27,"value":8543},"Allow renewal before expiration",{"type":21,"tag":2228,"props":8545,"children":8546},{},[8547,8548,8554,8556],{"type":27,"value":4005},{"type":21,"tag":141,"props":8549,"children":8551},{"className":8550},[],[8552],{"type":27,"value":8553},"30",{"type":27,"value":8555}," 天；如不限制填 ",{"type":21,"tag":141,"props":8557,"children":8559},{"className":8558},[],[8560],{"type":27,"value":8561},"-1",{"type":21,"tag":2200,"props":8563,"children":8564},{},[8565,8574],{"type":21,"tag":2228,"props":8566,"children":8567},{},[8568],{"type":21,"tag":141,"props":8569,"children":8571},{"className":8570},[],[8572],{"type":27,"value":8573},"Revocation reason to set after certificate issuance",{"type":21,"tag":2228,"props":8575,"children":8576},{},[8577,8579,8584],{"type":27,"value":8578},"默认 ",{"type":21,"tag":141,"props":8580,"children":8582},{"className":8581},[],[8583],{"type":27,"value":1975},{"type":27,"value":8585},"（一般不改）",{"type":21,"tag":2200,"props":8587,"children":8588},{},[8589,8598],{"type":21,"tag":2228,"props":8590,"children":8591},{},[8592],{"type":21,"tag":141,"props":8593,"children":8595},{"className":8594},[],[8596],{"type":27,"value":8597},"Redact Subject Name from logs",{"type":21,"tag":2228,"props":8599,"children":8600},{},[8601],{"type":27,"value":8602},"仅在隐私\u002F合规强需求时开启",{"type":21,"tag":2200,"props":8604,"children":8605},{},[8606,8615],{"type":21,"tag":2228,"props":8607,"children":8608},{},[8609],{"type":21,"tag":141,"props":8610,"children":8612},{"className":8611},[],[8613],{"type":27,"value":8614},"Send Notification",{"type":21,"tag":2228,"props":8616,"children":8617},{},[8618],{"type":27,"value":8619},"按需；与 SMTP 配置关联",{"type":21,"tag":150,"props":8621,"children":8623},{"id":8622},"_98-保存与授权",[8624],{"type":27,"value":8625},"9.8 保存与授权",{"type":21,"tag":546,"props":8627,"children":8628},{},[8629,8639,8650],{"type":21,"tag":54,"props":8630,"children":8631},{},[8632,8633,8638],{"type":27,"value":1806},{"type":21,"tag":42,"props":8634,"children":8635},{},[8636],{"type":27,"value":8637},"保存",{"type":27,"value":1732},{"type":21,"tag":54,"props":8640,"children":8641},{},[8642,8643,8648],{"type":27,"value":7533},{"type":21,"tag":42,"props":8644,"children":8645},{},[8646],{"type":27,"value":8647},"RA Web → Role Management",{"type":27,"value":8649}," 确认相关角色已被授权“使用此 End Entity Profile”（可见\u002F可创建）。",{"type":21,"tag":54,"props":8651,"children":8652},{},[8653,8654,8659,8661],{"type":27,"value":2001},{"type":21,"tag":42,"props":8655,"children":8656},{},[8657],{"type":27,"value":8658},"Search → End Entities",{"type":27,"value":8660}," 使用该模板创建测试用户，验证：\n",{"type":21,"tag":50,"props":8662,"children":8663},{},[8664,8669,8680],{"type":21,"tag":54,"props":8665,"children":8666},{},[8667],{"type":27,"value":8668},"DN\u002FSAN 是否按规则入库；",{"type":21,"tag":54,"props":8670,"children":8671},{},[8672,8674,8679],{"type":27,"value":8673},"证书是否使用了期望的 ",{"type":21,"tag":42,"props":8675,"children":8676},{},[8677],{"type":27,"value":8678},"Certificate Profile\u002FCA\u002FToken",{"type":27,"value":2084},{"type":21,"tag":54,"props":8681,"children":8682},{},[8683],{"type":27,"value":8684},"下载\u002F导入是否成功（P12\u002FPEM\u002FCSR 流程）。",{"type":21,"tag":65,"props":8686,"children":8687},{},[],{"type":21,"tag":29,"props":8689,"children":8691},{"id":8690},"_10-ra-普通用户申请终端证书",[8692],{"type":27,"value":8693},"10. RA 普通用户申请终端证书",{"type":21,"tag":531,"props":8695,"children":8696},{},[8697,8707],{"type":21,"tag":36,"props":8698,"children":8699},{},[8700,8701,8706],{"type":27,"value":7638},{"type":21,"tag":42,"props":8702,"children":8703},{},[8704],{"type":27,"value":8705},"RA Web → Enroll",{"type":27,"value":1732},{"type":21,"tag":36,"props":8708,"children":8709},{},[8710,8715,8717,8722],{"type":21,"tag":42,"props":8711,"children":8712},{},[8713],{"type":27,"value":8714},"默认建议：优先使用",{"type":27,"value":8716}," ",{"type":21,"tag":42,"props":8718,"children":8719},{},[8720],{"type":27,"value":8721},"By the CA",{"type":27,"value":8723},"（CA 端生成密钥），无需 CSR，流程最稳、最少出错。",{"type":21,"tag":150,"props":8725,"children":8727},{"id":8726},"_101-路径与前置",[8728],{"type":27,"value":8729},"10.1 路径与前置",{"type":21,"tag":50,"props":8731,"children":8732},{},[8733,8752],{"type":21,"tag":54,"props":8734,"children":8735},{},[8736,8738,8743,8745,8750],{"type":27,"value":8737},"已在 ",{"type":21,"tag":42,"props":8739,"children":8740},{},[8741],{"type":27,"value":8742},"End Entity Profiles",{"type":27,"value":8744},"（第 9 节）与 ",{"type":21,"tag":42,"props":8746,"children":8747},{},[8748],{"type":27,"value":8749},"Certificate Profiles",{"type":27,"value":8751}," 准备好模板；用户具备访问权限。",{"type":21,"tag":54,"props":8753,"children":8754},{},[8755],{"type":27,"value":8756},"若启用审批（第 8 节），提交后会进入待审队列，审批通过才签发。",{"type":21,"tag":150,"props":8758,"children":8760},{"id":8759},"_102-推荐by-the-ca无需-csr",[8761],{"type":27,"value":8762},"10.2 推荐：By the CA（无需 CSR）",{"type":21,"tag":546,"props":8764,"children":8765},{},[8766],{"type":21,"tag":54,"props":8767,"children":8768},{},[8769],{"type":27,"value":7158},{"type":21,"tag":182,"props":8771,"children":8773},{"code":8772},"Enroll → Make New Request\n",[8774],{"type":21,"tag":141,"props":8775,"children":8776},{"__ignoreMap":7},[8777],{"type":27,"value":8772},{"type":21,"tag":546,"props":8779,"children":8780},{},[8781,8800,8816,8835],{"type":21,"tag":54,"props":8782,"children":8783},{},[8784,8786,8791,8793,8798],{"type":27,"value":8785},"选择 ",{"type":21,"tag":42,"props":8787,"children":8788},{},[8789],{"type":27,"value":8790},"Certificate Type",{"type":27,"value":8792},"（End Entity Profile）与 ",{"type":21,"tag":42,"props":8794,"children":8795},{},[8796],{"type":27,"value":8797},"Certificate subtype",{"type":27,"value":8799},"（Certificate Profile）。",{"type":21,"tag":54,"props":8801,"children":8802},{},[8803,8804,8809,8811,8815],{"type":27,"value":2001},{"type":21,"tag":42,"props":8805,"children":8806},{},[8807],{"type":27,"value":8808},"Key‑pair generation",{"type":27,"value":8810}," 选择 ",{"type":21,"tag":42,"props":8812,"children":8813},{},[8814],{"type":27,"value":8721},{"type":27,"value":1732},{"type":21,"tag":54,"props":8817,"children":8818},{},[8819,8821,8826,8828,8833],{"type":27,"value":8820},"展开 ",{"type":21,"tag":42,"props":8822,"children":8823},{},[8824],{"type":27,"value":8825},"Provide request info",{"type":27,"value":8827},"，按模板要求填写 ",{"type":21,"tag":42,"props":8829,"children":8830},{},[8831],{"type":27,"value":8832},"Subject DN \u002F SAN",{"type":27,"value":8834},"（如 CN、Email、DNS\u002FIP）。",{"type":21,"tag":54,"props":8836,"children":8837},{},[8838,8840,8846],{"type":27,"value":8839},"下载 ",{"type":21,"tag":141,"props":8841,"children":8843},{"className":8842},[],[8844],{"type":27,"value":8845},"*.p12",{"type":27,"value":1732},{"type":21,"tag":150,"props":8848,"children":8850},{"id":8849},"_103-可选provided-by-user上传-csr",[8851],{"type":27,"value":8852},"10.3 可选：Provided by user（上传 CSR）",{"type":21,"tag":531,"props":8854,"children":8855},{},[8856],{"type":21,"tag":36,"props":8857,"children":8858},{},[8859,8861,8865],{"type":27,"value":8860},"仅当",{"type":21,"tag":42,"props":8862,"children":8863},{},[8864],{"type":27,"value":1642},{"type":27,"value":8866},"在客户端\u002F服务器本地生成密钥（如合规要求、HSM\u002F专用设备、已有密钥迁移）时使用。",{"type":21,"tag":546,"props":8868,"children":8869},{},[8870,8875,8895],{"type":21,"tag":54,"props":8871,"children":8872},{},[8873],{"type":27,"value":8874},"本地生成私钥与 CSR：",{"type":21,"tag":54,"props":8876,"children":8877},{},[8878,8880,8885,8887,8893],{"type":27,"value":8879},"在页面选择 ",{"type":21,"tag":42,"props":8881,"children":8882},{},[8883],{"type":27,"value":8884},"Provided by user",{"type":27,"value":8886},"，将完整 CSR（含 ",{"type":21,"tag":141,"props":8888,"children":8890},{"className":8889},[],[8891],{"type":27,"value":8892},"BEGIN\u002FEND CERTIFICATE REQUEST",{"type":27,"value":8894},"）粘贴到输入框。",{"type":21,"tag":54,"props":8896,"children":8897},{},[8898],{"type":27,"value":8899},"提交并按提示下载证书（不会包含你的私钥）。",{"type":21,"tag":150,"props":8901,"children":8903},{"id":8902},"_104-审批联动与通知",[8904],{"type":27,"value":8905},"10.4 审批联动与通知",{"type":21,"tag":50,"props":8907,"children":8908},{},[8909,8921],{"type":21,"tag":54,"props":8910,"children":8911},{},[8912,8914,8919],{"type":27,"value":8913},"当 Profile 绑定了 ",{"type":21,"tag":42,"props":8915,"children":8916},{},[8917],{"type":27,"value":8918},"Approval Profile",{"type":27,"value":8920}," 时，提交即进入待审；通过后自动签发或开放下载。",{"type":21,"tag":54,"props":8922,"children":8923},{},[8924],{"type":27,"value":8925},"邮件主题\u002F正文遵循第 8 节的通知模板。",{"type":21,"tag":150,"props":8927,"children":8929},{"id":8928},"_105-常见问题",[8930],{"type":27,"value":8931},"10.5 常见问题",{"type":21,"tag":50,"props":8933,"children":8934},{},[8935,8945,8955,8970],{"type":21,"tag":54,"props":8936,"children":8937},{},[8938,8943],{"type":21,"tag":42,"props":8939,"children":8940},{},[8941],{"type":27,"value":8942},"字段不通过",{"type":27,"value":8944},"：DN\u002FSAN 与 Profile 约束不一致；按第 9 节调整。",{"type":21,"tag":54,"props":8946,"children":8947},{},[8948,8953],{"type":21,"tag":42,"props":8949,"children":8950},{},[8951],{"type":27,"value":8952},"不能下载 P12",{"type":27,"value":8954},"：浏览器拦截或口令策略冲突；更换浏览器\u002F检查口令长度与字符集。",{"type":21,"tag":54,"props":8956,"children":8957},{},[8958,8963,8965,8969],{"type":21,"tag":42,"props":8959,"children":8960},{},[8961],{"type":27,"value":8962},"CSR 被拒",{"type":27,"value":8964},"：CSR 中 Subject\u002FSAN 与模板冲突；按模板重建 CSR 或改用 ",{"type":21,"tag":42,"props":8966,"children":8967},{},[8968],{"type":27,"value":8721},{"type":27,"value":1732},{"type":21,"tag":54,"props":8971,"children":8972},{},[8973,8978],{"type":21,"tag":42,"props":8974,"children":8975},{},[8976],{"type":27,"value":8977},"审批卡住",{"type":27,"value":8979},"：审批人数未满足或审批人权限不足；去“监察员功能 → Approvals”。",{"type":21,"tag":8981,"props":8982,"children":8983},"style",{},[8984],{"type":27,"value":8985},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html .sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}html.sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}",{"title":7,"searchDepth":279,"depth":279,"links":8987},[8988,8989,8990,8991,9004,9033,9041,9055,9063,9075],{"id":31,"depth":222,"text":34},{"id":70,"depth":222,"text":73},{"id":102,"depth":222,"text":105},{"id":124,"depth":222,"text":127,"children":8992},[8993,8998,8999,9000,9001,9002,9003],{"id":152,"depth":270,"text":155,"children":8994},[8995,8996,8997],{"id":172,"depth":279,"text":175},{"id":288,"depth":279,"text":291},{"id":383,"depth":279,"text":383},{"id":477,"depth":270,"text":480},{"id":541,"depth":270,"text":544},{"id":1143,"depth":270,"text":1146},{"id":1181,"depth":270,"text":1184},{"id":1203,"depth":270,"text":1206},{"id":1629,"depth":270,"text":1632},{"id":1738,"depth":222,"text":1741,"children":9005},[9006,9007,9011,9012,9013,9014,9024],{"id":1744,"depth":270,"text":1747},{"id":1776,"depth":270,"text":1779,"children":9008},[9009,9010],{"id":1782,"depth":279,"text":1785},{"id":1816,"depth":279,"text":1819},{"id":1860,"depth":270,"text":1863},{"id":1979,"depth":270,"text":1982},{"id":2054,"depth":270,"text":2057},{"id":2181,"depth":270,"text":2184,"children":9015},[9016,9017,9018,9019,9020,9021,9022,9023],{"id":2187,"depth":279,"text":2190},{"id":2385,"depth":279,"text":2388},{"id":2540,"depth":279,"text":2543},{"id":2802,"depth":279,"text":2805},{"id":3112,"depth":279,"text":3115},{"id":3231,"depth":279,"text":3234},{"id":3347,"depth":279,"text":3350},{"id":3414,"depth":279,"text":3417},{"id":3711,"depth":270,"text":3714,"children":9025},[9026,9027,9028,9029,9030,9031,9032],{"id":3717,"depth":279,"text":2190},{"id":3862,"depth":279,"text":2388},{"id":3971,"depth":279,"text":2543},{"id":4170,"depth":279,"text":2805},{"id":4386,"depth":279,"text":4389},{"id":4479,"depth":279,"text":4482},{"id":4583,"depth":279,"text":4586},{"id":4671,"depth":222,"text":4674,"children":9034},[9035,9036,9037,9038,9039,9040],{"id":4677,"depth":270,"text":4680},{"id":4884,"depth":270,"text":4887},{"id":5103,"depth":270,"text":5106},{"id":5186,"depth":270,"text":5189},{"id":5369,"depth":270,"text":5372},{"id":5405,"depth":270,"text":5408},{"id":5456,"depth":222,"text":5459,"children":9042},[9043,9044,9045,9046,9047,9048,9049,9050,9051,9052,9053,9054],{"id":5470,"depth":270,"text":5473},{"id":5677,"depth":270,"text":5680},{"id":5900,"depth":270,"text":5903},{"id":5987,"depth":270,"text":5990},{"id":6144,"depth":270,"text":6147},{"id":6600,"depth":270,"text":6603},{"id":6684,"depth":270,"text":6687},{"id":6770,"depth":270,"text":6773},{"id":6825,"depth":270,"text":6828},{"id":6880,"depth":270,"text":6883},{"id":6950,"depth":270,"text":6953},{"id":7044,"depth":270,"text":7047},{"id":7141,"depth":222,"text":7144,"children":9056},[9057,9058,9059,9060,9061,9062],{"id":7147,"depth":270,"text":7150},{"id":7204,"depth":270,"text":7207},{"id":7313,"depth":270,"text":7316},{"id":7443,"depth":270,"text":7446},{"id":7517,"depth":270,"text":7520},{"id":7549,"depth":270,"text":7552},{"id":7627,"depth":222,"text":7630,"children":9064},[9065,9066,9067,9069,9071,9072,9073,9074],{"id":7648,"depth":270,"text":7651},{"id":7701,"depth":270,"text":7704},{"id":7982,"depth":270,"text":9068},"9.3 主体 DN 属性（Subject DN Attributes）—需要自己添加",{"id":8153,"depth":270,"text":9070},"9.4 其他主体属性（Other Subject Attributes）—需要自己添加",{"id":8274,"depth":270,"text":8277},{"id":8408,"depth":270,"text":8411},{"id":8486,"depth":270,"text":8489},{"id":8622,"depth":270,"text":8625},{"id":8690,"depth":222,"text":8693,"children":9076},[9077,9078,9079,9080,9081],{"id":8726,"depth":270,"text":8729},{"id":8759,"depth":270,"text":8762},{"id":8849,"depth":270,"text":8852},{"id":8902,"depth":270,"text":8905},{"id":8928,"depth":270,"text":8931},"markdown","content:zh:blogs:pki-cert-service-guide.md","content","zh\u002Fblogs\u002Fpki-cert-service-guide.md","zh\u002Fblogs\u002Fpki-cert-service-guide","md","PKI 实践指南：构建完整的证书服务系统 1. 引言 本文是一份基于  EJBCA  的证书服务实践教程，目标是在 Demo 环境中快速跑通 CA\u002FRA 全流程，包括证书模板创建、终端实体模板配置、审批流程启用，以及 RA 端的终端证书申请与下载。教程聚焦“能跑起来”，适合实验、PoC 或内部演示，不涉及生产环境的安全加固与合规细节。 主要收获 ：掌握 EJBCA 的核心操作路径，完成从模板配置到证书签发的全过程  2. 方案架构与术语 RA ：负责终端实体注册与身份审核。 证书模板（Certificate Profile） ：预设密钥用法、SAN、有效期等。  3. 实验环境与前置条件 操作系统：Ubuntu 20.04 Server（离线安装） 前置软件：Docker ，docker-compose (apt 包)  4. EJBCA Docker 部署与持久化 本文将详细介绍如何在 Docker 中部署  EJBCA 证书服务 ，并确保其数据持久化存储在独立数据盘上，避免因容器或虚拟机重启导致数据丢失。内容包括使用内部数据库（默认 H2）的持久化配置、 docker-compose  方式运行容器、开放远程访问所需的配置。 4.1 环境准备与代理配置 由于部分 EJBCA Docker 镜像（如  keyfactor\u002Fejbca-ce  ）需要从公网拉取，为确保环境可用，请先配置 Docker Daemon 的 HTTP\u002FHTTPS 代理。 配置 systemd 代理 Docker Daemon 运行在 systemd 管理下，需添加配置以继承系统代理。 sudo  mkdir  -p  \u002Fetc\u002Fsystemd\u002Fsystem\u002Fdocker.service.d\n sudo  nano  \u002Fetc\u002Fsystemd\u002Fsystem\u002Fdocker.service.d\u002Fhttp-proxy.conf\n 内容如下： [Service]\n Environment=\"HTTP_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\n Environment=\"HTTPS_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\n Environment=\"NO_PROXY=127.0.0.1,localhost,192.168.13.119\"\u002F\u002Fip需要改成自己虚拟机主机ip\n 重新加载并重启 Docker sudo  systemctl  daemon-reload\n sudo  systemctl  restart  docker\n sudo  systemctl  status  docker  --no-pager  -l\n 若输出中含有  Active: active (running)  即表示代理配置生效。 验证代理是否生效 docker  info  |  grep  -i  proxy\n 出现如下输出说明代理生效： HTTP  Proxy:  http:\u002F\u002F192.168.xxx.xxx:7890\n HTTPS  Proxy:  http:\u002F\u002F192.168.xxx.xxx:7890\n 4.2 数据持久化配置 使用文件方式保存 H2 数据库：将数据库配置为  jdbc:h2:\u002Fmnt\u002Fpersistent\u002Fejbcadb;DB_CLOSE_DELAY=-1 宿主机挂载路径： \u002Fopt\u002Fejbca-data:\u002Fmnt\u002Fpersistent 避免使用  --rm  启动容器 设置宿主机权限： chown -R 10001:10001 \u002Fopt\u002Fejbca-data 📌 提示：正式环境建议切换到 PostgreSQL \u002F MySQL 等外部数据库，提升可靠性与容灾能力。 4.3 使用 Docker Compose 部署 创建目录结构： mkdir  -p  \u002Fopt\u002Fejbca-compose\n cd  \u002Fopt\u002Fejbca-compose\n mkdir  -p  \u002Fopt\u002Fejbca-data\n chown  -R  10001:10001  \u002Fopt\u002Fejbca-data\n 当前目录下创建 docker-compose.yml ，编写  docker-compose.yml ： version :  \"3.3\"  # 使用 Docker Compose 文件格式版本 3.3\n \n services :\n   ejbca :  # 定义名为 ejbca 的服务\n     image :  keyfactor\u002Fejbca-ce:latest  # 使用 Keyfactor 提供的 EJBCA 社区版镜像，使用最新版本\n     container_name :  ejbca  # 容器名称为 ejbca\n     hostname :  myejbca.test.local  # 容器内部主机名，影响证书中的 CN 等字段\n \n     environment :  # 设置环境变量配置 EJBCA 的启动行为\n       -  DATABASE_JDBC_URL=jdbc:h2:\u002Fmnt\u002Fpersistent\u002Fejbcadb;DB_CLOSE_DELAY=-1  # 使用嵌入式 H2 数据库，数据保存在挂载目录下\n       -  TLS_SETUP_ENABLED=true  # 启用自动 TLS 设置（用于 HTTPS 接入）\n       -  SMTP_DESTINATION=192.168.xx.xx  # 设置 SMTP 邮件服务器地址（用于发送通知邮件）\n       -  SMTP_DESTINATION_PORT=25  # SMTP 服务端口，默认 25（未启用加密）\n       -  SMTP_FROM=ejbca@example.local  # 设置邮件发送的发件人地址\n       -  SMTP_TLS_ENABLED=false  # 不启用 SMTP 的 STARTTLS\n       -  SMTP_SSL_ENABLED=false  # 不启用 SMTP 的 SSL\u002FTLS 加密\n \n     ports :  # 映射容器端口到宿主机\n       -  \"80:8080\"  # 宿主机 80 端口映射到容器的 8080（HTTP）\n       -  \"443:8443\"  # 宿主机 443 端口映射到容器的 8443（HTTPS）\n \n     volumes :  # 数据卷挂载，将容器中的目录映射到宿主机，以持久化数据\n       -  \u002Fopt\u002Fejbca-data:\u002Fmnt\u002Fpersistent  # 将宿主机的 \u002Fopt\u002Fejbca-data 目录挂载到容器中，持久化数据库等数据\n \n     restart :  unless-stopped  # 如果容器异常退出则自动重启，除非人为停止\n 启动容器服务： docker-compose  up  -d\n docker-compose  logs  -f\n ⚙️ 使用 Compose 可轻松管理配置版本，便于团队协作和恢复。 4.4 远程访问配置 提前设置容器 hostname（影响 TLS 证书 CN）： hostname :  myejbca.test.local\n 4.5 管理证书信任 下载超级管理员证书  .p12  后需双击导入证书存储 4.6 登录流程摘要 docker-compose logs -f 查找容器日志中  SuperAdmin URL  和一次性密码： ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *                                                                                                     *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *    URL:      https:\u002F\u002Fmyejbca.test.local:443\u002Fejbca\u002Fra\u002Fenrollwithusername.xhtml ? username = superadmin  *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *    Password: urAMy0He5c\u002FhHy+DYyDFNy4E                                                                *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *                                                                                                     *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *  Once the P12 is downloaded, use  \"urAMy0He5c\u002FhHy+DYyDFNy4E\"  to import it.                            *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *                                                                                                     *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  ******************************************************************************************************\n 访问领取 URL 填写密码 → 设置导出密码 → 下载  .p12 导入浏览器后访问： https:\u002F\u002Fmyejbca.test.local\u002Fejbca\u002Fadminweb 若提示未提供客户端证书，检查是否导入成功、代理关闭、域名正确解析 ✅ 至此，EJBCA 部署 + 持久化 + 管理登录流程即告完成。 4.7 重要提示（请务必遵守以下要求） ✅  必须  先将  myejbca.test.local  添加到  hosts  文件，或搭建本地 DNS 服务器，否则浏览器可能无法解析域名。 ✅  超级管理员证书算法默认是 DILITHIUM2 （根据版本默认算法会不一样），但  Windows 大概不能识别 ，建议改为  RSA 4096 ，以确保兼容性。 ✅  不能开代理 ，否则 EJBCA 可能无法正确处理客户端证书认证。 ✅  确保 Windows\u002FmacOS\u002FLinux 证书存储正确导入 ，避免  No client certificate was presented  错误。 ✅  第一次建议使用 chrome 浏览器无痕模式 ，避免缓存问题导致 No client certificate was presented 。  5. 初始 CA 创建与证书层级搭建 5.1 进入证书 Profile 管理 登录  EJBCA 管理控制台 。 依次点击  CA Functions → Certificate Profiles  进入管理页面。 5.2 创建证书 Profile 方法 1：克隆现有 Profile 在列表中找到合适的 Profile（如  ENDUSER ）。 点击  Clone ，输入新名称，保存。 方法 2：手动创建 Profile 点击  Add ，输入名称后进入编辑页面。 根据实际需求设置  Key Usage 、 Extended Key Usage 、有效期、Subject DN 设置等。 保存后返回列表查看。 5.3 创建 Crypto Token 进入  CA Functions → Crypto Tokens 。 点击  Create new  并填写： Name ：输入 Crypto Token 名称。 Type ：选择  SOFT 。 Auto-activation ：可选，勾选可自动激活。 Allow export of private keys ：如需导出私钥，勾选  Allow 。 Authentication Code ：输入认证码并重复确认。  dd if=\u002Fdev\u002Frandom bs=1 count=128 2>&1| sha256sum | awk '{print $1} 保存并在列表中确保状态为  Active 。 5.4 生成密钥对 进入  Crypto Token  详情页面。 在  Crypto Token currently does not contain any key pairs.  处输入密钥名称（如  signKey ）。 选择密钥算法（如  RSA 4096 ）。 点击  Generate new key pair  生成密钥。 注意 ：默认 Profile 不能修改，需克隆后新建。 5.5 创建 CA 打开  CA Functions → Certification Authorities 。 在顶部列表中会看到默认的  ManagementCA (Active) ； 无需选中它 。 滚动到页面底部的  Add CA  区域：\n 在文本框中输入新 CA 名称，例如  DemoCA 。 点击右侧  Create…  按钮，进入 CA 配置向导。 在  Create CA  页面完成相关字段： 点击最下方  Create  保存。若配置正确，页面将跳转回 CA 列表并看到  DemoSubCA (Active)  状态。 （可选）若要手动上传由根 CA 签发的证书，可在列表中选中新 CA，然后使用  Import CA certificate…  功能上传链文件。 到此，中间 CA 创建完成，后续即可用它签发终端实体证书。 5.6 Root CA 创建简要步骤案例 1️⃣ CA 类型与密钥配置 参数 说明 CA Type X.509 CA  ✅ 标准 X.509 证书 CA。 Crypto Token 选择已创建的  Crypto Token  ✅（如  demoCrypto ）。 Signing Algorithm SHA256WithRSA  ✅ 更安全的签名算法。 Alternative Signing Algorithm None  ❌ 无需备用签名算法。 Key Sequence Format Numeric (0-9)  ✅ 用于 CA 证书序列号。 Key Sequence 00000  ✅ 初始序列号，可修改。 Description Root CA 说明，可填写用途、管理单位等 ✅  2️⃣ 证书策略（Directives） 参数 说明 Enforce unique public keys ✅ 强制公钥唯一性，防止重复 Enforce key renewal ❌ Root CA 可不启用 Enforce unique DN ✅ 确保  DN  唯一（适用于小规模 CA） Enforce unique Subject DN SerialNumber ❌ 仅适用于大规模 CA（20 个以下证书可不启用） Use Certificate Request History ❌ 记录证书请求历史,Root CA 不启用 Use User Storage ✅ 存储用户信息 Use Certificate Storage ✅ 存储已颁发证书  3️⃣ 证书数据（CA Certificate Data） 参数 说明 Subject DN CN=test EnterpriseIT Root CA  ✅ Signed By Self Signed  ✅ Root CA 必须自签名 Certificate Profile ITROOTCA_profile  ✅ 选择克隆后的 ROOTCA，允许修改参数 Validity 20y  ✅ 证书有效期 20 年 Subject Alternative Name ❌ Root CA 通常不需要 Certificate Policy OID ❌ 可选，默认留空 Use UTF-8 in policy notice text ✅ 确保国际字符支持 PrintableString encoding in DN ❌ 不勾选，避免影响国际化 LDAP DN order ✅ 确保  DN  按 LDAP 规范排列 Serial Number Octet Size 20  ✅ 推荐 20 字节，确保唯一性 Name Constraints, Permitted ❌ Root CA 默认禁用，留空 Name Constraints, Excluded ❌ Root CA 默认禁用，留空  4️⃣ CRL 配置（证书吊销列表） 参数 说明 Microsoft CA Compatibility Mode ❌ Root CA 不启用，仅适用于 Windows 证书颁发机构（AD CS）。 Authority Key ID ✅ 启用，并标记  Critical ，用于标识 CRL 发行者。建议 Root CA 和中间 CA 都启用。 CRL Number ✅ 启用，并标记  Critical ，确保 CRL 版本唯一。建议 Root CA 和中间 CA 启用。 Issuing Distribution Point on CRLs ❌ Root CA 可不启用，仅适用于分层 CRL 结构的大规模 CA。 CA issuer URI ❌ 留空，证书下载后期由用户自行提供接口。 Keep expired certificates on CRL ❌ Root CA 不启用，中间 CA 视情况决定，启用后即使证书过期仍会出现在 CRL 中。 Use CRL partitions ❌ Root CA 负载小，不需要。适用于大规模证书管理的 CA。 CRL Expire Period 30d  ✅ Root CA 设长一些，如  30d ，中间 CA 采用较短的 CRL 过期时间。 CRL Issue Interval 7d  ✅ 定期更新 CRL，建议活跃 CA 采用  7d 。 CRL Overlap Time 12h  ✅ 旧 CRL 与新 CRL 重叠 12h，防止证书验证失败。 Delta CRL Period 0m  ❌ Root CA 不使用 Delta CRL，只有对实时性要求高的 CA 才需要启用。 Generate CRL Upon Revocation ❌ Root CA 不启用，中间 CA 需要时启用，证书撤销后立即生成新的 CRL。 Allow changing revocation reason ✅ 启用，允许修改证书撤销原因。适用于所有 CA。 Allow invalidity date ✅ 启用，允许设置证书失效日期。适用于所有 CA。  5️⃣ 审批设置 参数 说明 Add\u002FEdit End Entity None  ❌ Root CA 不管理终端实体 Key Recovery None  ❌ Root CA 不提供密钥恢复 Revocation None  ❌ Root CA 很少撤销自身证书 CA Service Activation None  ❌ Root CA 手动激活  6️⃣ 其他数据 参数 说明 Validators Finish User  ✅ 启用证书验证策略。 CMP RA Authentication Secret ❌ 留空，仅在使用 CMP 协议时需要配置。 Monitor if CA active (healthcheck) Activate  ✅ 启用 CA 运行监控，适用于所有 CA。 Request Processor None  ❌ Root CA 通常不需要外部请求处理。  7️⃣ 外部签名 CA 创建或更新（Externally signed CA creation\u002Frenewal） 参数 说明 Renew CA ❌ 建议创建新的 Root CA，而不是重新生成密钥并重新签名现有 CA，以避免同名 Root CA 证书带来的问题。 CA Chain Certificates ✅ 仅当 CA 由外部 CA 签名时才需要上传证书链文件（PEM\u002FDER 格式）。如果 Root CA 已安装在本地，则不需要上传此文件。  8️⃣ 完成 CA 创建 检查所有参数，确认无误后，点击  Create  生成 CA。 ① 下载并验证 Root CA 证书： 使用以下 OpenSSL 命令验证证书格式和有效性： # 验证 PEM 格式证书\n openssl  x509  -in  rootca.pem  -text  -noout\n \n # 验证 DER 格式证书\n openssl  x509  -in  rootca.der  -inform  DER  -text  -noout\n \n # 检查证书 SHA256 指纹信息\n openssl  x509  -noout  -fingerprint  -sha256  -in  rootca.pem\n \n # 验证证书的有效性（自签名证书验证）\n openssl  verify  -CAfile  rootca.pem  rootca.pem\n ② 部署并验证 CRL（证书吊销列表）： 若配置了 CRL URL，执行： # 验证 CRL 文件\n openssl  crl  -in  rootca.crl  -text  -noout\n 确保 CRL 可通过 Web 正常访问。 🚀  Root CA 现在已成功创建，可用于签发中间 CA！  🎉 5.7 中间 CA 创建简要步骤案例 1️⃣ CA 类型与密钥配置 参数 说明 CA Type X.509 CA  ✅ 标准 X.509 证书 CA Crypto Token 选择已创建的 Crypto Token ✅（如  demoCrypto ） Signing Algorithm SHA256WithRSA  ✅ 更安全的签名算法 Alternative Signing Algorithm None  ❌ 无需备用签名算法 Key Sequence Format Numeric (0-9)  ✅ 用于 CA 证书序列号 Key Sequence 00001  ✅ 初始序列号，与 Root CA 区分 Description 中间 CA 说明，可填写用途、管理单位等 ✅  2️⃣ 证书策略（Directives） 参数 说明 Enforce unique public keys ✅ 强制公钥唯一性，防止重复 Enforce key renewal ✅ 中间 CA 建议启用，保证安全 Enforce unique DN ✅ 确保 DN 唯一 Enforce unique Subject DN SerialNumber ❌ 规模小于 20 个证书时可不启用 Use Certificate Request History ✅ 记录证书请求历史 Use User Storage ✅ 存储用户信息 Use Certificate Storage ✅ 存储已颁发证书  3️⃣ 证书数据（CA Certificate Data） 参数 说明 Subject DN 例如  CN=test Intermediate CA  ✅ Signed By test EnterpriseIT Root CA  ✅ 中间 CA 必须由 Root CA 签名 Certificate Profile INTERMEDIATE_CA_profile  ✅ 克隆后配置适合中间 CA Validity 10y  ✅ 通常为 10 年，有效期小于 Root CA Subject Alternative Name ❌ 中间 CA 通常不需要 Certificate Policy OID ❌ 默认留空，或按需填写 Use UTF-8 in policy notice text ✅ 确保国际字符支持 PrintableString encoding in DN ❌ 不勾选，避免影响国际化 LDAP DN order ✅ 按 LDAP 规范排列 DN Serial Number Octet Size 20  ✅ 推荐 20 字节 Name Constraints, Permitted ❌ 默认禁用，留空 Name Constraints, Excluded ❌ 默认禁用，留空  4️⃣ CRL 配置（证书吊销列表） 参数 说明 Microsoft CA Compatibility Mode ❌ 一般不启用，仅用于 Windows AD 环境 Authority Key ID ✅ 启用，并标记为 Critical CRL Number ✅ 启用，并标记为 Critical Issuing Distribution Point on CRLs ❌ 通常不启用 CA issuer URI ❌ 留空，或按需填写下载地址 Keep expired certificates on CRL ❌ 中间 CA 建议启用，保留过期证书，目前不启用，会导致吊销列表越来越大 Use CRL partitions ❌ 通常不需要 CRL Expire Period 7d  ✅ 建议 7 天，确保及时更新 CRL Issue Interval 1d  ✅ 每天发布，确保及时更新 CRL Overlap Time 12h  ✅ 与旧 CRL 重叠 12 小时，确保平稳过渡 Delta CRL Period 0m  ❌ 不使用 Delta CRL Generate CRL Upon Revocation ✅ 启用，证书撤销后立即更新 Allow changing revocation reason ✅ 允许修改证书撤销原因 Allow invalidity date ✅ 允许设置证书失效日期  5️⃣ 默认 CA 验证数据（Default CA defined validation data） 参数 说明 Default CRL Distribution Point ❌ 默认留空或按需填写，用于 CRL 分发地址 Default CRL Issuer ❌ 默认留空，通常无需填写 Default Freshest CRL Distribution Point ❌ 默认留空，通常无需填写 OCSP Service Default URI ❌ 默认留空，按需填写 OCSP 地址 CA Issuer Default URI ❌ 默认留空或后期提供接口  6️⃣ 审批设置与其他数据 审批设置目前只有 None 选项，表示无需额外审批流程，如需开启需检查 EJBCA 的全局审批策略，Supervision Fuctions。 参数 说明 Validators Finish User  ✅ 启用证书验证策略 CMP RA Authentication Secret ❌ 留空，仅在使用 CMP 协议时需要配置 Monitor if CA active (healthcheck) Activate  ✅ 启用运行监控 Request Processor None  ❌ 一般不需外部请求处理  7️⃣ 完成中间 CA 创建 检查所有参数，确认无误后，点击  Create  生成 CA 请求文件 (CSR)。 提交 CSR 给 Root CA 签名后，下载签名后的证书并验证： openssl  x509  -in  intermediate_ca.pem  -text  -noout\n openssl  verify  -CAfile  rootca.pem  intermediate_ca.pem\n 🚀 中间 CA 已成功创建，可用于签发终端实体证书！🎉  6. RA 普通用户创建与权限配置 6.1 创建 RA 角色（Role） 进入 RA 管理界面 （RA Web），选择菜单： Role Management →Roles →Create New Role\n 填写角色信息 ： 字段 推荐填写值 Namespace No namespace Role name test RA Users 设置 Certificate Authorities 权限 ： 从Available列表选择对应CA（如  Intermediate CA ,  Root CA ），点击 Add 。 设置 End Entity 权限（permissions） （推荐配置）： ✅ Create end entities ✅ Create certificates\n ✅ ...by using username and password ✅ ...by using a request ID ✅ View end entities and certificates 设置 End Entity Profiles 权限 ： 从 Available 列表选择 EMPTY ，点击 Add 。 点击 Add 保存创建好的角色。 6.2 创建 RA 普通用户 (End Entity) 进入 EJBCA Admin Web 界面 ，选择： RA Functions → Add End Entity\n 填写用户详细信息： 字段 推荐填写值 End Entity Profile EMPTY Username test_signuser Password 123 Confirm Password 123 Batch generation 不勾选 E-mail cert-user@example.com CN test RA user S1 O test C CN Certificate Profile ENDUSER CA test Intermediate CA Token P12 file 点击 Add ，完成 End Entity 创建。 6.3 用户证书下载 用户进入 RA Web 界面 ，选择： Enroll → Use Username\n 使用刚创建的用户名和密码登录： Username:  test_signuser Password:  123 登录后选择密钥算法： 选择 RSA 4096 算法，生成并下载 .p12 用户证书。 6.4 将用户加入 RA 角色 进入 RA Web 界面，选择菜单： Search → End Entities\n 查找并复制刚才创建证书的 CN 。 进入 RA 管理界面，选择菜单： Role Management → Roles → Members → Add Role Member\n 填写 Role Member 信息： 字段 推荐填写值 Role test RA Users Token Type Certificate CA test Intermediate CA Match with CN Common Name Match Value 粘贴刚复制的证书 CN Description RA 普通用户 点击 Add ，完成角色成员添加。 重启 EJBCA 服务 ，使权限生效（推荐）： docker  restart  ejbca\n 6.5 用户登录 RA 界面 非管理员角色 将下载的 .p12 证书导入浏览器。 访问 RA Web 界面，自动认证并登录。 用户即可执行授权内的 RA 操作（如创建和查看证书等）。 6.6 重要提示（请务必遵守以下要求） ✅  第一次建议使用 chrome 浏览器无痕模式快速启动验证 ，避免缓存问题导致 No OAuth providers configured. Please log in using a valid certificate. 。 ✅  访问时候 使用 https 访问 ， https:\u002F\u002F192.168.xxx.xxx\u002Fejbca\u002Fra\u002F ,避免出现 No OAuth providers configured. Please log in using a valid certificate. 。  7. 证书模板设置说明 本节用于解释 EJBCA 中终端证书模板（Certificate Profile）设置项的具体含义及推荐用途，适用于 HTTPS\u002FWeb\u002F设备\u002F客户端等常见终端证书签发需求。  7.1 基本信息 配置项 描述 Certificate Profile ID 模板在数据库中的唯一标识，仅供系统内部识别 类型 可用终端实体，子 CA，根 CA Available Key Algorithms 可用密钥算法，如 RSA、ECDSA、Ed25519、 DILITHIUM 等 Available ECDSA curves ECDSA 可选曲线，当前未启用任何曲线 可用位长度 支持的密钥位数（针对 RSA），如 2048、4096 等 签名算法 用于签发证书时的签名哈希算法，如 SHA3-256withRSA Alternative Signature 是否启用替代签名算法，如 ECDSA, EdDSA 等 有效期 or end date of the certificate 默认有效期，如 \"2y\" 表示 2 年 Validity Offset 签发日期的偏移量，允许向前或向后设定起始时间 Expiration Restrictions 限制最大到期时间，用于合规控制 Profile Description 证书模板说明，用于备注用途（如“终端设备证书”）  7.2 权限控制（Permissions） 配置项 描述 推荐设置 Allow Validity Override 允许在签发证书时覆盖默认有效期 ✅，如需手动调整有效期时使用 Allow Expired Validity End Date 允许设置一个已过期的结束时间（用于测试或审计） ✅（调试用） Allow Extension Override 允许 CSR 中的扩展字段覆盖模板中预定义的扩展 ❌，若开启会破坏模板统一性，可能引入风险 Allow certificate serial number override 允许在签发时自定义证书序列号 ❌，仅特定需求下开启（如证书克隆、替换） Allow Subject DN Override by CSR 允许 CSR 中的主题信息（如 CN\u002FO）覆盖模板配置 ✅，适用于自动化签发流程 Allow Subject DN Override by End Entity Information 允许通过终端实体信息（用户输入）指定 Subject 字段 ✅，灵活性高，推荐开启 Allow Key Usage Override 允许 CSR 中设置 keyUsage 字段覆盖模板配置 ❌，开启会造成用途不一致，影响安全性 Allow Backdated Revocation 允许将吊销时间设置为历史时间，用于追溯性撤销 ✅，部分审计\u002F合规场景下需要 Use Certificate Storage 启用证书在数据库中存储（必须开启，除非特殊离线用途） ✅ Store Certificate Data 存储证书完整原文数据（配合 OCSP\u002FCRL 使用） ✅，建议与存储功能一同开启 ✅ 建议： 在生产环境中保持模板统一性，除非明确需要，否则尽量关闭 Override 类权限项，避免 CSR\u002FEnd Entity 越权操作。  7.3 X.509v3 扩展 - 基础信息 扩展项 描述 推荐设置 基本约束（Basic Constraints） 限制是否为 CA 证书（终端证书应设为 FALSE） ✅ 使用，关键 CA 密钥标识符 标识签发 CA 的信息 ✅ 使用 主题密钥标识符 生成此证书的唯一标识 ✅ 使用  7.4 X.509v3 扩展 - 密钥用途（Key Usage） 项目 描述 数字签名 (digitalSignature) 用于验证签名，如身份认证、代码签名 不可抵赖 (nonRepudiation) 表明签名不可否认（法律场景） 数据加密 (dataEncipherment) 用于加密非密钥数据 密钥加密 (keyEncipherment) 用于加密密钥材料，如对称密钥 密钥协议 (keyAgreement) 支持密钥协商协议（如 DH） CRL 签名 (cRLSign) 用于签署吊销列表（CA 用） 密钥证书签名 (keyCertSign) 用于签署证书（CA 用） 只用于加密 (encipherOnly) 与密钥协议联合使用（仅加密） 只用于解密 (decipherOnly) 与密钥协议联合使用（仅解密） Forbid encryption usage for ECC keys 禁止 ECC 密钥用于加密 7.5 X.509v3 扩展 - 扩展密钥用途（Extended Key Usage） 扩展用途 描述 TLS client 用于客户端 TLS 认证 TLS server 用于服务器 TLS 认证 EAP over LAN (EAPOL) 企业网身份认证 EAP over PPP 点对点协议身份认证 ETSI TSL Signing 用于 ETSI TSL 签名场景 ICAO Deviation List Signing ICAO 签名用途之一 ICAO Master List Signing ICAO 主列表签名 Intel AMT management Intel 管理认证专用 Internet Key Exchange for IPsec IPsec 密钥交换 Kerberos Client Authentication Kerberos 客户端认证 Kerberos KDC Kerberos 密钥中心 MS CA Key Exchange Microsoft CA 密钥交换用途 MS Commercial Code Signing Microsoft 商业代码签名 MS Document Signing Microsoft 文档签名 MS EFS Recovery Microsoft EFS 恢复用途 MS Encrypted File System Microsoft 加密文件系统用途 MS Individual Code Signing Microsoft 个人代码签名 MS 智能卡登录 Microsoft 智能卡登录验证 OCSP 签发者 在线证书状态协议（OCSP）签名证书用途 PDF Signing 用于 PDF 文件签名 PIV Card Authentication PIV 卡身份认证 RFC9336 Document Signing 符合 RFC9336 的文档签名用途 SCVP Client 简化证书验证协议客户端 SCVP Server 简化证书验证协议服务端 SIP Domain 用于 VoIP\u002FSIP 域名认证用途 SSH Client 用于 SSH 客户端认证 SSH Server 用于 SSH 服务器认证 代码签名 (codeSigning) 用于软件\u002F驱动程序签名 任意扩展的密钥用途 任意通用用途扩展支持 安全 Email (emailProtection) S\u002FMIME 邮件签名\u002F加密用途 客户身份验证 (clientAuth) 用于 TLS 客户端身份认证 时间戳 (timeStamping) 时间戳服务签名用途 服务器验证 (serverAuth) 用于服务器身份验证（HTTPS 等） 7.6 名称扩展 项目 描述 建议 主题别名（Subject Alt Name） 支持 IP\u002FDNS\u002FUEmail 作为证书标识 ✅ 使用 Issuer Alternative Name 可添加额外的 CA 名称信息 可选 Name Constraints 限定主题中可用的命名空间 可选（高安全场景使用） 7.7 验证扩展（Validation Data） 项目 描述 推荐 CRL 发布点 证书吊销列表地址 ✅ 使用，关键 Delta CRL（Freshest CRL） 增量吊销列表 按需开启 Authority Information Access (AIA) 提供 OCSP\u002FCA 信息 ✅  7.8 私钥使用期限制 项目 描述 Start Offset 私钥可用的起始偏移时间 Period Length 私钥的可使用周期（独立于证书有效期）  7.9 🇪🇺 ETSI 合规扩展（一般用于合规性要求高的 PKI 环境） 项目 描述 资质证书声明 用于标识法律或合规用途证书 Assured validity 确保短期证书的有效性  7.10 其他扩展（Other Extensions） 扩展 用途 OCSP No Check 禁用 OCSP 检查（通常仅对 OCSP responder 有用） Microsoft 模板值 用于 Windows AD 集成的特殊扩展 CA\u002FB Forum OID 用于 CA\u002FB 合规的组织标识扩展  7.11 审批设置 & 附加字段 配置项 说明 添加\u002F编辑终端实体 绑定的审批流程 密钥恢复 是否支持密钥找回（如用于备份恢复） 撤销审批 吊销时是否需审批 CN 后缀 在 Subject CN 后自动添加字符串 主题字段子集限制 限制允许使用的 Subject 字段  7.12 CA & 发布设置 项目 说明 可用的 CA 允许哪些 CA 使用此证书模板 发布器（Publisher） 可配置发布至 LDAP、数据库或外部服务 单证书限制 是否启用一个 End Entity 只能有一张有效证书 Account Binding Namespace 用于设备账户绑定场景（如 IoT）  如需配置 \"代码签名证书\" 模板，请在此基础上调整 keyUsage 与 extendedKeyUsage 字段即可。 📌 建议对不同应用（如：VPN、HTTPS、代码签名、客户端认证）创建不同模板，便于管理和合规控制。  8. 审批配置与管理 8.1 创建 Approval Profile（审批配置） 进入： 监察员功能 → Approval Profiles\n 在底部输入名称（如  test ）→ 点击  添加 。 在列表中点击  编辑  进入详细设置。 8.2 基本参数设置 字段 建议\u002F示例 Approval Profile Type Accumulative Approval（累计）；跨部门可用 Partitioned Approval（分区） Request Expiration Period 8h （超时未批作废） Approval Expiration Period 8h （结果过期需重批） Max Extension Time 0d （不允许延长） Allow Self Approved Request Editing 不勾选（生产禁用自批） 8.3 审批步骤（Approval Steps） 设置  Number of Required Approvals ： 开发\u002F测试： 1 （1-of-1）。 生产\u002F敏感操作： 2 （2-of-2）或分区审批。 通知邮件： Notification message email recipient ： approval-admin-group@example.org supervisor@example.org Notification message email sender ： no-reply@192.168.xxx.xx 主题模板示例： [AR-${approvalRequest.ID}-${approvalRequest.STEP_ID}-${approvalRequest.PARTITION_ID}] Approval Request\n 正文可引用变量： ${approvalRequest.TYPE} 、 ${approvalRequest.REQUESTOR} 、 ${approvalRequest.WORKFLOWSTATE}  等。 8.4 绑定到具体动作 End Entity Profile： CA Functions → End Entity Profiles → \u003CProfile> → Approval Settings → 勾选需要审批的操作（如Add\u002FEdit End Entity） → 选择上面创建的 Approval Profile → Save\n 常用勾选： Add\u002FEdit End Entity 、 Key Recovery （若启用）。 Certificate Profile： CA Functions → Certificate Profiles → \u003CProfile> → Approval Settings → 勾选相关操作 → 选择 Approval Profile → Save\n 管理员敏感动作：  中间 CA 变更、吊销等建议使用  2-of-2  或分区审批。 8.5 测试与验证 用一个普通 RA 账号在 RA Web 发起一次需要审批的操作（如创建 End Entity）。 到  监察员功能 → Approvals  查看待审批队列，使用另一个审批员账号完成审批。 确认操作自动执行，且邮件通知正常到达。 8.6 常见问题 邮件收不到 ：检查 SMTP 配置、防火墙、收件人拼写；查看容器日志。 一直待审批 ： Number of Required Approvals  设置过高或审批人不具备权限。 能自批 ：误勾选了  Allow Self Approved Request Editing ；生产应关闭。 过期作废 ： Request\u002FApproval Expiration  设置过短；可调到  8–24h 。  9. 终端实体模板设置 位置： RA Functions → End Entity Profiles 。终端实体模板（End Entity Profile）决定了“能填哪些字段”“哪些必填\u002F可改”“默认使用哪个证书模板\u002FCA\u002FToken”。 9.1 新建与进入 进入： RA Functions → End Entity Profiles\n 在底部输入模板名（如  test ）→  添加模板 。 在列表中选中该模板 →  编辑终端实体模板 。 9.2 基本信息（用户名\u002F密码\u002F邮箱） 是否必须提前填？  通常  不需要  在模板里写死具体“用户名\u002F密码”。模板里只定义“规则与方式”，具体的  Username\u002FPassword\u002FEnrollment Code  在 创建 End Entity 或申请时 填写即可。 推荐做法 Username ：选择  Auto-generated （批量\u002F自动化最方便），或在创建 End Entity 时手动指定。 Password (or Enrollment Code) ：勾选  Required ，作为一次性  Enrollment Code  使用；具体值在创建 End Entity 或 RA 端申请时再填。 Minimum password strength \u002F length ：保持策略（如长度 ≥ 8），但不在模板里填具体密码。 Maximum number of failed login attempts ：按需限制；可勾  Modifiable  便于临时调整。 Batch generation ：一般关闭；避免明文存储 Enrollment Code。 E-mail ：按业务是否  Required\u002FModifiable ，便于通知与标识。 不同申请路径对 Username\u002FPassword 的影响 RA Web → Enroll → Use Username ：创建 End Entity 时需要指定  Username  与  Password\u002FEnrollment Code ，用户用该账号登录领取证书。 RA Web → Enroll → Use Request ID ：由系统分配  Request ID ， Password\u002FEnrollment Code  在创建时设置，申请人用 ID+Code 领取。 User Generated（CSR 提交） ： Token=User Generated ；保留  Required  以生成一次性代码，申请人用 CSR+Code 完成签发。 Directives（指令） Reverse Subject DN and Subject Alt Name Checks ：不勾也可以。 Allow merge DN for all interfaces ：通常  不勾 ，仅在多接口需要聚合 DN 时启用。 Allow multi-value RDNs ：仅特殊需求启用（默认关闭更安全）。 9.3 主体 DN 属性（Subject DN Attributes）— 需要自己添加 左侧是“可选属性”，右侧是“已选属性”。把需要的字段添加到右侧，并为每个字段设置  Required \u002F Modifiable \u002F Validation 。 常见推荐（客户端\u002F通用）： 字段 建议 CN, Common name Required ； Modifiable  由 RA 决定 emailAddress, E-mail address in DN 选配；如需与邮件系统绑定可  Required O, Organization  \u002F  OU, Org. Unit 视业务；建议  Modifiable  关闭以避免乱填 C, Country 固定为  CN  或所在国家；通常不允许修改 若需要更严格的校验，可在  Validation  指定正则\u002F格式规则。 9.4 其他主体属性（Other Subject Attributes）— 需要自己添加 Subject Alternative Name（SAN） ： 客户端证书： RFC 822 Name (e-mail address) （与账户邮箱一致） 服务器证书： DNS Name 、 IP Address （按域名\u002FIP 添加） 设备证书： OtherName （写入设备 ID\u002FOID） Subject Directory Attributes （可选）： 仅在需要存档\u002F合规时使用，例如  Date of birth (YYYYMMDD)  等；默认不建议开启过多目录属性。 添加方法：在  Other Subject Attributes  区域选择条目 →  添加  到右侧；如界面支持，可设置  Required\u002FModifiable 。 9.5 主要证书数据（Main Certificate Data） 字段 建议\u002F说明 Default Certificate Profile 选择目标证书模板（如  ENDUSER  \u002F  SERVER ） Available Certificate Profiles 仅勾选允许使用的模板，避免误选 Default CA  \u002F  Available CAs 指定可签发的 CA； 注意：修改可用 CA 会影响角色对此 Profile 的访问 Default Token  \u002F  Available Tokens P12 file （RA 直接下载 p12）或  User Generated （用户自带 CSR） 9.6 其他证书数据（Other Certificate Data） Custom certificate serial number ：默认关闭 Certificate Validity Start\u002FEnd Time ：默认由  Certificate Profile  控制；如需临时证书可开启并  Modifiable Name Constraints (Permitted\u002FExcluded) ：一般用于中间 CA；终端实体模板通常不启用 Custom certificate extension data  \u002F  ETSI PSD2 QC Statement  \u002F  CA\u002FB Forum Organization Identifier ：按合规需要开启 9.7 其他数据与限制（Other Data \u002F Restrictions） 字段 建议 Number of allowed requests 1 （防多次重复签发） Allow renewal before expiration 例如  30  天；如不限制填  -1 Revocation reason to set after certificate issuance 默认  Active （一般不改） Redact Subject Name from logs 仅在隐私\u002F合规强需求时开启 Send Notification 按需；与 SMTP 配置关联 9.8 保存与授权 点击  保存 。 到  RA Web → Role Management  确认相关角色已被授权“使用此 End Entity Profile”（可见\u002F可创建）。 在  Search → End Entities  使用该模板创建测试用户，验证：\n DN\u002FSAN 是否按规则入库； 证书是否使用了期望的  Certificate Profile\u002FCA\u002FToken ； 下载\u002F导入是否成功（P12\u002FPEM\u002FCSR 流程）。  10. RA 普通用户申请终端证书 位置： RA Web → Enroll 。 默认建议：优先使用   By the CA （CA 端生成密钥），无需 CSR，流程最稳、最少出错。 10.1 路径与前置 已在  End Entity Profiles （第 9 节）与  Certificate Profiles  准备好模板；用户具备访问权限。 若启用审批（第 8 节），提交后会进入待审队列，审批通过才签发。 10.2 推荐：By the CA（无需 CSR） 进入： Enroll → Make New Request\n 选择  Certificate Type （End Entity Profile）与  Certificate subtype （Certificate Profile）。 在  Key‑pair generation  选择  By the CA 。 展开  Provide request info ，按模板要求填写  Subject DN \u002F SAN （如 CN、Email、DNS\u002FIP）。 下载  *.p12 。 10.3 可选：Provided by user（上传 CSR） 仅当 必须 在客户端\u002F服务器本地生成密钥（如合规要求、HSM\u002F专用设备、已有密钥迁移）时使用。 本地生成私钥与 CSR： 在页面选择  Provided by user ，将完整 CSR（含  BEGIN\u002FEND CERTIFICATE REQUEST ）粘贴到输入框。 提交并按提示下载证书（不会包含你的私钥）。 10.4 审批联动与通知 当 Profile 绑定了  Approval Profile  时，提交即进入待审；通过后自动签发或开放下载。 邮件主题\u002F正文遵循第 8 节的通知模板。 10.5 常见问题 字段不通过 ：DN\u002FSAN 与 Profile 约束不一致；按第 9 节调整。 不能下载 P12 ：浏览器拦截或口令策略冲突；更换浏览器\u002F检查口令长度与字符集。 CSR 被拒 ：CSR 中 Subject\u002FSAN 与模板冲突；按模板重建 CSR 或改用  By the CA 。 审批卡住 ：审批人数未满足或审批人权限不足；去“监察员功能 → Approvals”。 html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html .sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}html.sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}",[15],{"_path":9091,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":9092,"description":9093,"date":10,"category":11,"archives":12,"author":9094,"body":9097,"_type":9082,"_id":17142,"_source":9084,"_file":17143,"_stem":17144,"_extension":9087,"plainText":17145,"authorNames":17146},"\u002Fen\u002Fblogs\u002Fpki-cert-service-guide","PKI Practice: Building a Complete Certificate Service System (openubmc.cn)","This tutorial provides a hands-on guide based on EJBCA, designed to compliance the CA\u002FRA workflow in a demo environment. It walks through key operational steps including certificate profile creation, end entity profile configuration, approval process activation, and RA certificate issuance and download. This tutorial focuses on practical execution, making it ideal for experiments, proof-of-concept (PoC) setups, or internal demonstrations. Please note that this tutorial does not cover production-level security hardening or compliance requirements.",[9095],{"name":15,"description":9096},"Active openUBMC community developer, who is eager to explore and share new ideas on BMC and open source firmware.",{"type":18,"children":9098,"toc":17047},[9099,9104,9110,9114,9124,9127,9133,9155,9158,9164,9177,9180,9186,9191,9197,9209,9215,9220,9260,9265,9301,9307,9374,9386,9392,9425,9430,9466,9472,9519,9527,9533,9541,9607,9622,9999,10007,10043,10051,10057,10065,10086,10092,10097,10103,10118,10458,10490,10498,10504,10573,10576,10582,10588,10607,10613,10619,10644,10650,10685,10691,10793,10799,10852,10865,10871,10977,10982,10988,10994,11170,11173,11179,11317,11320,11326,11565,11568,11574,11853,11856,11862,11973,11976,11982,12086,12089,12095,12151,12154,12160,12171,12179,12184,12360,12368,12373,12415,12420,12430,12436,12441,12577,12580,12585,12686,12689,12694,12885,12888,12893,13104,13107,13113,13192,13195,13201,13213,13297,13300,13306,13316,13321,13377,13382,13385,13391,13397,13576,13582,13773,13778,13784,13856,13862,14018,14024,14047,14053,14058,14076,14079,14085,14090,14093,14099,14288,14291,14297,14491,14501,14504,14510,14588,14591,14597,14747,14753,15177,15183,15259,15265,15339,15342,15348,15392,15395,15401,15446,15449,15455,15514,15517,15523,15606,15609,15615,15686,15689,15694,15702,15705,15711,15717,15757,15763,15844,15850,15963,15969,15977,16000,16017,16025,16046,16056,16062,16080,16086,16109,16115,16127,16133,16151,16157,16182,16190,16223,16231,16249,16257,16275,16281,16293,16301,16370,16380,16392,16400,16418,16428,16439,16462,16468,16539,16545,16585,16591,16715,16721,16777,16780,16786,16809,16815,16840,16846,16920,16926,16934,16964,16970,16989,16995,17043],{"type":21,"tag":22,"props":9100,"children":9102},{"id":9101},"pki-practice-building-a-complete-certificate-service-system-openubmccn",[9103],{"type":27,"value":9092},{"type":21,"tag":29,"props":9105,"children":9107},{"id":9106},"_1-introduction",[9108],{"type":27,"value":9109},"1. Introduction",{"type":21,"tag":36,"props":9111,"children":9112},{},[9113],{"type":27,"value":9093},{"type":21,"tag":36,"props":9115,"children":9116},{},[9117,9122],{"type":21,"tag":42,"props":9118,"children":9119},{},[9120],{"type":27,"value":9121},"Objective",{"type":27,"value":9123},": Master the core operations of EJBCA and complete the entire process from template configuration to certificate issuance.",{"type":21,"tag":65,"props":9125,"children":9126},{},[],{"type":21,"tag":29,"props":9128,"children":9130},{"id":9129},"_2-terms",[9131],{"type":27,"value":9132},"2. Terms",{"type":21,"tag":50,"props":9134,"children":9135},{},[9136,9145],{"type":21,"tag":54,"props":9137,"children":9138},{},[9139,9143],{"type":21,"tag":42,"props":9140,"children":9141},{},[9142],{"type":27,"value":84},{"type":27,"value":9144},": registers end entities and reviews their identities.",{"type":21,"tag":54,"props":9146,"children":9147},{},[9148,9153],{"type":21,"tag":42,"props":9149,"children":9150},{},[9151],{"type":27,"value":9152},"Certificate profile",{"type":27,"value":9154},": presets key usages, SANs, and validity periods.",{"type":21,"tag":65,"props":9156,"children":9157},{},[],{"type":21,"tag":29,"props":9159,"children":9161},{"id":9160},"_3-experiment-environment-and-prerequisites",[9162],{"type":27,"value":9163},"3. Experiment Environment and Prerequisites",{"type":21,"tag":50,"props":9165,"children":9166},{},[9167,9172],{"type":21,"tag":54,"props":9168,"children":9169},{},[9170],{"type":27,"value":9171},"OS: Ubuntu 20.04 Server (installed offline)",{"type":21,"tag":54,"props":9173,"children":9174},{},[9175],{"type":27,"value":9176},"Software to be preset: Docker and docker-compose (apt package)",{"type":21,"tag":65,"props":9178,"children":9179},{},[],{"type":21,"tag":29,"props":9181,"children":9183},{"id":9182},"_4-ejbca-docker-deployment-and-persistence",[9184],{"type":27,"value":9185},"4. EJBCA Docker Deployment and Persistence",{"type":21,"tag":36,"props":9187,"children":9188},{},[9189],{"type":27,"value":9190},"This chapter explains how to deploy the EJBCA certificate service using Docker, with a focus on ensuring persistent data storage on a dedicated drive. This setup helps prevent data loss in the event of container or virtual machine restarts. Key topics cover configuring data persistence of the internal database (H2 by default), running containers using docke-compose, and setting up remote access through appropriate configuration parameters.",{"type":21,"tag":150,"props":9192,"children":9194},{"id":9193},"_41-environment-setup-and-proxy-configuration",[9195],{"type":27,"value":9196},"4.1 Environment Setup and Proxy Configuration",{"type":21,"tag":36,"props":9198,"children":9199},{},[9200,9202,9207],{"type":27,"value":9201},"Some EJBCA Docker images (such as ",{"type":21,"tag":141,"props":9203,"children":9205},{"className":9204},[],[9206],{"type":27,"value":166},{"type":27,"value":9208},") need to be pulled from the public network. To ensure environment availability, configure the HTTP\u002FHTTPS proxy of Docker Daemon.",{"type":21,"tag":170,"props":9210,"children":9212},{"id":9211},"step-1-configure-the-systemd-proxy",[9213],{"type":27,"value":9214},"Step 1 Configure the systemd proxy.",{"type":21,"tag":36,"props":9216,"children":9217},{},[9218],{"type":27,"value":9219},"Docker Daemon runs under the systemd management. You need to add the following configurations to inherit the system proxy.",{"type":21,"tag":182,"props":9221,"children":9222},{"code":184,"language":185,"meta":7,"className":186,"style":7},[9223],{"type":21,"tag":141,"props":9224,"children":9225},{"__ignoreMap":7},[9226,9245],{"type":21,"tag":192,"props":9227,"children":9228},{"class":194,"line":195},[9229,9233,9237,9241],{"type":21,"tag":192,"props":9230,"children":9231},{"style":199},[9232],{"type":27,"value":202},{"type":21,"tag":192,"props":9234,"children":9235},{"style":205},[9236],{"type":27,"value":208},{"type":21,"tag":192,"props":9238,"children":9239},{"style":211},[9240],{"type":27,"value":214},{"type":21,"tag":192,"props":9242,"children":9243},{"style":205},[9244],{"type":27,"value":219},{"type":21,"tag":192,"props":9246,"children":9247},{"class":194,"line":222},[9248,9252,9256],{"type":21,"tag":192,"props":9249,"children":9250},{"style":199},[9251],{"type":27,"value":202},{"type":21,"tag":192,"props":9253,"children":9254},{"style":205},[9255],{"type":27,"value":232},{"type":21,"tag":192,"props":9257,"children":9258},{"style":205},[9259],{"type":27,"value":237},{"type":21,"tag":36,"props":9261,"children":9262},{},[9263],{"type":27,"value":9264},"Content:",{"type":21,"tag":182,"props":9266,"children":9268},{"code":9267,"language":246,"meta":7,"className":247,"style":7},"[Service]\nEnvironment=\"HTTP_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\nEnvironment=\"HTTPS_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\nEnvironment=\"NO_PROXY=127.0.0.1,localhost,192.168.13.119\" \u002F\u002F Change the IP address to the host IP address of your virtual machine.\n",[9269],{"type":21,"tag":141,"props":9270,"children":9271},{"__ignoreMap":7},[9272,9279,9286,9293],{"type":21,"tag":192,"props":9273,"children":9274},{"class":194,"line":195},[9275],{"type":21,"tag":192,"props":9276,"children":9277},{},[9278],{"type":27,"value":259},{"type":21,"tag":192,"props":9280,"children":9281},{"class":194,"line":222},[9282],{"type":21,"tag":192,"props":9283,"children":9284},{},[9285],{"type":27,"value":267},{"type":21,"tag":192,"props":9287,"children":9288},{"class":194,"line":270},[9289],{"type":21,"tag":192,"props":9290,"children":9291},{},[9292],{"type":27,"value":276},{"type":21,"tag":192,"props":9294,"children":9295},{"class":194,"line":279},[9296],{"type":21,"tag":192,"props":9297,"children":9298},{},[9299],{"type":27,"value":9300},"Environment=\"NO_PROXY=127.0.0.1,localhost,192.168.13.119\" \u002F\u002F Change the IP address to the host IP address of your virtual machine.\n",{"type":21,"tag":170,"props":9302,"children":9304},{"id":9303},"step-2-reload-and-restart-docker",[9305],{"type":27,"value":9306},"Step 2 Reload and restart Docker.",{"type":21,"tag":182,"props":9308,"children":9309},{"code":294,"language":185,"meta":7,"className":186,"style":7},[9310],{"type":21,"tag":141,"props":9311,"children":9312},{"__ignoreMap":7},[9313,9328,9347],{"type":21,"tag":192,"props":9314,"children":9315},{"class":194,"line":195},[9316,9320,9324],{"type":21,"tag":192,"props":9317,"children":9318},{"style":199},[9319],{"type":27,"value":202},{"type":21,"tag":192,"props":9321,"children":9322},{"style":205},[9323],{"type":27,"value":310},{"type":21,"tag":192,"props":9325,"children":9326},{"style":205},[9327],{"type":27,"value":315},{"type":21,"tag":192,"props":9329,"children":9330},{"class":194,"line":222},[9331,9335,9339,9343],{"type":21,"tag":192,"props":9332,"children":9333},{"style":199},[9334],{"type":27,"value":202},{"type":21,"tag":192,"props":9336,"children":9337},{"style":205},[9338],{"type":27,"value":310},{"type":21,"tag":192,"props":9340,"children":9341},{"style":205},[9342],{"type":27,"value":331},{"type":21,"tag":192,"props":9344,"children":9345},{"style":205},[9346],{"type":27,"value":336},{"type":21,"tag":192,"props":9348,"children":9349},{"class":194,"line":270},[9350,9354,9358,9362,9366,9370],{"type":21,"tag":192,"props":9351,"children":9352},{"style":199},[9353],{"type":27,"value":202},{"type":21,"tag":192,"props":9355,"children":9356},{"style":205},[9357],{"type":27,"value":310},{"type":21,"tag":192,"props":9359,"children":9360},{"style":205},[9361],{"type":27,"value":352},{"type":21,"tag":192,"props":9363,"children":9364},{"style":205},[9365],{"type":27,"value":357},{"type":21,"tag":192,"props":9367,"children":9368},{"style":211},[9369],{"type":27,"value":362},{"type":21,"tag":192,"props":9371,"children":9372},{"style":211},[9373],{"type":27,"value":367},{"type":21,"tag":36,"props":9375,"children":9376},{},[9377,9379,9384],{"type":27,"value":9378},"If the output contains ",{"type":21,"tag":141,"props":9380,"children":9382},{"className":9381},[],[9383],{"type":27,"value":378},{"type":27,"value":9385},", the proxy configuration takes effect.",{"type":21,"tag":170,"props":9387,"children":9389},{"id":9388},"step-3-check-whether-the-proxy-has-taken-effect",[9390],{"type":27,"value":9391},"Step 3 Check whether the proxy has taken effect.",{"type":21,"tag":182,"props":9393,"children":9394},{"code":388,"language":185,"meta":7,"className":186,"style":7},[9395],{"type":21,"tag":141,"props":9396,"children":9397},{"__ignoreMap":7},[9398],{"type":21,"tag":192,"props":9399,"children":9400},{"class":194,"line":195},[9401,9405,9409,9413,9417,9421],{"type":21,"tag":192,"props":9402,"children":9403},{"style":199},[9404],{"type":27,"value":400},{"type":21,"tag":192,"props":9406,"children":9407},{"style":205},[9408],{"type":27,"value":405},{"type":21,"tag":192,"props":9410,"children":9411},{"style":408},[9412],{"type":27,"value":411},{"type":21,"tag":192,"props":9414,"children":9415},{"style":199},[9416],{"type":27,"value":416},{"type":21,"tag":192,"props":9418,"children":9419},{"style":211},[9420],{"type":27,"value":421},{"type":21,"tag":192,"props":9422,"children":9423},{"style":205},[9424],{"type":27,"value":426},{"type":21,"tag":36,"props":9426,"children":9427},{},[9428],{"type":27,"value":9429},"If the following information is displayed, the proxy has taken effect:",{"type":21,"tag":182,"props":9431,"children":9432},{"code":434,"language":435,"meta":7,"className":436,"style":7},[9433],{"type":21,"tag":141,"props":9434,"children":9435},{"__ignoreMap":7},[9436,9451],{"type":21,"tag":192,"props":9437,"children":9438},{"class":194,"line":195},[9439,9443,9447],{"type":21,"tag":192,"props":9440,"children":9441},{"style":199},[9442],{"type":27,"value":448},{"type":21,"tag":192,"props":9444,"children":9445},{"style":205},[9446],{"type":27,"value":453},{"type":21,"tag":192,"props":9448,"children":9449},{"style":205},[9450],{"type":27,"value":458},{"type":21,"tag":192,"props":9452,"children":9453},{"class":194,"line":222},[9454,9458,9462],{"type":21,"tag":192,"props":9455,"children":9456},{"style":199},[9457],{"type":27,"value":466},{"type":21,"tag":192,"props":9459,"children":9460},{"style":205},[9461],{"type":27,"value":453},{"type":21,"tag":192,"props":9463,"children":9464},{"style":205},[9465],{"type":27,"value":458},{"type":21,"tag":150,"props":9467,"children":9469},{"id":9468},"_42-data-persistence-configuration",[9470],{"type":27,"value":9471},"4.2 Data Persistence Configuration",{"type":21,"tag":50,"props":9473,"children":9474},{},[9475,9487,9497,9509],{"type":21,"tag":54,"props":9476,"children":9477},{},[9478,9480,9485],{"type":27,"value":9479},"Save the H2 database in files, and set the database as follows: ",{"type":21,"tag":141,"props":9481,"children":9483},{"className":9482},[],[9484],{"type":27,"value":494},{"type":27,"value":9486},".",{"type":21,"tag":54,"props":9488,"children":9489},{},[9490,9492],{"type":27,"value":9491},"Host mount path: ",{"type":21,"tag":141,"props":9493,"children":9495},{"className":9494},[],[9496],{"type":27,"value":505},{"type":21,"tag":54,"props":9498,"children":9499},{},[9500,9502,9507],{"type":27,"value":9501},"Do not use ",{"type":21,"tag":141,"props":9503,"children":9505},{"className":9504},[],[9506],{"type":27,"value":516},{"type":27,"value":9508}," to start the container.",{"type":21,"tag":54,"props":9510,"children":9511},{},[9512,9514],{"type":27,"value":9513},"Set the host permission: ",{"type":21,"tag":141,"props":9515,"children":9517},{"className":9516},[],[9518],{"type":27,"value":529},{"type":21,"tag":531,"props":9520,"children":9521},{},[9522],{"type":21,"tag":36,"props":9523,"children":9524},{},[9525],{"type":27,"value":9526},"📌 Note: In a formal environment, it is recommended to use external database, such as PostgreSQL or MySQL, to improve system reliability and disaster recovery capabilities.",{"type":21,"tag":150,"props":9528,"children":9530},{"id":9529},"deployment-using-docker-compose",[9531],{"type":27,"value":9532},"Deployment Using Docker Compose",{"type":21,"tag":546,"props":9534,"children":9535},{},[9536],{"type":21,"tag":54,"props":9537,"children":9538},{},[9539],{"type":27,"value":9540},"Create a directory structure.",{"type":21,"tag":182,"props":9542,"children":9543},{"code":556,"language":185,"meta":7,"className":186,"style":7},[9544],{"type":21,"tag":141,"props":9545,"children":9546},{"__ignoreMap":7},[9547,9562,9573,9588],{"type":21,"tag":192,"props":9548,"children":9549},{"class":194,"line":195},[9550,9554,9558],{"type":21,"tag":192,"props":9551,"children":9552},{"style":199},[9553],{"type":27,"value":568},{"type":21,"tag":192,"props":9555,"children":9556},{"style":211},[9557],{"type":27,"value":214},{"type":21,"tag":192,"props":9559,"children":9560},{"style":205},[9561],{"type":27,"value":577},{"type":21,"tag":192,"props":9563,"children":9564},{"class":194,"line":222},[9565,9569],{"type":21,"tag":192,"props":9566,"children":9567},{"style":583},[9568],{"type":27,"value":586},{"type":21,"tag":192,"props":9570,"children":9571},{"style":205},[9572],{"type":27,"value":577},{"type":21,"tag":192,"props":9574,"children":9575},{"class":194,"line":270},[9576,9580,9584],{"type":21,"tag":192,"props":9577,"children":9578},{"style":199},[9579],{"type":27,"value":568},{"type":21,"tag":192,"props":9581,"children":9582},{"style":211},[9583],{"type":27,"value":214},{"type":21,"tag":192,"props":9585,"children":9586},{"style":205},[9587],{"type":27,"value":606},{"type":21,"tag":192,"props":9589,"children":9590},{"class":194,"line":279},[9591,9595,9599,9603],{"type":21,"tag":192,"props":9592,"children":9593},{"style":199},[9594],{"type":27,"value":614},{"type":21,"tag":192,"props":9596,"children":9597},{"style":211},[9598],{"type":27,"value":619},{"type":21,"tag":192,"props":9600,"children":9601},{"style":205},[9602],{"type":27,"value":624},{"type":21,"tag":192,"props":9604,"children":9605},{"style":205},[9606],{"type":27,"value":606},{"type":21,"tag":546,"props":9608,"children":9609},{"start":222},[9610],{"type":21,"tag":54,"props":9611,"children":9612},{},[9613,9615,9620],{"type":27,"value":9614},"Create and compile ",{"type":21,"tag":141,"props":9616,"children":9618},{"className":9617},[],[9619],{"type":27,"value":642},{"type":27,"value":9621}," in the current directory.",{"type":21,"tag":182,"props":9623,"children":9625},{"code":9624,"language":655,"meta":7,"className":656,"style":7},"version: \"3.3\" # Use Docker Compose v3.3.\n\nservices:\n  ejbca: # Define the service ejbca.\n    image: keyfactor\u002Fejbca-ce:latest # Use the latest EJBCA image (community-edition) provided by Keyfactor.\n    container_name: ejbca # Set the container name to ejbca.\n    hostname: myejbca.test.local # Set the internal host name of the container, which affects fields such as CN in the certificate.\n\n    environment: # Set environment variables to configure the EJBCA startup behavior.\n      - DATABASE_JDBC_URL=jdbc:h2:\u002Fmnt\u002Fpersistent\u002Fejbcadb;DB_CLOSE_DELAY=-1 # Use the embedded H2 database. The data is stored in the mount directory.\n      - TLS_SETUP_ENABLED=true # Enable automatic TLS settings (for HTTPS access).\n      - SMTP_DESTINATION=192.168.xx.xx # Set the SMTP email server address (for sending notification emails).\n      - SMTP_DESTINATION_PORT=25 # Set SMTP service port. The default value is 25. (Encryption is disabled.)\n      - SMTP_FROM=ejbca@example.local # Set the email sender address.\n      - SMTP_TLS_ENABLED=false # Do not enable STARTTLS for SMTP.\n      - SMTP_SSL_ENABLED=false # Do not enable SSL\u002FTLS encryption for SMTP.\n\n    ports: # Map the container port to the host.\n      - \"80:8080\" # Map the host port 80 to the container port 8080 (HTTP).\n      - \"443:8443\" # Map the host port 443 to the container port 8443 (HTTPS).\n\n    volumes: # Mount the data volume to map the directory in the container to the host for data persistence.\n      - \u002Fopt\u002Fejbca-data:\u002Fmnt\u002Fpersistent # Mount the \u002Fopt\u002Fejbca-data directory on the host to the container to persist data such as the database.\n\n    restart: unless-stopped # If the container exits abnormally, the container is automatically restarted unless you manually stop the container.\n",[9626],{"type":21,"tag":141,"props":9627,"children":9628},{"__ignoreMap":7},[9629,9649,9656,9667,9683,9703,9723,9743,9750,9766,9782,9798,9814,9830,9846,9862,9878,9885,9901,9917,9933,9940,9956,9972,9979],{"type":21,"tag":192,"props":9630,"children":9631},{"class":194,"line":195},[9632,9636,9640,9644],{"type":21,"tag":192,"props":9633,"children":9634},{"style":666},[9635],{"type":27,"value":669},{"type":21,"tag":192,"props":9637,"children":9638},{"style":672},[9639],{"type":27,"value":675},{"type":21,"tag":192,"props":9641,"children":9642},{"style":205},[9643],{"type":27,"value":680},{"type":21,"tag":192,"props":9645,"children":9646},{"style":683},[9647],{"type":27,"value":9648}," # Use Docker Compose v3.3.\n",{"type":21,"tag":192,"props":9650,"children":9651},{"class":194,"line":222},[9652],{"type":21,"tag":192,"props":9653,"children":9654},{"emptyLinePlaceholder":692},[9655],{"type":27,"value":695},{"type":21,"tag":192,"props":9657,"children":9658},{"class":194,"line":270},[9659,9663],{"type":21,"tag":192,"props":9660,"children":9661},{"style":666},[9662],{"type":27,"value":703},{"type":21,"tag":192,"props":9664,"children":9665},{"style":672},[9666],{"type":27,"value":708},{"type":21,"tag":192,"props":9668,"children":9669},{"class":194,"line":279},[9670,9674,9678],{"type":21,"tag":192,"props":9671,"children":9672},{"style":666},[9673],{"type":27,"value":716},{"type":21,"tag":192,"props":9675,"children":9676},{"style":672},[9677],{"type":27,"value":675},{"type":21,"tag":192,"props":9679,"children":9680},{"style":683},[9681],{"type":27,"value":9682},"# Define the service ejbca.\n",{"type":21,"tag":192,"props":9684,"children":9685},{"class":194,"line":728},[9686,9690,9694,9698],{"type":21,"tag":192,"props":9687,"children":9688},{"style":666},[9689],{"type":27,"value":734},{"type":21,"tag":192,"props":9691,"children":9692},{"style":672},[9693],{"type":27,"value":675},{"type":21,"tag":192,"props":9695,"children":9696},{"style":205},[9697],{"type":27,"value":743},{"type":21,"tag":192,"props":9699,"children":9700},{"style":683},[9701],{"type":27,"value":9702}," # Use the latest EJBCA image (community-edition) provided by Keyfactor.\n",{"type":21,"tag":192,"props":9704,"children":9705},{"class":194,"line":751},[9706,9710,9714,9718],{"type":21,"tag":192,"props":9707,"children":9708},{"style":666},[9709],{"type":27,"value":757},{"type":21,"tag":192,"props":9711,"children":9712},{"style":672},[9713],{"type":27,"value":675},{"type":21,"tag":192,"props":9715,"children":9716},{"style":205},[9717],{"type":27,"value":766},{"type":21,"tag":192,"props":9719,"children":9720},{"style":683},[9721],{"type":27,"value":9722}," # Set the container name to ejbca.\n",{"type":21,"tag":192,"props":9724,"children":9725},{"class":194,"line":774},[9726,9730,9734,9738],{"type":21,"tag":192,"props":9727,"children":9728},{"style":666},[9729],{"type":27,"value":780},{"type":21,"tag":192,"props":9731,"children":9732},{"style":672},[9733],{"type":27,"value":675},{"type":21,"tag":192,"props":9735,"children":9736},{"style":205},[9737],{"type":27,"value":789},{"type":21,"tag":192,"props":9739,"children":9740},{"style":683},[9741],{"type":27,"value":9742}," # Set the internal host name of the container, which affects fields such as CN in the certificate.\n",{"type":21,"tag":192,"props":9744,"children":9745},{"class":194,"line":797},[9746],{"type":21,"tag":192,"props":9747,"children":9748},{"emptyLinePlaceholder":692},[9749],{"type":27,"value":695},{"type":21,"tag":192,"props":9751,"children":9752},{"class":194,"line":805},[9753,9757,9761],{"type":21,"tag":192,"props":9754,"children":9755},{"style":666},[9756],{"type":27,"value":811},{"type":21,"tag":192,"props":9758,"children":9759},{"style":672},[9760],{"type":27,"value":675},{"type":21,"tag":192,"props":9762,"children":9763},{"style":683},[9764],{"type":27,"value":9765},"# Set environment variables to configure the EJBCA startup behavior.\n",{"type":21,"tag":192,"props":9767,"children":9768},{"class":194,"line":823},[9769,9773,9777],{"type":21,"tag":192,"props":9770,"children":9771},{"style":672},[9772],{"type":27,"value":829},{"type":21,"tag":192,"props":9774,"children":9775},{"style":205},[9776],{"type":27,"value":834},{"type":21,"tag":192,"props":9778,"children":9779},{"style":683},[9780],{"type":27,"value":9781}," # Use the embedded H2 database. The data is stored in the mount directory.\n",{"type":21,"tag":192,"props":9783,"children":9784},{"class":194,"line":842},[9785,9789,9793],{"type":21,"tag":192,"props":9786,"children":9787},{"style":672},[9788],{"type":27,"value":829},{"type":21,"tag":192,"props":9790,"children":9791},{"style":205},[9792],{"type":27,"value":852},{"type":21,"tag":192,"props":9794,"children":9795},{"style":683},[9796],{"type":27,"value":9797}," # Enable automatic TLS settings (for HTTPS access).\n",{"type":21,"tag":192,"props":9799,"children":9800},{"class":194,"line":860},[9801,9805,9809],{"type":21,"tag":192,"props":9802,"children":9803},{"style":672},[9804],{"type":27,"value":829},{"type":21,"tag":192,"props":9806,"children":9807},{"style":205},[9808],{"type":27,"value":870},{"type":21,"tag":192,"props":9810,"children":9811},{"style":683},[9812],{"type":27,"value":9813}," # Set the SMTP email server address (for sending notification emails).\n",{"type":21,"tag":192,"props":9815,"children":9816},{"class":194,"line":878},[9817,9821,9825],{"type":21,"tag":192,"props":9818,"children":9819},{"style":672},[9820],{"type":27,"value":829},{"type":21,"tag":192,"props":9822,"children":9823},{"style":205},[9824],{"type":27,"value":888},{"type":21,"tag":192,"props":9826,"children":9827},{"style":683},[9828],{"type":27,"value":9829}," # Set SMTP service port. The default value is 25. (Encryption is disabled.)\n",{"type":21,"tag":192,"props":9831,"children":9832},{"class":194,"line":896},[9833,9837,9841],{"type":21,"tag":192,"props":9834,"children":9835},{"style":672},[9836],{"type":27,"value":829},{"type":21,"tag":192,"props":9838,"children":9839},{"style":205},[9840],{"type":27,"value":906},{"type":21,"tag":192,"props":9842,"children":9843},{"style":683},[9844],{"type":27,"value":9845}," # Set the email sender address.\n",{"type":21,"tag":192,"props":9847,"children":9848},{"class":194,"line":914},[9849,9853,9857],{"type":21,"tag":192,"props":9850,"children":9851},{"style":672},[9852],{"type":27,"value":829},{"type":21,"tag":192,"props":9854,"children":9855},{"style":205},[9856],{"type":27,"value":924},{"type":21,"tag":192,"props":9858,"children":9859},{"style":683},[9860],{"type":27,"value":9861}," # Do not enable STARTTLS for SMTP.\n",{"type":21,"tag":192,"props":9863,"children":9864},{"class":194,"line":932},[9865,9869,9873],{"type":21,"tag":192,"props":9866,"children":9867},{"style":672},[9868],{"type":27,"value":829},{"type":21,"tag":192,"props":9870,"children":9871},{"style":205},[9872],{"type":27,"value":942},{"type":21,"tag":192,"props":9874,"children":9875},{"style":683},[9876],{"type":27,"value":9877}," # Do not enable SSL\u002FTLS encryption for SMTP.\n",{"type":21,"tag":192,"props":9879,"children":9880},{"class":194,"line":950},[9881],{"type":21,"tag":192,"props":9882,"children":9883},{"emptyLinePlaceholder":692},[9884],{"type":27,"value":695},{"type":21,"tag":192,"props":9886,"children":9887},{"class":194,"line":958},[9888,9892,9896],{"type":21,"tag":192,"props":9889,"children":9890},{"style":666},[9891],{"type":27,"value":964},{"type":21,"tag":192,"props":9893,"children":9894},{"style":672},[9895],{"type":27,"value":675},{"type":21,"tag":192,"props":9897,"children":9898},{"style":683},[9899],{"type":27,"value":9900},"# Map the container port to the host.\n",{"type":21,"tag":192,"props":9902,"children":9903},{"class":194,"line":976},[9904,9908,9912],{"type":21,"tag":192,"props":9905,"children":9906},{"style":672},[9907],{"type":27,"value":829},{"type":21,"tag":192,"props":9909,"children":9910},{"style":205},[9911],{"type":27,"value":986},{"type":21,"tag":192,"props":9913,"children":9914},{"style":683},[9915],{"type":27,"value":9916}," # Map the host port 80 to the container port 8080 (HTTP).\n",{"type":21,"tag":192,"props":9918,"children":9919},{"class":194,"line":994},[9920,9924,9928],{"type":21,"tag":192,"props":9921,"children":9922},{"style":672},[9923],{"type":27,"value":829},{"type":21,"tag":192,"props":9925,"children":9926},{"style":205},[9927],{"type":27,"value":1004},{"type":21,"tag":192,"props":9929,"children":9930},{"style":683},[9931],{"type":27,"value":9932}," # Map the host port 443 to the container port 8443 (HTTPS).\n",{"type":21,"tag":192,"props":9934,"children":9935},{"class":194,"line":1012},[9936],{"type":21,"tag":192,"props":9937,"children":9938},{"emptyLinePlaceholder":692},[9939],{"type":27,"value":695},{"type":21,"tag":192,"props":9941,"children":9942},{"class":194,"line":1020},[9943,9947,9951],{"type":21,"tag":192,"props":9944,"children":9945},{"style":666},[9946],{"type":27,"value":1026},{"type":21,"tag":192,"props":9948,"children":9949},{"style":672},[9950],{"type":27,"value":675},{"type":21,"tag":192,"props":9952,"children":9953},{"style":683},[9954],{"type":27,"value":9955},"# Mount the data volume to map the directory in the container to the host for data persistence.\n",{"type":21,"tag":192,"props":9957,"children":9958},{"class":194,"line":1038},[9959,9963,9967],{"type":21,"tag":192,"props":9960,"children":9961},{"style":672},[9962],{"type":27,"value":829},{"type":21,"tag":192,"props":9964,"children":9965},{"style":205},[9966],{"type":27,"value":505},{"type":21,"tag":192,"props":9968,"children":9969},{"style":683},[9970],{"type":27,"value":9971}," # Mount the \u002Fopt\u002Fejbca-data directory on the host to the container to persist data such as the database.\n",{"type":21,"tag":192,"props":9973,"children":9974},{"class":194,"line":1055},[9975],{"type":21,"tag":192,"props":9976,"children":9977},{"emptyLinePlaceholder":692},[9978],{"type":27,"value":695},{"type":21,"tag":192,"props":9980,"children":9981},{"class":194,"line":1063},[9982,9986,9990,9994],{"type":21,"tag":192,"props":9983,"children":9984},{"style":666},[9985],{"type":27,"value":1069},{"type":21,"tag":192,"props":9987,"children":9988},{"style":672},[9989],{"type":27,"value":675},{"type":21,"tag":192,"props":9991,"children":9992},{"style":205},[9993],{"type":27,"value":1078},{"type":21,"tag":192,"props":9995,"children":9996},{"style":683},[9997],{"type":27,"value":9998}," # If the container exits abnormally, the container is automatically restarted unless you manually stop the container.\n",{"type":21,"tag":546,"props":10000,"children":10001},{"start":270},[10002],{"type":21,"tag":54,"props":10003,"children":10004},{},[10005],{"type":27,"value":10006},"Start the container service.：",{"type":21,"tag":182,"props":10008,"children":10009},{"code":1094,"language":185,"meta":7,"className":186,"style":7},[10010],{"type":21,"tag":141,"props":10011,"children":10012},{"__ignoreMap":7},[10013,10028],{"type":21,"tag":192,"props":10014,"children":10015},{"class":194,"line":195},[10016,10020,10024],{"type":21,"tag":192,"props":10017,"children":10018},{"style":199},[10019],{"type":27,"value":146},{"type":21,"tag":192,"props":10021,"children":10022},{"style":205},[10023],{"type":27,"value":1110},{"type":21,"tag":192,"props":10025,"children":10026},{"style":211},[10027],{"type":27,"value":1115},{"type":21,"tag":192,"props":10029,"children":10030},{"class":194,"line":222},[10031,10035,10039],{"type":21,"tag":192,"props":10032,"children":10033},{"style":199},[10034],{"type":27,"value":146},{"type":21,"tag":192,"props":10036,"children":10037},{"style":205},[10038],{"type":27,"value":1127},{"type":21,"tag":192,"props":10040,"children":10041},{"style":211},[10042],{"type":27,"value":1132},{"type":21,"tag":531,"props":10044,"children":10045},{},[10046],{"type":21,"tag":36,"props":10047,"children":10048},{},[10049],{"type":27,"value":10050},"⚙️ You can use Compose to easily manage configuration versions, facilitating team collaboration and version recovery.",{"type":21,"tag":150,"props":10052,"children":10054},{"id":10053},"_44-remote-access-configuration",[10055],{"type":27,"value":10056},"4.4 Remote Access Configuration",{"type":21,"tag":546,"props":10058,"children":10059},{},[10060],{"type":21,"tag":54,"props":10061,"children":10062},{},[10063],{"type":27,"value":10064},"Set the container's hostname in advance, which affects CN of the TLS certificate.",{"type":21,"tag":182,"props":10066,"children":10067},{"code":1157,"language":655,"meta":7,"className":656,"style":7},[10068],{"type":21,"tag":141,"props":10069,"children":10070},{"__ignoreMap":7},[10071],{"type":21,"tag":192,"props":10072,"children":10073},{"class":194,"line":195},[10074,10078,10082],{"type":21,"tag":192,"props":10075,"children":10076},{"style":666},[10077],{"type":27,"value":1169},{"type":21,"tag":192,"props":10079,"children":10080},{"style":672},[10081],{"type":27,"value":675},{"type":21,"tag":192,"props":10083,"children":10084},{"style":205},[10085],{"type":27,"value":1178},{"type":21,"tag":150,"props":10087,"children":10089},{"id":10088},"_45-certificate-trust-management",[10090],{"type":27,"value":10091},"4.5 Certificate Trust Management",{"type":21,"tag":36,"props":10093,"children":10094},{},[10095],{"type":27,"value":10096},"After downloading the super administrator certificate ·, double-click to import it.",{"type":21,"tag":150,"props":10098,"children":10100},{"id":10099},"_46-login-process-summary",[10101],{"type":27,"value":10102},"4.6 Login Process Summary",{"type":21,"tag":546,"props":10104,"children":10105},{},[10106],{"type":21,"tag":54,"props":10107,"children":10108},{},[10109,10111,10116],{"type":27,"value":10110},"Run ",{"type":21,"tag":141,"props":10112,"children":10114},{"className":10113},[],[10115],{"type":27,"value":1218},{"type":27,"value":10117}," to search for SuperAdmin URL and one-time password in the container logs.",{"type":21,"tag":182,"props":10119,"children":10121},{"code":10120,"language":185,"meta":7,"className":186,"style":7},"ejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *                                                                                                    *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *   URL:      https:\u002F\u002Fmyejbca.test.local:443\u002Fejbca\u002Fra\u002Fenrollwithusername.xhtml?username=superadmin *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *   Password: urAMy0He5c\u002FhHy+DYyDFNy4E                                                               *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *                                                                                                    *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) * Once the P12 is downloaded, use \"urAMy0He5c\u002FhHy+DYyDFNy4E\" to import it.                           *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) *                                                                                                    *\nejbca    | 2025-08-05 09:11:31,656+0000 INFO  [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] (process:1) ******************************************************************************************************\n",[10122],{"type":21,"tag":141,"props":10123,"children":10124},{"__ignoreMap":7},[10125,10168,10231,10278,10321,10376,10419],{"type":21,"tag":192,"props":10126,"children":10127},{"class":194,"line":195},[10128,10132,10136,10140,10144,10148,10152,10156,10160,10164],{"type":21,"tag":192,"props":10129,"children":10130},{"style":199},[10131],{"type":27,"value":766},{"type":21,"tag":192,"props":10133,"children":10134},{"style":408},[10135],{"type":27,"value":1247},{"type":21,"tag":192,"props":10137,"children":10138},{"style":199},[10139],{"type":27,"value":1252},{"type":21,"tag":192,"props":10141,"children":10142},{"style":205},[10143],{"type":27,"value":1257},{"type":21,"tag":192,"props":10145,"children":10146},{"style":205},[10147],{"type":27,"value":1262},{"type":21,"tag":192,"props":10149,"children":10150},{"style":672},[10151],{"type":27,"value":1267},{"type":21,"tag":192,"props":10153,"children":10154},{"style":199},[10155],{"type":27,"value":1272},{"type":21,"tag":192,"props":10157,"children":10158},{"style":672},[10159],{"type":27,"value":1277},{"type":21,"tag":192,"props":10161,"children":10162},{"style":408},[10163],{"type":27,"value":1282},{"type":21,"tag":192,"props":10165,"children":10166},{"style":408},[10167],{"type":27,"value":1287},{"type":21,"tag":192,"props":10169,"children":10170},{"class":194,"line":222},[10171,10175,10179,10183,10187,10191,10195,10199,10203,10207,10211,10215,10219,10223,10227],{"type":21,"tag":192,"props":10172,"children":10173},{"style":199},[10174],{"type":27,"value":766},{"type":21,"tag":192,"props":10176,"children":10177},{"style":408},[10178],{"type":27,"value":1247},{"type":21,"tag":192,"props":10180,"children":10181},{"style":199},[10182],{"type":27,"value":1252},{"type":21,"tag":192,"props":10184,"children":10185},{"style":205},[10186],{"type":27,"value":1257},{"type":21,"tag":192,"props":10188,"children":10189},{"style":205},[10190],{"type":27,"value":1262},{"type":21,"tag":192,"props":10192,"children":10193},{"style":672},[10194],{"type":27,"value":1267},{"type":21,"tag":192,"props":10196,"children":10197},{"style":199},[10198],{"type":27,"value":1272},{"type":21,"tag":192,"props":10200,"children":10201},{"style":672},[10202],{"type":27,"value":1277},{"type":21,"tag":192,"props":10204,"children":10205},{"style":408},[10206],{"type":27,"value":1282},{"type":21,"tag":192,"props":10208,"children":10209},{"style":672},[10210],{"type":27,"value":1331},{"type":21,"tag":192,"props":10212,"children":10213},{"style":408},[10214],{"type":27,"value":1336},{"type":21,"tag":192,"props":10216,"children":10217},{"style":672},[10218],{"type":27,"value":1341},{"type":21,"tag":192,"props":10220,"children":10221},{"style":408},[10222],{"type":27,"value":1346},{"type":21,"tag":192,"props":10224,"children":10225},{"style":205},[10226],{"type":27,"value":1351},{"type":21,"tag":192,"props":10228,"children":10229},{"style":199},[10230],{"type":27,"value":1356},{"type":21,"tag":192,"props":10232,"children":10233},{"class":194,"line":270},[10234,10238,10242,10246,10250,10254,10258,10262,10266,10270,10274],{"type":21,"tag":192,"props":10235,"children":10236},{"style":199},[10237],{"type":27,"value":766},{"type":21,"tag":192,"props":10239,"children":10240},{"style":408},[10241],{"type":27,"value":1247},{"type":21,"tag":192,"props":10243,"children":10244},{"style":199},[10245],{"type":27,"value":1252},{"type":21,"tag":192,"props":10247,"children":10248},{"style":205},[10249],{"type":27,"value":1257},{"type":21,"tag":192,"props":10251,"children":10252},{"style":205},[10253],{"type":27,"value":1262},{"type":21,"tag":192,"props":10255,"children":10256},{"style":672},[10257],{"type":27,"value":1267},{"type":21,"tag":192,"props":10259,"children":10260},{"style":199},[10261],{"type":27,"value":1272},{"type":21,"tag":192,"props":10263,"children":10264},{"style":672},[10265],{"type":27,"value":1277},{"type":21,"tag":192,"props":10267,"children":10268},{"style":408},[10269],{"type":27,"value":1282},{"type":21,"tag":192,"props":10271,"children":10272},{"style":672},[10273],{"type":27,"value":1400},{"type":21,"tag":192,"props":10275,"children":10276},{"style":408},[10277],{"type":27,"value":1405},{"type":21,"tag":192,"props":10279,"children":10280},{"class":194,"line":279},[10281,10285,10289,10293,10297,10301,10305,10309,10313,10317],{"type":21,"tag":192,"props":10282,"children":10283},{"style":199},[10284],{"type":27,"value":766},{"type":21,"tag":192,"props":10286,"children":10287},{"style":408},[10288],{"type":27,"value":1247},{"type":21,"tag":192,"props":10290,"children":10291},{"style":199},[10292],{"type":27,"value":1252},{"type":21,"tag":192,"props":10294,"children":10295},{"style":205},[10296],{"type":27,"value":1257},{"type":21,"tag":192,"props":10298,"children":10299},{"style":205},[10300],{"type":27,"value":1262},{"type":21,"tag":192,"props":10302,"children":10303},{"style":672},[10304],{"type":27,"value":1267},{"type":21,"tag":192,"props":10306,"children":10307},{"style":199},[10308],{"type":27,"value":1272},{"type":21,"tag":192,"props":10310,"children":10311},{"style":672},[10312],{"type":27,"value":1277},{"type":21,"tag":192,"props":10314,"children":10315},{"style":408},[10316],{"type":27,"value":1282},{"type":21,"tag":192,"props":10318,"children":10319},{"style":408},[10320],{"type":27,"value":1287},{"type":21,"tag":192,"props":10322,"children":10323},{"class":194,"line":728},[10324,10328,10332,10336,10340,10344,10348,10352,10356,10360,10364,10368,10372],{"type":21,"tag":192,"props":10325,"children":10326},{"style":199},[10327],{"type":27,"value":766},{"type":21,"tag":192,"props":10329,"children":10330},{"style":408},[10331],{"type":27,"value":1247},{"type":21,"tag":192,"props":10333,"children":10334},{"style":199},[10335],{"type":27,"value":1252},{"type":21,"tag":192,"props":10337,"children":10338},{"style":205},[10339],{"type":27,"value":1257},{"type":21,"tag":192,"props":10341,"children":10342},{"style":205},[10343],{"type":27,"value":1262},{"type":21,"tag":192,"props":10345,"children":10346},{"style":672},[10347],{"type":27,"value":1267},{"type":21,"tag":192,"props":10349,"children":10350},{"style":199},[10351],{"type":27,"value":1272},{"type":21,"tag":192,"props":10353,"children":10354},{"style":672},[10355],{"type":27,"value":1277},{"type":21,"tag":192,"props":10357,"children":10358},{"style":408},[10359],{"type":27,"value":1282},{"type":21,"tag":192,"props":10361,"children":10362},{"style":672},[10363],{"type":27,"value":1492},{"type":21,"tag":192,"props":10365,"children":10366},{"style":205},[10367],{"type":27,"value":1497},{"type":21,"tag":192,"props":10369,"children":10370},{"style":672},[10371],{"type":27,"value":1502},{"type":21,"tag":192,"props":10373,"children":10374},{"style":408},[10375],{"type":27,"value":1405},{"type":21,"tag":192,"props":10377,"children":10378},{"class":194,"line":751},[10379,10383,10387,10391,10395,10399,10403,10407,10411,10415],{"type":21,"tag":192,"props":10380,"children":10381},{"style":199},[10382],{"type":27,"value":766},{"type":21,"tag":192,"props":10384,"children":10385},{"style":408},[10386],{"type":27,"value":1247},{"type":21,"tag":192,"props":10388,"children":10389},{"style":199},[10390],{"type":27,"value":1252},{"type":21,"tag":192,"props":10392,"children":10393},{"style":205},[10394],{"type":27,"value":1257},{"type":21,"tag":192,"props":10396,"children":10397},{"style":205},[10398],{"type":27,"value":1262},{"type":21,"tag":192,"props":10400,"children":10401},{"style":672},[10402],{"type":27,"value":1267},{"type":21,"tag":192,"props":10404,"children":10405},{"style":199},[10406],{"type":27,"value":1272},{"type":21,"tag":192,"props":10408,"children":10409},{"style":672},[10410],{"type":27,"value":1277},{"type":21,"tag":192,"props":10412,"children":10413},{"style":408},[10414],{"type":27,"value":1282},{"type":21,"tag":192,"props":10416,"children":10417},{"style":408},[10418],{"type":27,"value":1287},{"type":21,"tag":192,"props":10420,"children":10421},{"class":194,"line":774},[10422,10426,10430,10434,10438,10442,10446,10450,10454],{"type":21,"tag":192,"props":10423,"children":10424},{"style":199},[10425],{"type":27,"value":766},{"type":21,"tag":192,"props":10427,"children":10428},{"style":408},[10429],{"type":27,"value":1247},{"type":21,"tag":192,"props":10431,"children":10432},{"style":199},[10433],{"type":27,"value":1252},{"type":21,"tag":192,"props":10435,"children":10436},{"style":205},[10437],{"type":27,"value":1257},{"type":21,"tag":192,"props":10439,"children":10440},{"style":205},[10441],{"type":27,"value":1262},{"type":21,"tag":192,"props":10443,"children":10444},{"style":672},[10445],{"type":27,"value":1267},{"type":21,"tag":192,"props":10447,"children":10448},{"style":199},[10449],{"type":27,"value":1272},{"type":21,"tag":192,"props":10451,"children":10452},{"style":672},[10453],{"type":27,"value":1277},{"type":21,"tag":192,"props":10455,"children":10456},{"style":408},[10457],{"type":27,"value":1589},{"type":21,"tag":546,"props":10459,"children":10460},{},[10461,10473,10485],{"type":21,"tag":54,"props":10462,"children":10463},{},[10464,10466,10471],{"type":27,"value":10465},"Access the URL, enter the password, set the export password, and download the ",{"type":21,"tag":141,"props":10467,"children":10469},{"className":10468},[],[10470],{"type":27,"value":1198},{"type":27,"value":10472}," certificate.",{"type":21,"tag":54,"props":10474,"children":10475},{},[10476,10478,10484],{"type":27,"value":10477},"Import the certificate and access ",{"type":21,"tag":5009,"props":10479,"children":10482},{"href":1613,"rel":10480},[10481],"nofollow",[10483],{"type":27,"value":1613},{"type":27,"value":9486},{"type":21,"tag":54,"props":10486,"children":10487},{},[10488],{"type":27,"value":10489},"If the system displays a message indicating that the client certificate is not provided, check whether the certificate is successfully imported, the proxy is disabled, and the domain name is correctly resolved.",{"type":21,"tag":531,"props":10491,"children":10492},{},[10493],{"type":21,"tag":36,"props":10494,"children":10495},{},[10496],{"type":27,"value":10497},"✅ So far, the EJBCA deployment, persistence, and management login process is completed.",{"type":21,"tag":150,"props":10499,"children":10501},{"id":10500},"important-notes-must-be-followed",[10502],{"type":27,"value":10503},"Important Notes (Must Be Followed)",{"type":21,"tag":36,"props":10505,"children":10506},{},[10507,10508,10513,10515,10519,10521,10524,10526,10529,10531,10536,10538,10541,10542,10547,10549,10554,10556,10559,10560,10565,10566,10571],{"type":27,"value":1637},{"type":21,"tag":42,"props":10509,"children":10510},{},[10511],{"type":27,"value":10512},"You must",{"type":27,"value":10514}," add ",{"type":21,"tag":42,"props":10516,"children":10517},{},[10518],{"type":27,"value":789},{"type":27,"value":10520}," to the hosts file or set up a local DNS server. Otherwise, the browser may fail to resolve the domain name.",{"type":21,"tag":1957,"props":10522,"children":10523},{},[],{"type":27,"value":10525},"\n✅ The default algorithm for the super administrator certificate is DILITHIUM2, which may vary by version. However, Windows probably cannot recognize DILITHIUM2. To ensure compatibility, it is advised to switch the algorithm to RSA 4096.",{"type":21,"tag":1957,"props":10527,"children":10528},{},[],{"type":27,"value":10530},"\n✅ ",{"type":21,"tag":42,"props":10532,"children":10533},{},[10534],{"type":27,"value":10535},"No proxy should be enabled",{"type":27,"value":10537},". Otherwise, EJBCA may fail to correctly process client certificate authentication.",{"type":21,"tag":1957,"props":10539,"children":10540},{},[],{"type":27,"value":10530},{"type":21,"tag":42,"props":10543,"children":10544},{},[10545],{"type":27,"value":10546},"Ensure that the Windows\u002FmacOS\u002FLinux certificate is correctly imported",{"type":27,"value":10548}," to avoid the \"",{"type":21,"tag":141,"props":10550,"children":10552},{"className":10551},[],[10553],{"type":27,"value":1712},{"type":27,"value":10555},"\" error.",{"type":21,"tag":1957,"props":10557,"children":10558},{},[],{"type":27,"value":10530},{"type":21,"tag":42,"props":10561,"children":10562},{},[10563],{"type":27,"value":10564},"It is recommended that you use the Chrome browser in Incognito mode for the first time",{"type":27,"value":10548},{"type":21,"tag":141,"props":10567,"children":10569},{"className":10568},[],[10570],{"type":27,"value":1712},{"type":27,"value":10572},"\" error caused by cache problems.",{"type":21,"tag":65,"props":10574,"children":10575},{},[],{"type":21,"tag":29,"props":10577,"children":10579},{"id":10578},"_5-initial-ca-creation-and-certificate-level-setup",[10580],{"type":27,"value":10581},"5. Initial CA Creation and Certificate Level Setup",{"type":21,"tag":150,"props":10583,"children":10585},{"id":10584},"_51-managing-certificate-profiles",[10586],{"type":27,"value":10587},"5.1 Managing Certificate Profiles",{"type":21,"tag":50,"props":10589,"children":10590},{},[10591,10596],{"type":21,"tag":54,"props":10592,"children":10593},{},[10594],{"type":27,"value":10595},"Log in to the EJBCA management console.",{"type":21,"tag":54,"props":10597,"children":10598},{},[10599,10601,10606],{"type":27,"value":10600},"Choose ",{"type":21,"tag":42,"props":10602,"children":10603},{},[10604],{"type":27,"value":10605},"CA Functions > Certificate Profiles",{"type":27,"value":9486},{"type":21,"tag":150,"props":10608,"children":10610},{"id":10609},"_52-creating-a-certificate-profile",[10611],{"type":27,"value":10612},"5.2 Creating a Certificate Profile",{"type":21,"tag":170,"props":10614,"children":10616},{"id":10615},"method-1-cloning-an-existing-profile",[10617],{"type":27,"value":10618},"Method 1: Cloning an Existing Profile",{"type":21,"tag":50,"props":10620,"children":10621},{},[10622,10633],{"type":21,"tag":54,"props":10623,"children":10624},{},[10625,10627,10631],{"type":27,"value":10626},"Find an appropriate profile (for example, ",{"type":21,"tag":42,"props":10628,"children":10629},{},[10630],{"type":27,"value":1799},{"type":27,"value":10632},") in the list.",{"type":21,"tag":54,"props":10634,"children":10635},{},[10636,10638,10642],{"type":27,"value":10637},"Click ",{"type":21,"tag":42,"props":10639,"children":10640},{},[10641],{"type":27,"value":1811},{"type":27,"value":10643},", enter the new name, and save the profile.",{"type":21,"tag":170,"props":10645,"children":10647},{"id":10646},"method-2-manually-creating-a-profile",[10648],{"type":27,"value":10649},"Method 2: Manually Creating a Profile",{"type":21,"tag":50,"props":10651,"children":10652},{},[10653,10663,10680],{"type":21,"tag":54,"props":10654,"children":10655},{},[10656,10657,10661],{"type":27,"value":10637},{"type":21,"tag":42,"props":10658,"children":10659},{},[10660],{"type":27,"value":1831},{"type":27,"value":10662}," and enter the name. The editing page is displayed.",{"type":21,"tag":54,"props":10664,"children":10665},{},[10666,10668,10672,10674,10678],{"type":27,"value":10667},"Set necessary information as required, including ",{"type":21,"tag":42,"props":10669,"children":10670},{},[10671],{"type":27,"value":1843},{"type":27,"value":10673},", ",{"type":21,"tag":42,"props":10675,"children":10676},{},[10677],{"type":27,"value":1850},{"type":27,"value":10679},", validity period, and Subject DN.",{"type":21,"tag":54,"props":10681,"children":10682},{},[10683],{"type":27,"value":10684},"Save the settings and return to the list for check.",{"type":21,"tag":150,"props":10686,"children":10688},{"id":10687},"_53-creating-a-crypto-token",[10689],{"type":27,"value":10690},"5.3 Creating a Crypto Token",{"type":21,"tag":546,"props":10692,"children":10693},{},[10694,10703,10782],{"type":21,"tag":54,"props":10695,"children":10696},{},[10697,10698,10702],{"type":27,"value":10600},{"type":21,"tag":42,"props":10699,"children":10700},{},[10701],{"type":27,"value":1876},{"type":27,"value":1732},{"type":21,"tag":54,"props":10704,"children":10705},{},[10706,10707,10711,10713],{"type":27,"value":10637},{"type":21,"tag":42,"props":10708,"children":10709},{},[10710],{"type":27,"value":1886},{"type":27,"value":10712}," and enter the following information:",{"type":21,"tag":50,"props":10714,"children":10715},{},[10716,10725,10740,10750,10765],{"type":21,"tag":54,"props":10717,"children":10718},{},[10719,10723],{"type":21,"tag":42,"props":10720,"children":10721},{},[10722],{"type":27,"value":1899},{"type":27,"value":10724},"：Enter the name of your crypto token.",{"type":21,"tag":54,"props":10726,"children":10727},{},[10728,10732,10734,10739],{"type":21,"tag":42,"props":10729,"children":10730},{},[10731],{"type":27,"value":1909},{"type":27,"value":10733},"：Select ",{"type":21,"tag":141,"props":10735,"children":10737},{"className":10736},[],[10738],{"type":27,"value":1917},{"type":27,"value":1732},{"type":21,"tag":54,"props":10741,"children":10742},{},[10743,10748],{"type":21,"tag":42,"props":10744,"children":10745},{},[10746],{"type":27,"value":10747},"Auto-activation(Optional)",{"type":27,"value":10749},"：If selected, the crypto token can be automatically activated.",{"type":21,"tag":54,"props":10751,"children":10752},{},[10753,10757,10758,10763],{"type":21,"tag":42,"props":10754,"children":10755},{},[10756],{"type":27,"value":1936},{"type":27,"value":10733},{"type":21,"tag":141,"props":10759,"children":10761},{"className":10760},[],[10762],{"type":27,"value":1944},{"type":27,"value":10764}," if you want to export the private key.",{"type":21,"tag":54,"props":10766,"children":10767},{},[10768,10772,10774,10777],{"type":21,"tag":42,"props":10769,"children":10770},{},[10771],{"type":27,"value":1953},{"type":27,"value":10773},"：Enter the authentication code and confirm it.",{"type":21,"tag":1957,"props":10775,"children":10776},{},[],{"type":21,"tag":141,"props":10778,"children":10780},{"className":10779},[],[10781],{"type":27,"value":1965},{"type":21,"tag":54,"props":10783,"children":10784},{},[10785,10787,10791],{"type":27,"value":10786},"Save the settings and ensure that the status is ",{"type":21,"tag":42,"props":10788,"children":10789},{},[10790],{"type":27,"value":1975},{"type":27,"value":10792}," in the list。",{"type":21,"tag":150,"props":10794,"children":10796},{"id":10795},"_54-generating-a-key-pair",[10797],{"type":27,"value":10798},"5.4 Generating a Key Pair",{"type":21,"tag":50,"props":10800,"children":10801},{},[10802,10813,10832,10843],{"type":21,"tag":54,"props":10803,"children":10804},{},[10805,10807,10811],{"type":27,"value":10806},"Access the x",{"type":21,"tag":42,"props":10808,"children":10809},{},[10810],{"type":27,"value":1994},{"type":27,"value":10812}," details page.",{"type":21,"tag":54,"props":10814,"children":10815},{},[10816,10818,10823,10825,10831],{"type":27,"value":10817},"Enter the key name, for example, ",{"type":21,"tag":141,"props":10819,"children":10821},{"className":10820},[],[10822],{"type":27,"value":2015},{"type":27,"value":10824},", in ",{"type":21,"tag":141,"props":10826,"children":10828},{"className":10827},[],[10829],{"type":27,"value":10830},"Crypto Token currently does not contain any key pairs",{"type":27,"value":9486},{"type":21,"tag":54,"props":10833,"children":10834},{},[10835,10837,10842],{"type":27,"value":10836},"Select a key algorithm, for example, ",{"type":21,"tag":141,"props":10838,"children":10840},{"className":10839},[],[10841],{"type":27,"value":1682},{"type":27,"value":9486},{"type":21,"tag":54,"props":10844,"children":10845},{},[10846,10847,10851],{"type":27,"value":10637},{"type":21,"tag":42,"props":10848,"children":10849},{},[10850],{"type":27,"value":2036},{"type":27,"value":9486},{"type":21,"tag":531,"props":10853,"children":10854},{},[10855],{"type":21,"tag":36,"props":10856,"children":10857},{},[10858,10863],{"type":21,"tag":42,"props":10859,"children":10860},{},[10861],{"type":27,"value":10862},"Note",{"type":27,"value":10864},": The default profile cannot be modified. You need to clone it before creating a new one.",{"type":21,"tag":150,"props":10866,"children":10868},{"id":10867},"_55-creating-a-ca",[10869],{"type":27,"value":10870},"5.5 Creating a CA",{"type":21,"tag":546,"props":10872,"children":10873},{},[10874,10883,10901,10938,10949,10966],{"type":21,"tag":54,"props":10875,"children":10876},{},[10877,10878,10882],{"type":27,"value":10600},{"type":21,"tag":42,"props":10879,"children":10880},{},[10881],{"type":27,"value":2070},{"type":27,"value":1732},{"type":21,"tag":54,"props":10884,"children":10885},{},[10886,10888,10893,10895,10900],{"type":27,"value":10887},"The default ",{"type":21,"tag":141,"props":10889,"children":10891},{"className":10890},[],[10892],{"type":27,"value":2082},{"type":27,"value":10894}," is displayed in the list on the top. ",{"type":21,"tag":42,"props":10896,"children":10897},{},[10898],{"type":27,"value":10899},"You do not need to select it",{"type":27,"value":1732},{"type":21,"tag":54,"props":10902,"children":10903},{},[10904,10906,10911,10913],{"type":27,"value":10905},"Scroll to the ",{"type":21,"tag":141,"props":10907,"children":10909},{"className":10908},[],[10910],{"type":27,"value":2100},{"type":27,"value":10912}," area at the bottom of the page.\n",{"type":21,"tag":50,"props":10914,"children":10915},{},[10916,10928],{"type":21,"tag":54,"props":10917,"children":10918},{},[10919,10921,10926],{"type":27,"value":10920},"Enter the new CA name, for example, ",{"type":21,"tag":141,"props":10922,"children":10924},{"className":10923},[],[10925],{"type":27,"value":2116},{"type":27,"value":10927},", in the text box.",{"type":21,"tag":54,"props":10929,"children":10930},{},[10931,10932,10936],{"type":27,"value":10637},{"type":21,"tag":42,"props":10933,"children":10934},{},[10935],{"type":27,"value":2127},{"type":27,"value":10937}," on the right. The CA configuration wizard is displayed.",{"type":21,"tag":54,"props":10939,"children":10940},{},[10941,10943,10947],{"type":27,"value":10942},"Enter necessary fields on the ",{"type":21,"tag":42,"props":10944,"children":10945},{},[10946],{"type":27,"value":2139},{"type":27,"value":10948}," page.",{"type":21,"tag":54,"props":10950,"children":10951},{},[10952,10953,10957,10959,10964],{"type":27,"value":10637},{"type":21,"tag":42,"props":10954,"children":10955},{},[10956],{"type":27,"value":2151},{"type":27,"value":10958}," at the bottom to save the CA. If the configuration is correct, the CA list is displayed and the ",{"type":21,"tag":141,"props":10960,"children":10962},{"className":10961},[],[10963],{"type":27,"value":2159},{"type":27,"value":10965}," status is displayed.",{"type":21,"tag":54,"props":10967,"children":10968},{},[10969,10971,10975],{"type":27,"value":10970},"(Optional) If you want to manually upload the certificate issued by the root CA, select the new CA in the list and select ",{"type":21,"tag":42,"props":10972,"children":10973},{},[10974],{"type":27,"value":2171},{"type":27,"value":10976}," to upload the chain file.",{"type":21,"tag":36,"props":10978,"children":10979},{},[10980],{"type":27,"value":10981},"The intermediate CA is created. You can use it to issue end-entity certificates.",{"type":21,"tag":150,"props":10983,"children":10985},{"id":10984},"_56-example-creating-a-root-ca",[10986],{"type":27,"value":10987},"5.6 (Example) Creating a Root CA",{"type":21,"tag":170,"props":10989,"children":10991},{"id":10990},"_1️⃣-ca-type-and-key-configuration",[10992],{"type":27,"value":10993},"1️⃣ CA type and key configuration",{"type":21,"tag":2192,"props":10995,"children":10996},{},[10997,11018],{"type":21,"tag":2196,"props":10998,"children":10999},{},[11000],{"type":21,"tag":2200,"props":11001,"children":11002},{},[11003,11011],{"type":21,"tag":2204,"props":11004,"children":11005},{},[11006],{"type":21,"tag":42,"props":11007,"children":11008},{},[11009],{"type":27,"value":11010},"Parameter",{"type":21,"tag":2204,"props":11012,"children":11013},{},[11014],{"type":21,"tag":42,"props":11015,"children":11016},{},[11017],{"type":27,"value":2374},{"type":21,"tag":2221,"props":11019,"children":11020},{},[11021,11042,11070,11091,11113,11134,11155],{"type":21,"tag":2200,"props":11022,"children":11023},{},[11024,11031],{"type":21,"tag":2228,"props":11025,"children":11026},{},[11027],{"type":21,"tag":42,"props":11028,"children":11029},{},[11030],{"type":27,"value":2235},{"type":21,"tag":2228,"props":11032,"children":11033},{},[11034,11035,11040],{"type":27,"value":1637},{"type":21,"tag":141,"props":11036,"children":11038},{"className":11037},[],[11039],{"type":27,"value":2244},{"type":27,"value":11041},"; Standard X.509 CA",{"type":21,"tag":2200,"props":11043,"children":11044},{},[11045,11052],{"type":21,"tag":2228,"props":11046,"children":11047},{},[11048],{"type":21,"tag":42,"props":11049,"children":11050},{},[11051],{"type":27,"value":1994},{"type":21,"tag":2228,"props":11053,"children":11054},{},[11055,11057,11062,11064,11069],{"type":27,"value":11056},"✅ Select the created ",{"type":21,"tag":141,"props":11058,"children":11060},{"className":11059},[],[11061],{"type":27,"value":1994},{"type":27,"value":11063},", for example, ",{"type":21,"tag":141,"props":11065,"children":11067},{"className":11066},[],[11068],{"type":27,"value":2274},{"type":27,"value":9486},{"type":21,"tag":2200,"props":11071,"children":11072},{},[11073,11080],{"type":21,"tag":2228,"props":11074,"children":11075},{},[11076],{"type":21,"tag":42,"props":11077,"children":11078},{},[11079],{"type":27,"value":2286},{"type":21,"tag":2228,"props":11081,"children":11082},{},[11083,11084,11089],{"type":27,"value":1637},{"type":21,"tag":141,"props":11085,"children":11087},{"className":11086},[],[11088],{"type":27,"value":2295},{"type":27,"value":11090},"; Secure signature algorithm",{"type":21,"tag":2200,"props":11092,"children":11093},{},[11094,11101],{"type":21,"tag":2228,"props":11095,"children":11096},{},[11097],{"type":21,"tag":42,"props":11098,"children":11099},{},[11100],{"type":27,"value":2308},{"type":21,"tag":2228,"props":11102,"children":11103},{},[11104,11106,11111],{"type":27,"value":11105},"❌ ",{"type":21,"tag":141,"props":11107,"children":11109},{"className":11108},[],[11110],{"type":27,"value":2317},{"type":27,"value":11112},"; No backup signature algorithm is required.",{"type":21,"tag":2200,"props":11114,"children":11115},{},[11116,11123],{"type":21,"tag":2228,"props":11117,"children":11118},{},[11119],{"type":21,"tag":42,"props":11120,"children":11121},{},[11122],{"type":27,"value":2330},{"type":21,"tag":2228,"props":11124,"children":11125},{},[11126,11127,11132],{"type":27,"value":1637},{"type":21,"tag":141,"props":11128,"children":11130},{"className":11129},[],[11131],{"type":27,"value":2339},{"type":27,"value":11133},"; Serial number of the CA certificate",{"type":21,"tag":2200,"props":11135,"children":11136},{},[11137,11144],{"type":21,"tag":2228,"props":11138,"children":11139},{},[11140],{"type":21,"tag":42,"props":11141,"children":11142},{},[11143],{"type":27,"value":2352},{"type":21,"tag":2228,"props":11145,"children":11146},{},[11147,11148,11153],{"type":27,"value":1637},{"type":21,"tag":141,"props":11149,"children":11151},{"className":11150},[],[11152],{"type":27,"value":2361},{"type":27,"value":11154}," ; Initial serial number, which can be changed.",{"type":21,"tag":2200,"props":11156,"children":11157},{},[11158,11165],{"type":21,"tag":2228,"props":11159,"children":11160},{},[11161],{"type":21,"tag":42,"props":11162,"children":11163},{},[11164],{"type":27,"value":2374},{"type":21,"tag":2228,"props":11166,"children":11167},{},[11168],{"type":27,"value":11169},"✅ Root CA description, including the purpose and management unit.",{"type":21,"tag":65,"props":11171,"children":11172},{},[],{"type":21,"tag":170,"props":11174,"children":11176},{"id":11175},"_2️⃣-certificate-policies-directives",[11177],{"type":27,"value":11178},"2️⃣ Certificate policies (Directives)",{"type":21,"tag":2192,"props":11180,"children":11181},{},[11182,11202],{"type":21,"tag":2196,"props":11183,"children":11184},{},[11185],{"type":21,"tag":2200,"props":11186,"children":11187},{},[11188,11195],{"type":21,"tag":2204,"props":11189,"children":11190},{},[11191],{"type":21,"tag":42,"props":11192,"children":11193},{},[11194],{"type":27,"value":11010},{"type":21,"tag":2204,"props":11196,"children":11197},{},[11198],{"type":21,"tag":42,"props":11199,"children":11200},{},[11201],{"type":27,"value":2374},{"type":21,"tag":2221,"props":11203,"children":11204},{},[11205,11220,11235,11257,11272,11287,11302],{"type":21,"tag":2200,"props":11206,"children":11207},{},[11208,11215],{"type":21,"tag":2228,"props":11209,"children":11210},{},[11211],{"type":21,"tag":42,"props":11212,"children":11213},{},[11214],{"type":27,"value":2425},{"type":21,"tag":2228,"props":11216,"children":11217},{},[11218],{"type":27,"value":11219},"✅ Enforces the public key to be unique.",{"type":21,"tag":2200,"props":11221,"children":11222},{},[11223,11230],{"type":21,"tag":2228,"props":11224,"children":11225},{},[11226],{"type":21,"tag":42,"props":11227,"children":11228},{},[11229],{"type":27,"value":2441},{"type":21,"tag":2228,"props":11231,"children":11232},{},[11233],{"type":27,"value":11234},"❌ Not required for the root CA.",{"type":21,"tag":2200,"props":11236,"children":11237},{},[11238,11245],{"type":21,"tag":2228,"props":11239,"children":11240},{},[11241],{"type":21,"tag":42,"props":11242,"children":11243},{},[11244],{"type":27,"value":2457},{"type":21,"tag":2228,"props":11246,"children":11247},{},[11248,11250,11255],{"type":27,"value":11249},"✅ Ensures ",{"type":21,"tag":141,"props":11251,"children":11253},{"className":11252},[],[11254],{"type":27,"value":2468},{"type":27,"value":11256}," uniqueness (applicable to small-scale CAs).",{"type":21,"tag":2200,"props":11258,"children":11259},{},[11260,11267],{"type":21,"tag":2228,"props":11261,"children":11262},{},[11263],{"type":21,"tag":42,"props":11264,"children":11265},{},[11266],{"type":27,"value":2481},{"type":21,"tag":2228,"props":11268,"children":11269},{},[11270],{"type":27,"value":11271},"❌ Applicable only to large-scale CAs (not required for CAs with fewer than 20 certificates).",{"type":21,"tag":2200,"props":11273,"children":11274},{},[11275,11282],{"type":21,"tag":2228,"props":11276,"children":11277},{},[11278],{"type":21,"tag":42,"props":11279,"children":11280},{},[11281],{"type":27,"value":2497},{"type":21,"tag":2228,"props":11283,"children":11284},{},[11285],{"type":27,"value":11286},"❌ Records certificate request history (not required for the root CA).",{"type":21,"tag":2200,"props":11288,"children":11289},{},[11290,11297],{"type":21,"tag":2228,"props":11291,"children":11292},{},[11293],{"type":21,"tag":42,"props":11294,"children":11295},{},[11296],{"type":27,"value":2513},{"type":21,"tag":2228,"props":11298,"children":11299},{},[11300],{"type":27,"value":11301},"✅ Stores user information.",{"type":21,"tag":2200,"props":11303,"children":11304},{},[11305,11312],{"type":21,"tag":2228,"props":11306,"children":11307},{},[11308],{"type":21,"tag":42,"props":11309,"children":11310},{},[11311],{"type":27,"value":2529},{"type":21,"tag":2228,"props":11313,"children":11314},{},[11315],{"type":27,"value":11316},"✅ Stores issued certificates.",{"type":21,"tag":65,"props":11318,"children":11319},{},[],{"type":21,"tag":170,"props":11321,"children":11323},{"id":11322},"_3️⃣-ca-certificate-data",[11324],{"type":27,"value":11325},"3️⃣ CA certificate data",{"type":21,"tag":2192,"props":11327,"children":11328},{},[11329,11349],{"type":21,"tag":2196,"props":11330,"children":11331},{},[11332],{"type":21,"tag":2200,"props":11333,"children":11334},{},[11335,11342],{"type":21,"tag":2204,"props":11336,"children":11337},{},[11338],{"type":21,"tag":42,"props":11339,"children":11340},{},[11341],{"type":27,"value":11010},{"type":21,"tag":2204,"props":11343,"children":11344},{},[11345],{"type":21,"tag":42,"props":11346,"children":11347},{},[11348],{"type":27,"value":2374},{"type":21,"tag":2221,"props":11350,"children":11351},{},[11352,11371,11392,11413,11434,11448,11463,11478,11493,11515,11536,11551],{"type":21,"tag":2200,"props":11353,"children":11354},{},[11355,11362],{"type":21,"tag":2228,"props":11356,"children":11357},{},[11358],{"type":21,"tag":42,"props":11359,"children":11360},{},[11361],{"type":27,"value":2580},{"type":21,"tag":2228,"props":11363,"children":11364},{},[11365,11366],{"type":27,"value":1637},{"type":21,"tag":141,"props":11367,"children":11369},{"className":11368},[],[11370],{"type":27,"value":2589},{"type":21,"tag":2200,"props":11372,"children":11373},{},[11374,11381],{"type":21,"tag":2228,"props":11375,"children":11376},{},[11377],{"type":21,"tag":42,"props":11378,"children":11379},{},[11380],{"type":27,"value":2602},{"type":21,"tag":2228,"props":11382,"children":11383},{},[11384,11385,11390],{"type":27,"value":1637},{"type":21,"tag":141,"props":11386,"children":11388},{"className":11387},[],[11389],{"type":27,"value":2611},{"type":27,"value":11391},"; Root CA must be self-signed.",{"type":21,"tag":2200,"props":11393,"children":11394},{},[11395,11402],{"type":21,"tag":2228,"props":11396,"children":11397},{},[11398],{"type":21,"tag":42,"props":11399,"children":11400},{},[11401],{"type":27,"value":2624},{"type":21,"tag":2228,"props":11403,"children":11404},{},[11405,11406,11411],{"type":27,"value":1637},{"type":21,"tag":141,"props":11407,"children":11409},{"className":11408},[],[11410],{"type":27,"value":2633},{"type":27,"value":11412},"; Select the cloned root CA.   This parameter can be modified.",{"type":21,"tag":2200,"props":11414,"children":11415},{},[11416,11423],{"type":21,"tag":2228,"props":11417,"children":11418},{},[11419],{"type":21,"tag":42,"props":11420,"children":11421},{},[11422],{"type":27,"value":2646},{"type":21,"tag":2228,"props":11424,"children":11425},{},[11426,11427,11432],{"type":27,"value":1637},{"type":21,"tag":141,"props":11428,"children":11430},{"className":11429},[],[11431],{"type":27,"value":2655},{"type":27,"value":11433},"; The certificate validity period is 20 years.",{"type":21,"tag":2200,"props":11435,"children":11436},{},[11437,11444],{"type":21,"tag":2228,"props":11438,"children":11439},{},[11440],{"type":21,"tag":42,"props":11441,"children":11442},{},[11443],{"type":27,"value":2668},{"type":21,"tag":2228,"props":11445,"children":11446},{},[11447],{"type":27,"value":11234},{"type":21,"tag":2200,"props":11449,"children":11450},{},[11451,11458],{"type":21,"tag":2228,"props":11452,"children":11453},{},[11454],{"type":21,"tag":42,"props":11455,"children":11456},{},[11457],{"type":27,"value":2684},{"type":21,"tag":2228,"props":11459,"children":11460},{},[11461],{"type":27,"value":11462},"❌ (Optional) By default, this parameter is left blank.",{"type":21,"tag":2200,"props":11464,"children":11465},{},[11466,11473],{"type":21,"tag":2228,"props":11467,"children":11468},{},[11469],{"type":21,"tag":42,"props":11470,"children":11471},{},[11472],{"type":27,"value":2700},{"type":21,"tag":2228,"props":11474,"children":11475},{},[11476],{"type":27,"value":11477},"✅ Ensures international character support.",{"type":21,"tag":2200,"props":11479,"children":11480},{},[11481,11488],{"type":21,"tag":2228,"props":11482,"children":11483},{},[11484],{"type":21,"tag":42,"props":11485,"children":11486},{},[11487],{"type":27,"value":2716},{"type":21,"tag":2228,"props":11489,"children":11490},{},[11491],{"type":27,"value":11492},"❌ Do not select this parameter to avoid affecting internationalization.",{"type":21,"tag":2200,"props":11494,"children":11495},{},[11496,11503],{"type":21,"tag":2228,"props":11497,"children":11498},{},[11499],{"type":21,"tag":42,"props":11500,"children":11501},{},[11502],{"type":27,"value":2732},{"type":21,"tag":2228,"props":11504,"children":11505},{},[11506,11508,11513],{"type":27,"value":11507},"✅ Ensures that ",{"type":21,"tag":141,"props":11509,"children":11511},{"className":11510},[],[11512],{"type":27,"value":2468},{"type":27,"value":11514}," is sorted according to the LDAP specifications.",{"type":21,"tag":2200,"props":11516,"children":11517},{},[11518,11525],{"type":21,"tag":2228,"props":11519,"children":11520},{},[11521],{"type":21,"tag":42,"props":11522,"children":11523},{},[11524],{"type":27,"value":2754},{"type":21,"tag":2228,"props":11526,"children":11527},{},[11528,11529,11534],{"type":27,"value":1637},{"type":21,"tag":141,"props":11530,"children":11532},{"className":11531},[],[11533],{"type":27,"value":2763},{"type":27,"value":11535},"; 20-byte is recommended to ensure uniqueness.",{"type":21,"tag":2200,"props":11537,"children":11538},{},[11539,11546],{"type":21,"tag":2228,"props":11540,"children":11541},{},[11542],{"type":21,"tag":42,"props":11543,"children":11544},{},[11545],{"type":27,"value":2776},{"type":21,"tag":2228,"props":11547,"children":11548},{},[11549],{"type":27,"value":11550},"❌ Disabled for the root CA. Leave this parameter empty.",{"type":21,"tag":2200,"props":11552,"children":11553},{},[11554,11561],{"type":21,"tag":2228,"props":11555,"children":11556},{},[11557],{"type":21,"tag":42,"props":11558,"children":11559},{},[11560],{"type":27,"value":2792},{"type":21,"tag":2228,"props":11562,"children":11563},{},[11564],{"type":27,"value":11550},{"type":21,"tag":65,"props":11566,"children":11567},{},[],{"type":21,"tag":170,"props":11569,"children":11571},{"id":11570},"_4️⃣-crl-configuration",[11572],{"type":27,"value":11573},"4️⃣ CRL configuration",{"type":21,"tag":2192,"props":11575,"children":11576},{},[11577,11597],{"type":21,"tag":2196,"props":11578,"children":11579},{},[11580],{"type":21,"tag":2200,"props":11581,"children":11582},{},[11583,11590],{"type":21,"tag":2204,"props":11584,"children":11585},{},[11586],{"type":21,"tag":42,"props":11587,"children":11588},{},[11589],{"type":27,"value":11010},{"type":21,"tag":2204,"props":11591,"children":11592},{},[11593],{"type":21,"tag":42,"props":11594,"children":11595},{},[11596],{"type":27,"value":2374},{"type":21,"tag":2221,"props":11598,"children":11599},{},[11600,11615,11637,11658,11673,11688,11703,11718,11739,11766,11787,11808,11823,11838],{"type":21,"tag":2200,"props":11601,"children":11602},{},[11603,11610],{"type":21,"tag":2228,"props":11604,"children":11605},{},[11606],{"type":21,"tag":42,"props":11607,"children":11608},{},[11609],{"type":27,"value":2842},{"type":21,"tag":2228,"props":11611,"children":11612},{},[11613],{"type":27,"value":11614},"❌ Disabled for the root CA. This parameter is applicable only to Windows AD CS.",{"type":21,"tag":2200,"props":11616,"children":11617},{},[11618,11625],{"type":21,"tag":2228,"props":11619,"children":11620},{},[11621],{"type":21,"tag":42,"props":11622,"children":11623},{},[11624],{"type":27,"value":2858},{"type":21,"tag":2228,"props":11626,"children":11627},{},[11628,11630,11635],{"type":27,"value":11629},"✅ Enabled and marked as ",{"type":21,"tag":141,"props":11631,"children":11633},{"className":11632},[],[11634],{"type":27,"value":2869},{"type":27,"value":11636},". This parameter is used to identify the CRL issuer. It is recommended that it be enabled for the root CA and intermediate CA.",{"type":21,"tag":2200,"props":11638,"children":11639},{},[11640,11647],{"type":21,"tag":2228,"props":11641,"children":11642},{},[11643],{"type":21,"tag":42,"props":11644,"children":11645},{},[11646],{"type":27,"value":2882},{"type":21,"tag":2228,"props":11648,"children":11649},{},[11650,11651,11656],{"type":27,"value":11629},{"type":21,"tag":141,"props":11652,"children":11654},{"className":11653},[],[11655],{"type":27,"value":2869},{"type":27,"value":11657},". This parameter is used to ensure that the CRL version is unique. It is recommended that it be enabled for the root CA and intermediate CA.",{"type":21,"tag":2200,"props":11659,"children":11660},{},[11661,11668],{"type":21,"tag":2228,"props":11662,"children":11663},{},[11664],{"type":21,"tag":42,"props":11665,"children":11666},{},[11667],{"type":27,"value":2904},{"type":21,"tag":2228,"props":11669,"children":11670},{},[11671],{"type":27,"value":11672},"❌ Disabled for the root CA. This parameter is applicable only to large-scale CAs with hierarchical CRL structures.",{"type":21,"tag":2200,"props":11674,"children":11675},{},[11676,11683],{"type":21,"tag":2228,"props":11677,"children":11678},{},[11679],{"type":21,"tag":42,"props":11680,"children":11681},{},[11682],{"type":27,"value":2920},{"type":21,"tag":2228,"props":11684,"children":11685},{},[11686],{"type":27,"value":11687},"❌ Left empty. Users provide this URI during final certificate download stage.",{"type":21,"tag":2200,"props":11689,"children":11690},{},[11691,11698],{"type":21,"tag":2228,"props":11692,"children":11693},{},[11694],{"type":21,"tag":42,"props":11695,"children":11696},{},[11697],{"type":27,"value":2936},{"type":21,"tag":2228,"props":11699,"children":11700},{},[11701],{"type":27,"value":11702},"❌ Disabled for the root CA. Determine if this parameter should be enabled for the intermediate CA based on actual requirements. After this parameter is enabled, the certificate is still displayed in the CRL even if it expires.",{"type":21,"tag":2200,"props":11704,"children":11705},{},[11706,11713],{"type":21,"tag":2228,"props":11707,"children":11708},{},[11709],{"type":21,"tag":42,"props":11710,"children":11711},{},[11712],{"type":27,"value":2952},{"type":21,"tag":2228,"props":11714,"children":11715},{},[11716],{"type":27,"value":11717},"❌ Not required for the root CA due to its low load. This parameter is applicable to CA that manages a large number of certificates.",{"type":21,"tag":2200,"props":11719,"children":11720},{},[11721,11728],{"type":21,"tag":2228,"props":11722,"children":11723},{},[11724],{"type":21,"tag":42,"props":11725,"children":11726},{},[11727],{"type":27,"value":2968},{"type":21,"tag":2228,"props":11729,"children":11730},{},[11731,11732,11737],{"type":27,"value":1637},{"type":21,"tag":141,"props":11733,"children":11735},{"className":11734},[],[11736],{"type":27,"value":2977},{"type":27,"value":11738},". Set the period to a longer one for the root CA and to a shorter one for the intermediate CA.",{"type":21,"tag":2200,"props":11740,"children":11741},{},[11742,11749],{"type":21,"tag":2228,"props":11743,"children":11744},{},[11745],{"type":21,"tag":42,"props":11746,"children":11747},{},[11748],{"type":27,"value":2997},{"type":21,"tag":2228,"props":11750,"children":11751},{},[11752,11753,11758,11760,11765],{"type":27,"value":1637},{"type":21,"tag":141,"props":11754,"children":11756},{"className":11755},[],[11757],{"type":27,"value":3006},{"type":27,"value":11759},". Periodically updates the CRL. It is recommended that the active CA use ",{"type":21,"tag":141,"props":11761,"children":11763},{"className":11762},[],[11764],{"type":27,"value":3006},{"type":27,"value":9486},{"type":21,"tag":2200,"props":11767,"children":11768},{},[11769,11776],{"type":21,"tag":2228,"props":11770,"children":11771},{},[11772],{"type":21,"tag":42,"props":11773,"children":11774},{},[11775],{"type":27,"value":3025},{"type":21,"tag":2228,"props":11777,"children":11778},{},[11779,11780,11785],{"type":27,"value":1637},{"type":21,"tag":141,"props":11781,"children":11783},{"className":11782},[],[11784],{"type":27,"value":3034},{"type":27,"value":11786},". The old CRL and new CRL overlap for 12 hours to prevent certificate verification failures.",{"type":21,"tag":2200,"props":11788,"children":11789},{},[11790,11797],{"type":21,"tag":2228,"props":11791,"children":11792},{},[11793],{"type":21,"tag":42,"props":11794,"children":11795},{},[11796],{"type":27,"value":3047},{"type":21,"tag":2228,"props":11798,"children":11799},{},[11800,11801,11806],{"type":27,"value":11105},{"type":21,"tag":141,"props":11802,"children":11804},{"className":11803},[],[11805],{"type":27,"value":3056},{"type":27,"value":11807},". Delta CRL is not used for the root CA. It is enabled only for CAs that require high real-time performance.",{"type":21,"tag":2200,"props":11809,"children":11810},{},[11811,11818],{"type":21,"tag":2228,"props":11812,"children":11813},{},[11814],{"type":21,"tag":42,"props":11815,"children":11816},{},[11817],{"type":27,"value":3069},{"type":21,"tag":2228,"props":11819,"children":11820},{},[11821],{"type":27,"value":11822},"❌ Disabled for the root CA, and enabled for the intermediate CA as required. A new CRL is generated immediately after a certificate is revoked.",{"type":21,"tag":2200,"props":11824,"children":11825},{},[11826,11833],{"type":21,"tag":2228,"props":11827,"children":11828},{},[11829],{"type":21,"tag":42,"props":11830,"children":11831},{},[11832],{"type":27,"value":3085},{"type":21,"tag":2228,"props":11834,"children":11835},{},[11836],{"type":27,"value":11837},"✅ Enabled. This parameter allows to change the reason for certificate revocation. It is applicable to all CAs.",{"type":21,"tag":2200,"props":11839,"children":11840},{},[11841,11848],{"type":21,"tag":2228,"props":11842,"children":11843},{},[11844],{"type":21,"tag":42,"props":11845,"children":11846},{},[11847],{"type":27,"value":3101},{"type":21,"tag":2228,"props":11849,"children":11850},{},[11851],{"type":27,"value":11852},"✅ Enabled. This parameter allows to set the certificate invalidity date. It is applicable to all CAs.",{"type":21,"tag":65,"props":11854,"children":11855},{},[],{"type":21,"tag":170,"props":11857,"children":11859},{"id":11858},"_5️⃣-approval-settings",[11860],{"type":27,"value":11861},"5️⃣ Approval settings",{"type":21,"tag":2192,"props":11863,"children":11864},{},[11865,11885],{"type":21,"tag":2196,"props":11866,"children":11867},{},[11868],{"type":21,"tag":2200,"props":11869,"children":11870},{},[11871,11878],{"type":21,"tag":2204,"props":11872,"children":11873},{},[11874],{"type":21,"tag":42,"props":11875,"children":11876},{},[11877],{"type":27,"value":11010},{"type":21,"tag":2204,"props":11879,"children":11880},{},[11881],{"type":21,"tag":42,"props":11882,"children":11883},{},[11884],{"type":27,"value":2374},{"type":21,"tag":2221,"props":11886,"children":11887},{},[11888,11910,11931,11952],{"type":21,"tag":2200,"props":11889,"children":11890},{},[11891,11898],{"type":21,"tag":2228,"props":11892,"children":11893},{},[11894],{"type":21,"tag":42,"props":11895,"children":11896},{},[11897],{"type":27,"value":3152},{"type":21,"tag":2228,"props":11899,"children":11900},{},[11901,11903,11908],{"type":27,"value":11902},"❌",{"type":21,"tag":141,"props":11904,"children":11906},{"className":11905},[],[11907],{"type":27,"value":2317},{"type":27,"value":11909},". Root CA does not manage end entities.",{"type":21,"tag":2200,"props":11911,"children":11912},{},[11913,11920],{"type":21,"tag":2228,"props":11914,"children":11915},{},[11916],{"type":21,"tag":42,"props":11917,"children":11918},{},[11919],{"type":27,"value":3173},{"type":21,"tag":2228,"props":11921,"children":11922},{},[11923,11924,11929],{"type":27,"value":11902},{"type":21,"tag":141,"props":11925,"children":11927},{"className":11926},[],[11928],{"type":27,"value":2317},{"type":27,"value":11930},". Root CA does not provide key recovery.",{"type":21,"tag":2200,"props":11932,"children":11933},{},[11934,11941],{"type":21,"tag":2228,"props":11935,"children":11936},{},[11937],{"type":21,"tag":42,"props":11938,"children":11939},{},[11940],{"type":27,"value":3194},{"type":21,"tag":2228,"props":11942,"children":11943},{},[11944,11945,11950],{"type":27,"value":11902},{"type":21,"tag":141,"props":11946,"children":11948},{"className":11947},[],[11949],{"type":27,"value":2317},{"type":27,"value":11951},". Root CA rarely revokes its own certificates.",{"type":21,"tag":2200,"props":11953,"children":11954},{},[11955,11962],{"type":21,"tag":2228,"props":11956,"children":11957},{},[11958],{"type":21,"tag":42,"props":11959,"children":11960},{},[11961],{"type":27,"value":3215},{"type":21,"tag":2228,"props":11963,"children":11964},{},[11965,11966,11971],{"type":27,"value":11902},{"type":21,"tag":141,"props":11967,"children":11969},{"className":11968},[],[11970],{"type":27,"value":2317},{"type":27,"value":11972},". Root CA is manually activated.",{"type":21,"tag":65,"props":11974,"children":11975},{},[],{"type":21,"tag":170,"props":11977,"children":11979},{"id":11978},"_6️⃣-other-data",[11980],{"type":27,"value":11981},"6️⃣ Other data",{"type":21,"tag":2192,"props":11983,"children":11984},{},[11985,12005],{"type":21,"tag":2196,"props":11986,"children":11987},{},[11988],{"type":21,"tag":2200,"props":11989,"children":11990},{},[11991,11998],{"type":21,"tag":2204,"props":11992,"children":11993},{},[11994],{"type":21,"tag":42,"props":11995,"children":11996},{},[11997],{"type":27,"value":11010},{"type":21,"tag":2204,"props":11999,"children":12000},{},[12001],{"type":21,"tag":42,"props":12002,"children":12003},{},[12004],{"type":27,"value":2374},{"type":21,"tag":2221,"props":12006,"children":12007},{},[12008,12029,12044,12065],{"type":21,"tag":2200,"props":12009,"children":12010},{},[12011,12018],{"type":21,"tag":2228,"props":12012,"children":12013},{},[12014],{"type":21,"tag":42,"props":12015,"children":12016},{},[12017],{"type":27,"value":3271},{"type":21,"tag":2228,"props":12019,"children":12020},{},[12021,12022,12027],{"type":27,"value":1637},{"type":21,"tag":141,"props":12023,"children":12025},{"className":12024},[],[12026],{"type":27,"value":3280},{"type":27,"value":12028},". Enable the certificate verification policy.",{"type":21,"tag":2200,"props":12030,"children":12031},{},[12032,12039],{"type":21,"tag":2228,"props":12033,"children":12034},{},[12035],{"type":21,"tag":42,"props":12036,"children":12037},{},[12038],{"type":27,"value":3293},{"type":21,"tag":2228,"props":12040,"children":12041},{},[12042],{"type":27,"value":12043},"❌ Leave this parameter empty. This parameter needs to be configured only when the CMP protocol is used.",{"type":21,"tag":2200,"props":12045,"children":12046},{},[12047,12054],{"type":21,"tag":2228,"props":12048,"children":12049},{},[12050],{"type":21,"tag":42,"props":12051,"children":12052},{},[12053],{"type":27,"value":3309},{"type":21,"tag":2228,"props":12055,"children":12056},{},[12057,12058,12063],{"type":27,"value":1637},{"type":21,"tag":141,"props":12059,"children":12061},{"className":12060},[],[12062],{"type":27,"value":3318},{"type":27,"value":12064},". Enable CA running monitoring, which applies to all CAs.",{"type":21,"tag":2200,"props":12066,"children":12067},{},[12068,12075],{"type":21,"tag":2228,"props":12069,"children":12070},{},[12071],{"type":21,"tag":42,"props":12072,"children":12073},{},[12074],{"type":27,"value":3331},{"type":21,"tag":2228,"props":12076,"children":12077},{},[12078,12079,12084],{"type":27,"value":11105},{"type":21,"tag":141,"props":12080,"children":12082},{"className":12081},[],[12083],{"type":27,"value":2317},{"type":27,"value":12085},". Root CA usually does not need to process external requests.",{"type":21,"tag":65,"props":12087,"children":12088},{},[],{"type":21,"tag":170,"props":12090,"children":12092},{"id":12091},"_7️⃣-creationrenewal-of-externally-signed-cas",[12093],{"type":27,"value":12094},"7️⃣ Creation\u002FRenewal of Externally Signed CAs",{"type":21,"tag":2192,"props":12096,"children":12097},{},[12098,12118],{"type":21,"tag":2196,"props":12099,"children":12100},{},[12101],{"type":21,"tag":2200,"props":12102,"children":12103},{},[12104,12111],{"type":21,"tag":2204,"props":12105,"children":12106},{},[12107],{"type":21,"tag":42,"props":12108,"children":12109},{},[12110],{"type":27,"value":11010},{"type":21,"tag":2204,"props":12112,"children":12113},{},[12114],{"type":21,"tag":42,"props":12115,"children":12116},{},[12117],{"type":27,"value":2374},{"type":21,"tag":2221,"props":12119,"children":12120},{},[12121,12136],{"type":21,"tag":2200,"props":12122,"children":12123},{},[12124,12131],{"type":21,"tag":2228,"props":12125,"children":12126},{},[12127],{"type":21,"tag":42,"props":12128,"children":12129},{},[12130],{"type":27,"value":3387},{"type":21,"tag":2228,"props":12132,"children":12133},{},[12134],{"type":27,"value":12135},"❌ Creates a new root CA instead of regenerating the key and re-signing the existing CA. This avoids problems caused by root CA certificates with the same name.",{"type":21,"tag":2200,"props":12137,"children":12138},{},[12139,12146],{"type":21,"tag":2228,"props":12140,"children":12141},{},[12142],{"type":21,"tag":42,"props":12143,"children":12144},{},[12145],{"type":27,"value":3403},{"type":21,"tag":2228,"props":12147,"children":12148},{},[12149],{"type":27,"value":12150},"✅ Uploads the certificate chain file (in PEM\u002FDER format) only when the CA is signed externally. If the root CA has been installed locally, you do not need to upload the file.",{"type":21,"tag":65,"props":12152,"children":12153},{},[],{"type":21,"tag":170,"props":12155,"children":12157},{"id":12156},"_8️⃣-ca-creation",[12158],{"type":27,"value":12159},"8️⃣ CA Creation",{"type":21,"tag":36,"props":12161,"children":12162},{},[12163,12165,12169],{"type":27,"value":12164},"After confirming all parameters are correct, click ",{"type":21,"tag":42,"props":12166,"children":12167},{},[12168],{"type":27,"value":2151},{"type":27,"value":12170}," to generate a CA.",{"type":21,"tag":36,"props":12172,"children":12173},{},[12174],{"type":21,"tag":42,"props":12175,"children":12176},{},[12177],{"type":27,"value":12178},"1. Download and verify the root CA certificate.",{"type":21,"tag":36,"props":12180,"children":12181},{},[12182],{"type":27,"value":12183},"Run the following OpenSSL commands to verify the certificate format and validity:",{"type":21,"tag":182,"props":12185,"children":12187},{"code":12186,"language":3445,"meta":7,"className":3446,"style":7},"# Verify PEM certificates.\nopenssl x509 -in rootca.pem -text -noout\n\n# Verify DER certificates.\nopenssl x509 -in rootca.der -inform DER -text -noout\n\n# Check the certificate's SHA256 fingerprint information.\nopenssl x509 -noout -fingerprint -sha256 -in rootca.pem\n\n# Verify the self-signed certificate validity.\nopenssl verify -CAfile rootca.pem rootca.pem\n",[12188],{"type":21,"tag":141,"props":12189,"children":12190},{"__ignoreMap":7},[12191,12199,12226,12233,12241,12276,12283,12291,12322,12329,12337],{"type":21,"tag":192,"props":12192,"children":12193},{"class":194,"line":195},[12194],{"type":21,"tag":192,"props":12195,"children":12196},{"style":683},[12197],{"type":27,"value":12198},"# Verify PEM certificates.\n",{"type":21,"tag":192,"props":12200,"children":12201},{"class":194,"line":222},[12202,12206,12210,12214,12218,12222],{"type":21,"tag":192,"props":12203,"children":12204},{"style":199},[12205],{"type":27,"value":3466},{"type":21,"tag":192,"props":12207,"children":12208},{"style":205},[12209],{"type":27,"value":3471},{"type":21,"tag":192,"props":12211,"children":12212},{"style":211},[12213],{"type":27,"value":3476},{"type":21,"tag":192,"props":12215,"children":12216},{"style":205},[12217],{"type":27,"value":3481},{"type":21,"tag":192,"props":12219,"children":12220},{"style":211},[12221],{"type":27,"value":3486},{"type":21,"tag":192,"props":12223,"children":12224},{"style":211},[12225],{"type":27,"value":3491},{"type":21,"tag":192,"props":12227,"children":12228},{"class":194,"line":270},[12229],{"type":21,"tag":192,"props":12230,"children":12231},{"emptyLinePlaceholder":692},[12232],{"type":27,"value":695},{"type":21,"tag":192,"props":12234,"children":12235},{"class":194,"line":279},[12236],{"type":21,"tag":192,"props":12237,"children":12238},{"style":683},[12239],{"type":27,"value":12240},"# Verify DER certificates.\n",{"type":21,"tag":192,"props":12242,"children":12243},{"class":194,"line":728},[12244,12248,12252,12256,12260,12264,12268,12272],{"type":21,"tag":192,"props":12245,"children":12246},{"style":199},[12247],{"type":27,"value":3466},{"type":21,"tag":192,"props":12249,"children":12250},{"style":205},[12251],{"type":27,"value":3471},{"type":21,"tag":192,"props":12253,"children":12254},{"style":211},[12255],{"type":27,"value":3476},{"type":21,"tag":192,"props":12257,"children":12258},{"style":205},[12259],{"type":27,"value":3526},{"type":21,"tag":192,"props":12261,"children":12262},{"style":211},[12263],{"type":27,"value":3531},{"type":21,"tag":192,"props":12265,"children":12266},{"style":205},[12267],{"type":27,"value":3536},{"type":21,"tag":192,"props":12269,"children":12270},{"style":211},[12271],{"type":27,"value":3486},{"type":21,"tag":192,"props":12273,"children":12274},{"style":211},[12275],{"type":27,"value":3491},{"type":21,"tag":192,"props":12277,"children":12278},{"class":194,"line":751},[12279],{"type":21,"tag":192,"props":12280,"children":12281},{"emptyLinePlaceholder":692},[12282],{"type":27,"value":695},{"type":21,"tag":192,"props":12284,"children":12285},{"class":194,"line":774},[12286],{"type":21,"tag":192,"props":12287,"children":12288},{"style":683},[12289],{"type":27,"value":12290},"# Check the certificate's SHA256 fingerprint information.\n",{"type":21,"tag":192,"props":12292,"children":12293},{"class":194,"line":797},[12294,12298,12302,12306,12310,12314,12318],{"type":21,"tag":192,"props":12295,"children":12296},{"style":199},[12297],{"type":27,"value":3466},{"type":21,"tag":192,"props":12299,"children":12300},{"style":205},[12301],{"type":27,"value":3471},{"type":21,"tag":192,"props":12303,"children":12304},{"style":211},[12305],{"type":27,"value":3575},{"type":21,"tag":192,"props":12307,"children":12308},{"style":211},[12309],{"type":27,"value":3580},{"type":21,"tag":192,"props":12311,"children":12312},{"style":211},[12313],{"type":27,"value":3585},{"type":21,"tag":192,"props":12315,"children":12316},{"style":211},[12317],{"type":27,"value":3476},{"type":21,"tag":192,"props":12319,"children":12320},{"style":205},[12321],{"type":27,"value":3594},{"type":21,"tag":192,"props":12323,"children":12324},{"class":194,"line":805},[12325],{"type":21,"tag":192,"props":12326,"children":12327},{"emptyLinePlaceholder":692},[12328],{"type":27,"value":695},{"type":21,"tag":192,"props":12330,"children":12331},{"class":194,"line":823},[12332],{"type":21,"tag":192,"props":12333,"children":12334},{"style":683},[12335],{"type":27,"value":12336},"# Verify the self-signed certificate validity.\n",{"type":21,"tag":192,"props":12338,"children":12339},{"class":194,"line":842},[12340,12344,12348,12352,12356],{"type":21,"tag":192,"props":12341,"children":12342},{"style":199},[12343],{"type":27,"value":3466},{"type":21,"tag":192,"props":12345,"children":12346},{"style":205},[12347],{"type":27,"value":3621},{"type":21,"tag":192,"props":12349,"children":12350},{"style":211},[12351],{"type":27,"value":3626},{"type":21,"tag":192,"props":12353,"children":12354},{"style":205},[12355],{"type":27,"value":3481},{"type":21,"tag":192,"props":12357,"children":12358},{"style":205},[12359],{"type":27,"value":3594},{"type":21,"tag":36,"props":12361,"children":12362},{},[12363],{"type":21,"tag":42,"props":12364,"children":12365},{},[12366],{"type":27,"value":12367},"2. Deploy and verify the CRL.",{"type":21,"tag":36,"props":12369,"children":12370},{},[12371],{"type":27,"value":12372},"If the CRL URL is configured, run the following command:",{"type":21,"tag":182,"props":12374,"children":12376},{"code":12375,"language":3445,"meta":7,"className":3446,"style":7},"# Verify the CRL file.\nopenssl crl -in rootca.crl -text -noout\n",[12377],{"type":21,"tag":141,"props":12378,"children":12379},{"__ignoreMap":7},[12380,12388],{"type":21,"tag":192,"props":12381,"children":12382},{"class":194,"line":195},[12383],{"type":21,"tag":192,"props":12384,"children":12385},{"style":683},[12386],{"type":27,"value":12387},"# Verify the CRL file.\n",{"type":21,"tag":192,"props":12389,"children":12390},{"class":194,"line":222},[12391,12395,12399,12403,12407,12411],{"type":21,"tag":192,"props":12392,"children":12393},{"style":199},[12394],{"type":27,"value":3466},{"type":21,"tag":192,"props":12396,"children":12397},{"style":205},[12398],{"type":27,"value":3674},{"type":21,"tag":192,"props":12400,"children":12401},{"style":211},[12402],{"type":27,"value":3476},{"type":21,"tag":192,"props":12404,"children":12405},{"style":205},[12406],{"type":27,"value":3683},{"type":21,"tag":192,"props":12408,"children":12409},{"style":211},[12410],{"type":27,"value":3486},{"type":21,"tag":192,"props":12412,"children":12413},{"style":211},[12414],{"type":27,"value":3491},{"type":21,"tag":36,"props":12416,"children":12417},{},[12418],{"type":27,"value":12419},"Ensure that the CRL can be accessed through the web.",{"type":21,"tag":36,"props":12421,"children":12422},{},[12423,12424,12429],{"type":27,"value":3701},{"type":21,"tag":42,"props":12425,"children":12426},{},[12427],{"type":27,"value":12428},"The root CA has been created and can be used to issue intermediate CAs!",{"type":27,"value":3708},{"type":21,"tag":150,"props":12431,"children":12433},{"id":12432},"_57-creating-an-intermediate-ca-certificate",[12434],{"type":27,"value":12435},"5.7 Creating an Intermediate CA Certificate",{"type":21,"tag":170,"props":12437,"children":12439},{"id":12438},"_1️⃣-ca-type-and-key-configuration-1",[12440],{"type":27,"value":10993},{"type":21,"tag":2192,"props":12442,"children":12443},{},[12444,12458],{"type":21,"tag":2196,"props":12445,"children":12446},{},[12447],{"type":21,"tag":2200,"props":12448,"children":12449},{},[12450,12454],{"type":21,"tag":2204,"props":12451,"children":12452},{},[12453],{"type":27,"value":11010},{"type":21,"tag":2204,"props":12455,"children":12456},{},[12457],{"type":27,"value":2374},{"type":21,"tag":2221,"props":12459,"children":12460},{},[12461,12478,12496,12513,12530,12547,12565],{"type":21,"tag":2200,"props":12462,"children":12463},{},[12464,12468],{"type":21,"tag":2228,"props":12465,"children":12466},{},[12467],{"type":27,"value":2235},{"type":21,"tag":2228,"props":12469,"children":12470},{},[12471,12472,12477],{"type":27,"value":1637},{"type":21,"tag":141,"props":12473,"children":12475},{"className":12474},[],[12476],{"type":27,"value":2244},{"type":27,"value":11041},{"type":21,"tag":2200,"props":12479,"children":12480},{},[12481,12485],{"type":21,"tag":2228,"props":12482,"children":12483},{},[12484],{"type":27,"value":1994},{"type":21,"tag":2228,"props":12486,"children":12487},{},[12488,12490,12495],{"type":27,"value":12489},"✅ Select the created Crypto Token, for example, ",{"type":21,"tag":141,"props":12491,"children":12493},{"className":12492},[],[12494],{"type":27,"value":2274},{"type":27,"value":9486},{"type":21,"tag":2200,"props":12497,"children":12498},{},[12499,12503],{"type":21,"tag":2228,"props":12500,"children":12501},{},[12502],{"type":27,"value":2286},{"type":21,"tag":2228,"props":12504,"children":12505},{},[12506,12507,12512],{"type":27,"value":1637},{"type":21,"tag":141,"props":12508,"children":12510},{"className":12509},[],[12511],{"type":27,"value":2295},{"type":27,"value":11090},{"type":21,"tag":2200,"props":12514,"children":12515},{},[12516,12520],{"type":21,"tag":2228,"props":12517,"children":12518},{},[12519],{"type":27,"value":2308},{"type":21,"tag":2228,"props":12521,"children":12522},{},[12523,12524,12529],{"type":27,"value":11105},{"type":21,"tag":141,"props":12525,"children":12527},{"className":12526},[],[12528],{"type":27,"value":2317},{"type":27,"value":11112},{"type":21,"tag":2200,"props":12531,"children":12532},{},[12533,12537],{"type":21,"tag":2228,"props":12534,"children":12535},{},[12536],{"type":27,"value":2330},{"type":21,"tag":2228,"props":12538,"children":12539},{},[12540,12541,12546],{"type":27,"value":1637},{"type":21,"tag":141,"props":12542,"children":12544},{"className":12543},[],[12545],{"type":27,"value":2339},{"type":27,"value":11133},{"type":21,"tag":2200,"props":12548,"children":12549},{},[12550,12554],{"type":21,"tag":2228,"props":12551,"children":12552},{},[12553],{"type":27,"value":2352},{"type":21,"tag":2228,"props":12555,"children":12556},{},[12557,12558,12563],{"type":27,"value":1637},{"type":21,"tag":141,"props":12559,"children":12561},{"className":12560},[],[12562],{"type":27,"value":3842},{"type":27,"value":12564},"; Initial serial number, which should be different from that of the root CA.",{"type":21,"tag":2200,"props":12566,"children":12567},{},[12568,12572],{"type":21,"tag":2228,"props":12569,"children":12570},{},[12571],{"type":27,"value":2374},{"type":21,"tag":2228,"props":12573,"children":12574},{},[12575],{"type":27,"value":12576},"✅ Intermediate CA description, including the purpose and management unit.",{"type":21,"tag":65,"props":12578,"children":12579},{},[],{"type":21,"tag":170,"props":12581,"children":12583},{"id":12582},"_2️⃣-certificate-policies-directives-1",[12584],{"type":27,"value":11178},{"type":21,"tag":2192,"props":12586,"children":12587},{},[12588,12602],{"type":21,"tag":2196,"props":12589,"children":12590},{},[12591],{"type":21,"tag":2200,"props":12592,"children":12593},{},[12594,12598],{"type":21,"tag":2204,"props":12595,"children":12596},{},[12597],{"type":27,"value":11010},{"type":21,"tag":2204,"props":12599,"children":12600},{},[12601],{"type":27,"value":2374},{"type":21,"tag":2221,"props":12603,"children":12604},{},[12605,12616,12628,12640,12652,12664,12675],{"type":21,"tag":2200,"props":12606,"children":12607},{},[12608,12612],{"type":21,"tag":2228,"props":12609,"children":12610},{},[12611],{"type":27,"value":2425},{"type":21,"tag":2228,"props":12613,"children":12614},{},[12615],{"type":27,"value":11219},{"type":21,"tag":2200,"props":12617,"children":12618},{},[12619,12623],{"type":21,"tag":2228,"props":12620,"children":12621},{},[12622],{"type":27,"value":2441},{"type":21,"tag":2228,"props":12624,"children":12625},{},[12626],{"type":27,"value":12627},"✅ Recommended to be enabled for intermediate CAs to ensure security.",{"type":21,"tag":2200,"props":12629,"children":12630},{},[12631,12635],{"type":21,"tag":2228,"props":12632,"children":12633},{},[12634],{"type":27,"value":2457},{"type":21,"tag":2228,"props":12636,"children":12637},{},[12638],{"type":27,"value":12639},"✅ Ensures the DN to be unique.",{"type":21,"tag":2200,"props":12641,"children":12642},{},[12643,12647],{"type":21,"tag":2228,"props":12644,"children":12645},{},[12646],{"type":27,"value":2481},{"type":21,"tag":2228,"props":12648,"children":12649},{},[12650],{"type":27,"value":12651},"❌ Not required when the number of certificates is fewer than 20.",{"type":21,"tag":2200,"props":12653,"children":12654},{},[12655,12659],{"type":21,"tag":2228,"props":12656,"children":12657},{},[12658],{"type":27,"value":2497},{"type":21,"tag":2228,"props":12660,"children":12661},{},[12662],{"type":27,"value":12663},"✅ Records certificate request history.",{"type":21,"tag":2200,"props":12665,"children":12666},{},[12667,12671],{"type":21,"tag":2228,"props":12668,"children":12669},{},[12670],{"type":27,"value":2513},{"type":21,"tag":2228,"props":12672,"children":12673},{},[12674],{"type":27,"value":11301},{"type":21,"tag":2200,"props":12676,"children":12677},{},[12678,12682],{"type":21,"tag":2228,"props":12679,"children":12680},{},[12681],{"type":27,"value":2529},{"type":21,"tag":2228,"props":12683,"children":12684},{},[12685],{"type":27,"value":11316},{"type":21,"tag":65,"props":12687,"children":12688},{},[],{"type":21,"tag":170,"props":12690,"children":12692},{"id":12691},"_3️⃣-ca-certificate-data-1",[12693],{"type":27,"value":11325},{"type":21,"tag":2192,"props":12695,"children":12696},{},[12697,12712],{"type":21,"tag":2196,"props":12698,"children":12699},{},[12700],{"type":21,"tag":2200,"props":12701,"children":12702},{},[12703,12707],{"type":21,"tag":2204,"props":12704,"children":12705},{},[12706],{"type":27,"value":11010},{"type":21,"tag":2204,"props":12708,"children":12709},{},[12710],{"type":27,"value":12711},"Description\u002FExample Value",{"type":21,"tag":2221,"props":12713,"children":12714},{},[12715,12732,12750,12768,12786,12798,12810,12821,12832,12844,12862,12874],{"type":21,"tag":2200,"props":12716,"children":12717},{},[12718,12722],{"type":21,"tag":2228,"props":12719,"children":12720},{},[12721],{"type":27,"value":2580},{"type":21,"tag":2228,"props":12723,"children":12724},{},[12725,12726],{"type":27,"value":1637},{"type":21,"tag":141,"props":12727,"children":12729},{"className":12728},[],[12730],{"type":27,"value":12731},"CN=test Intermediate CA  ",{"type":21,"tag":2200,"props":12733,"children":12734},{},[12735,12739],{"type":21,"tag":2228,"props":12736,"children":12737},{},[12738],{"type":27,"value":2602},{"type":21,"tag":2228,"props":12740,"children":12741},{},[12742,12743,12748],{"type":27,"value":1637},{"type":21,"tag":141,"props":12744,"children":12746},{"className":12745},[],[12747],{"type":27,"value":4028},{"type":27,"value":12749}," The intermediate CA must be signed by the root CA.",{"type":21,"tag":2200,"props":12751,"children":12752},{},[12753,12757],{"type":21,"tag":2228,"props":12754,"children":12755},{},[12756],{"type":27,"value":2624},{"type":21,"tag":2228,"props":12758,"children":12759},{},[12760,12761,12766],{"type":27,"value":1637},{"type":21,"tag":141,"props":12762,"children":12764},{"className":12763},[],[12765],{"type":27,"value":4046},{"type":27,"value":12767}," Configured for the intermediate CA after cloning.",{"type":21,"tag":2200,"props":12769,"children":12770},{},[12771,12775],{"type":21,"tag":2228,"props":12772,"children":12773},{},[12774],{"type":27,"value":2646},{"type":21,"tag":2228,"props":12776,"children":12777},{},[12778,12779,12784],{"type":27,"value":1637},{"type":21,"tag":141,"props":12780,"children":12782},{"className":12781},[],[12783],{"type":27,"value":4064},{"type":27,"value":12785}," Generally, the validity period is 10 years, which is shorter than that of the root CA.",{"type":21,"tag":2200,"props":12787,"children":12788},{},[12789,12793],{"type":21,"tag":2228,"props":12790,"children":12791},{},[12792],{"type":27,"value":2668},{"type":21,"tag":2228,"props":12794,"children":12795},{},[12796],{"type":27,"value":12797},"❌ Not required for the intermediate CA.",{"type":21,"tag":2200,"props":12799,"children":12800},{},[12801,12805],{"type":21,"tag":2228,"props":12802,"children":12803},{},[12804],{"type":27,"value":2684},{"type":21,"tag":2228,"props":12806,"children":12807},{},[12808],{"type":27,"value":12809},"❌ Leave this parameter empty by default or enter a value as required.",{"type":21,"tag":2200,"props":12811,"children":12812},{},[12813,12817],{"type":21,"tag":2228,"props":12814,"children":12815},{},[12816],{"type":27,"value":2700},{"type":21,"tag":2228,"props":12818,"children":12819},{},[12820],{"type":27,"value":11477},{"type":21,"tag":2200,"props":12822,"children":12823},{},[12824,12828],{"type":21,"tag":2228,"props":12825,"children":12826},{},[12827],{"type":27,"value":2716},{"type":21,"tag":2228,"props":12829,"children":12830},{},[12831],{"type":27,"value":11492},{"type":21,"tag":2200,"props":12833,"children":12834},{},[12835,12839],{"type":21,"tag":2228,"props":12836,"children":12837},{},[12838],{"type":27,"value":2732},{"type":21,"tag":2228,"props":12840,"children":12841},{},[12842],{"type":27,"value":12843},"✅ Arranges the DN according to LDAP specifications.",{"type":21,"tag":2200,"props":12845,"children":12846},{},[12847,12851],{"type":21,"tag":2228,"props":12848,"children":12849},{},[12850],{"type":27,"value":2754},{"type":21,"tag":2228,"props":12852,"children":12853},{},[12854,12855,12860],{"type":27,"value":1637},{"type":21,"tag":141,"props":12856,"children":12858},{"className":12857},[],[12859],{"type":27,"value":2763},{"type":27,"value":12861}," 20-byte is recommended.",{"type":21,"tag":2200,"props":12863,"children":12864},{},[12865,12869],{"type":21,"tag":2228,"props":12866,"children":12867},{},[12868],{"type":27,"value":2776},{"type":21,"tag":2228,"props":12870,"children":12871},{},[12872],{"type":27,"value":12873},"❌ Disabled by default. Leave this parameter empty.",{"type":21,"tag":2200,"props":12875,"children":12876},{},[12877,12881],{"type":21,"tag":2228,"props":12878,"children":12879},{},[12880],{"type":27,"value":2792},{"type":21,"tag":2228,"props":12882,"children":12883},{},[12884],{"type":27,"value":12873},{"type":21,"tag":65,"props":12886,"children":12887},{},[],{"type":21,"tag":170,"props":12889,"children":12891},{"id":12890},"_4️⃣-crl-configuration-1",[12892],{"type":27,"value":11573},{"type":21,"tag":2192,"props":12894,"children":12895},{},[12896,12910],{"type":21,"tag":2196,"props":12897,"children":12898},{},[12899],{"type":21,"tag":2200,"props":12900,"children":12901},{},[12902,12906],{"type":21,"tag":2204,"props":12903,"children":12904},{},[12905],{"type":27,"value":11010},{"type":21,"tag":2204,"props":12907,"children":12908},{},[12909],{"type":27,"value":2374},{"type":21,"tag":2221,"props":12911,"children":12912},{},[12913,12925,12937,12948,12960,12972,12984,12996,13014,13032,13050,13068,13080,13092],{"type":21,"tag":2200,"props":12914,"children":12915},{},[12916,12920],{"type":21,"tag":2228,"props":12917,"children":12918},{},[12919],{"type":27,"value":2842},{"type":21,"tag":2228,"props":12921,"children":12922},{},[12923],{"type":27,"value":12924},"❌ Disabled, typically. This parameter is used only in the Windows AD environment.",{"type":21,"tag":2200,"props":12926,"children":12927},{},[12928,12932],{"type":21,"tag":2228,"props":12929,"children":12930},{},[12931],{"type":27,"value":2858},{"type":21,"tag":2228,"props":12933,"children":12934},{},[12935],{"type":27,"value":12936},"✅ Enabled and marked as Critical.",{"type":21,"tag":2200,"props":12938,"children":12939},{},[12940,12944],{"type":21,"tag":2228,"props":12941,"children":12942},{},[12943],{"type":27,"value":2882},{"type":21,"tag":2228,"props":12945,"children":12946},{},[12947],{"type":27,"value":12936},{"type":21,"tag":2200,"props":12949,"children":12950},{},[12951,12955],{"type":21,"tag":2228,"props":12952,"children":12953},{},[12954],{"type":27,"value":2904},{"type":21,"tag":2228,"props":12956,"children":12957},{},[12958],{"type":27,"value":12959},"❌ Disabled, typically.",{"type":21,"tag":2200,"props":12961,"children":12962},{},[12963,12967],{"type":21,"tag":2228,"props":12964,"children":12965},{},[12966],{"type":27,"value":2920},{"type":21,"tag":2228,"props":12968,"children":12969},{},[12970],{"type":27,"value":12971},"❌ Leave this parameter empty or enter a download address as required.",{"type":21,"tag":2200,"props":12973,"children":12974},{},[12975,12979],{"type":21,"tag":2228,"props":12976,"children":12977},{},[12978],{"type":27,"value":2936},{"type":21,"tag":2228,"props":12980,"children":12981},{},[12982],{"type":27,"value":12983},"❌ Recommended to be enabled for the intermediate CA and retain expired certificates. This parameter is disabled currently; otherwise, the CRL size will become large.",{"type":21,"tag":2200,"props":12985,"children":12986},{},[12987,12991],{"type":21,"tag":2228,"props":12988,"children":12989},{},[12990],{"type":27,"value":2952},{"type":21,"tag":2228,"props":12992,"children":12993},{},[12994],{"type":27,"value":12995},"❌ Not required, typically.",{"type":21,"tag":2200,"props":12997,"children":12998},{},[12999,13003],{"type":21,"tag":2228,"props":13000,"children":13001},{},[13002],{"type":27,"value":2968},{"type":21,"tag":2228,"props":13004,"children":13005},{},[13006,13007,13012],{"type":27,"value":1637},{"type":21,"tag":141,"props":13008,"children":13010},{"className":13009},[],[13011],{"type":27,"value":3006},{"type":27,"value":13013}," 7-day is recommended to ensure timely update.",{"type":21,"tag":2200,"props":13015,"children":13016},{},[13017,13021],{"type":21,"tag":2228,"props":13018,"children":13019},{},[13020],{"type":27,"value":2997},{"type":21,"tag":2228,"props":13022,"children":13023},{},[13024,13025,13030],{"type":27,"value":1637},{"type":21,"tag":141,"props":13026,"children":13028},{"className":13027},[],[13029],{"type":27,"value":4308},{"type":27,"value":13031}," The CRL is issued every day to ensure timely update.",{"type":21,"tag":2200,"props":13033,"children":13034},{},[13035,13039],{"type":21,"tag":2228,"props":13036,"children":13037},{},[13038],{"type":27,"value":3025},{"type":21,"tag":2228,"props":13040,"children":13041},{},[13042,13043,13048],{"type":27,"value":1637},{"type":21,"tag":141,"props":13044,"children":13046},{"className":13045},[],[13047],{"type":27,"value":3034},{"type":27,"value":13049}," The new CRL overlaps with the old CRL for 12 hours to ensure smooth transition.",{"type":21,"tag":2200,"props":13051,"children":13052},{},[13053,13057],{"type":21,"tag":2228,"props":13054,"children":13055},{},[13056],{"type":27,"value":3047},{"type":21,"tag":2228,"props":13058,"children":13059},{},[13060,13061,13066],{"type":27,"value":11105},{"type":21,"tag":141,"props":13062,"children":13064},{"className":13063},[],[13065],{"type":27,"value":3056},{"type":27,"value":13067}," Delta CRL is not used.",{"type":21,"tag":2200,"props":13069,"children":13070},{},[13071,13075],{"type":21,"tag":2228,"props":13072,"children":13073},{},[13074],{"type":27,"value":3069},{"type":21,"tag":2228,"props":13076,"children":13077},{},[13078],{"type":27,"value":13079},"✅ Enabled. The CRL is updated immediately after the certificate is revoked.",{"type":21,"tag":2200,"props":13081,"children":13082},{},[13083,13087],{"type":21,"tag":2228,"props":13084,"children":13085},{},[13086],{"type":27,"value":3085},{"type":21,"tag":2228,"props":13088,"children":13089},{},[13090],{"type":27,"value":13091},"✅ This parameter allows to change the reason for certificate revocation.",{"type":21,"tag":2200,"props":13093,"children":13094},{},[13095,13099],{"type":21,"tag":2228,"props":13096,"children":13097},{},[13098],{"type":27,"value":3101},{"type":21,"tag":2228,"props":13100,"children":13101},{},[13102],{"type":27,"value":13103},"✅ This parameter allows to set the certificate invalidity date.",{"type":21,"tag":65,"props":13105,"children":13106},{},[],{"type":21,"tag":170,"props":13108,"children":13110},{"id":13109},"_5️⃣-default-ca-defined-validation-data",[13111],{"type":27,"value":13112},"5️⃣ Default CA defined validation data",{"type":21,"tag":2192,"props":13114,"children":13115},{},[13116,13130],{"type":21,"tag":2196,"props":13117,"children":13118},{},[13119],{"type":21,"tag":2200,"props":13120,"children":13121},{},[13122,13126],{"type":21,"tag":2204,"props":13123,"children":13124},{},[13125],{"type":27,"value":11010},{"type":21,"tag":2204,"props":13127,"children":13128},{},[13129],{"type":27,"value":2374},{"type":21,"tag":2221,"props":13131,"children":13132},{},[13133,13145,13157,13168,13180],{"type":21,"tag":2200,"props":13134,"children":13135},{},[13136,13140],{"type":21,"tag":2228,"props":13137,"children":13138},{},[13139],{"type":27,"value":4417},{"type":21,"tag":2228,"props":13141,"children":13142},{},[13143],{"type":27,"value":13144},"❌ Leave this parameter empty or enter a value as required to distribute CRLs.",{"type":21,"tag":2200,"props":13146,"children":13147},{},[13148,13152],{"type":21,"tag":2228,"props":13149,"children":13150},{},[13151],{"type":27,"value":4430},{"type":21,"tag":2228,"props":13153,"children":13154},{},[13155],{"type":27,"value":13156},"❌ Leave this parameter empty. Typically, this parameter does not need to be set.",{"type":21,"tag":2200,"props":13158,"children":13159},{},[13160,13164],{"type":21,"tag":2228,"props":13161,"children":13162},{},[13163],{"type":27,"value":4443},{"type":21,"tag":2228,"props":13165,"children":13166},{},[13167],{"type":27,"value":13156},{"type":21,"tag":2200,"props":13169,"children":13170},{},[13171,13175],{"type":21,"tag":2228,"props":13172,"children":13173},{},[13174],{"type":27,"value":4455},{"type":21,"tag":2228,"props":13176,"children":13177},{},[13178],{"type":27,"value":13179},"❌ Leave this parameter empty or enter an OCSP address as required.",{"type":21,"tag":2200,"props":13181,"children":13182},{},[13183,13187],{"type":21,"tag":2228,"props":13184,"children":13185},{},[13186],{"type":27,"value":4468},{"type":21,"tag":2228,"props":13188,"children":13189},{},[13190],{"type":27,"value":13191},"❌ Leave this parameter empty or provide a URI later.",{"type":21,"tag":65,"props":13193,"children":13194},{},[],{"type":21,"tag":170,"props":13196,"children":13198},{"id":13197},"_6️⃣-approval-settings-and-other-data",[13199],{"type":27,"value":13200},"6️⃣ Approval settings and other data",{"type":21,"tag":36,"props":13202,"children":13203},{},[13204,13206,13211],{"type":27,"value":13205},"Currently, only ",{"type":21,"tag":141,"props":13207,"children":13209},{"className":13208},[],[13210],{"type":27,"value":2317},{"type":27,"value":13212}," is available for approval settings, indicating that no additional approval process is required. If it is required, check the global approval policy Supervision Functions of EJBCA.",{"type":21,"tag":2192,"props":13214,"children":13215},{},[13216,13230],{"type":21,"tag":2196,"props":13217,"children":13218},{},[13219],{"type":21,"tag":2200,"props":13220,"children":13221},{},[13222,13226],{"type":21,"tag":2204,"props":13223,"children":13224},{},[13225],{"type":27,"value":11010},{"type":21,"tag":2204,"props":13227,"children":13228},{},[13229],{"type":27,"value":2374},{"type":21,"tag":2221,"props":13231,"children":13232},{},[13233,13250,13261,13279],{"type":21,"tag":2200,"props":13234,"children":13235},{},[13236,13240],{"type":21,"tag":2228,"props":13237,"children":13238},{},[13239],{"type":27,"value":3271},{"type":21,"tag":2228,"props":13241,"children":13242},{},[13243,13244,13249],{"type":27,"value":1637},{"type":21,"tag":141,"props":13245,"children":13247},{"className":13246},[],[13248],{"type":27,"value":3280},{"type":27,"value":12028},{"type":21,"tag":2200,"props":13251,"children":13252},{},[13253,13257],{"type":21,"tag":2228,"props":13254,"children":13255},{},[13256],{"type":27,"value":3293},{"type":21,"tag":2228,"props":13258,"children":13259},{},[13260],{"type":27,"value":12043},{"type":21,"tag":2200,"props":13262,"children":13263},{},[13264,13268],{"type":21,"tag":2228,"props":13265,"children":13266},{},[13267],{"type":27,"value":3309},{"type":21,"tag":2228,"props":13269,"children":13270},{},[13271,13272,13277],{"type":27,"value":1637},{"type":21,"tag":141,"props":13273,"children":13275},{"className":13274},[],[13276],{"type":27,"value":3318},{"type":27,"value":13278},". Enable running monitoring.",{"type":21,"tag":2200,"props":13280,"children":13281},{},[13282,13286],{"type":21,"tag":2228,"props":13283,"children":13284},{},[13285],{"type":27,"value":3331},{"type":21,"tag":2228,"props":13287,"children":13288},{},[13289,13290,13295],{"type":27,"value":11105},{"type":21,"tag":141,"props":13291,"children":13293},{"className":13292},[],[13294],{"type":27,"value":2317},{"type":27,"value":13296},". Generally, external request processing is not required.",{"type":21,"tag":65,"props":13298,"children":13299},{},[],{"type":21,"tag":170,"props":13301,"children":13303},{"id":13302},"_7️⃣-intermediate-ca-creation",[13304],{"type":27,"value":13305},"7️⃣ Intermediate CA creation",{"type":21,"tag":36,"props":13307,"children":13308},{},[13309,13310,13314],{"type":27,"value":12164},{"type":21,"tag":42,"props":13311,"children":13312},{},[13313],{"type":27,"value":2151},{"type":27,"value":13315}," to generate a CSR.",{"type":21,"tag":36,"props":13317,"children":13318},{},[13319],{"type":27,"value":13320},"Submit the CSR to the root CA for signature, download the signed certificate, and verify it.",{"type":21,"tag":182,"props":13322,"children":13323},{"code":4604,"language":3445,"meta":7,"className":3446,"style":7},[13324],{"type":21,"tag":141,"props":13325,"children":13326},{"__ignoreMap":7},[13327,13354],{"type":21,"tag":192,"props":13328,"children":13329},{"class":194,"line":195},[13330,13334,13338,13342,13346,13350],{"type":21,"tag":192,"props":13331,"children":13332},{"style":199},[13333],{"type":27,"value":3466},{"type":21,"tag":192,"props":13335,"children":13336},{"style":205},[13337],{"type":27,"value":3471},{"type":21,"tag":192,"props":13339,"children":13340},{"style":211},[13341],{"type":27,"value":3476},{"type":21,"tag":192,"props":13343,"children":13344},{"style":205},[13345],{"type":27,"value":4628},{"type":21,"tag":192,"props":13347,"children":13348},{"style":211},[13349],{"type":27,"value":3486},{"type":21,"tag":192,"props":13351,"children":13352},{"style":211},[13353],{"type":27,"value":3491},{"type":21,"tag":192,"props":13355,"children":13356},{"class":194,"line":222},[13357,13361,13365,13369,13373],{"type":21,"tag":192,"props":13358,"children":13359},{"style":199},[13360],{"type":27,"value":3466},{"type":21,"tag":192,"props":13362,"children":13363},{"style":205},[13364],{"type":27,"value":3621},{"type":21,"tag":192,"props":13366,"children":13367},{"style":211},[13368],{"type":27,"value":3626},{"type":21,"tag":192,"props":13370,"children":13371},{"style":205},[13372],{"type":27,"value":3481},{"type":21,"tag":192,"props":13374,"children":13375},{"style":205},[13376],{"type":27,"value":4660},{"type":21,"tag":36,"props":13378,"children":13379},{},[13380],{"type":27,"value":13381},"🚀 The intermediate CA has been created and can be used to issue end entity certificates! 🎉",{"type":21,"tag":65,"props":13383,"children":13384},{},[],{"type":21,"tag":29,"props":13386,"children":13388},{"id":13387},"_6-ra-common-user-creation-and-permission-configuration",[13389],{"type":27,"value":13390},"6. RA Common User Creation and Permission Configuration",{"type":21,"tag":150,"props":13392,"children":13394},{"id":13393},"_61-creating-an-ra-role",[13395],{"type":27,"value":13396},"6.1 Creating an RA Role",{"type":21,"tag":546,"props":13398,"children":13399},{},[13400,13417,13470,13501,13535,13565],{"type":21,"tag":54,"props":13401,"children":13402},{},[13403,13408,13410],{"type":21,"tag":42,"props":13404,"children":13405},{},[13406],{"type":27,"value":13407},"Access the RA Web page",{"type":27,"value":13409}," and choose Role Management > Roles > Create New Role.",{"type":21,"tag":182,"props":13411,"children":13412},{"code":4696},[13413],{"type":21,"tag":141,"props":13414,"children":13415},{"__ignoreMap":7},[13416],{"type":27,"value":4696},{"type":21,"tag":54,"props":13418,"children":13419},{},[13420,13425,13426],{"type":21,"tag":42,"props":13421,"children":13422},{},[13423],{"type":27,"value":13424},"Enter role information.",{"type":27,"value":651},{"type":21,"tag":2192,"props":13427,"children":13428},{},[13429,13445],{"type":21,"tag":2196,"props":13430,"children":13431},{},[13432],{"type":21,"tag":2200,"props":13433,"children":13434},{},[13435,13440],{"type":21,"tag":2204,"props":13436,"children":13437},{},[13438],{"type":27,"value":13439},"Field",{"type":21,"tag":2204,"props":13441,"children":13442},{},[13443],{"type":27,"value":13444},"Recommended Value",{"type":21,"tag":2221,"props":13446,"children":13447},{},[13448,13459],{"type":21,"tag":2200,"props":13449,"children":13450},{},[13451,13455],{"type":21,"tag":2228,"props":13452,"children":13453},{},[13454],{"type":27,"value":4740},{"type":21,"tag":2228,"props":13456,"children":13457},{},[13458],{"type":27,"value":4745},{"type":21,"tag":2200,"props":13460,"children":13461},{},[13462,13466],{"type":21,"tag":2228,"props":13463,"children":13464},{},[13465],{"type":27,"value":4753},{"type":21,"tag":2228,"props":13467,"children":13468},{},[13469],{"type":27,"value":4758},{"type":21,"tag":54,"props":13471,"children":13472},{},[13473,13478,13479],{"type":21,"tag":42,"props":13474,"children":13475},{},[13476],{"type":27,"value":13477},"Set the permissions for Certificate Authorities.",{"type":27,"value":651},{"type":21,"tag":50,"props":13480,"children":13481},{},[13482],{"type":21,"tag":54,"props":13483,"children":13484},{},[13485,13487,13493,13495,13500],{"type":27,"value":13486},"Select a CA, for example, ",{"type":21,"tag":141,"props":13488,"children":13490},{"className":13489},[],[13491],{"type":27,"value":13492},"Intermediate CA",{"type":27,"value":13494}," or Root CA, from the Available list and click ",{"type":21,"tag":141,"props":13496,"children":13498},{"className":13497},[],[13499],{"type":27,"value":1831},{"type":27,"value":9486},{"type":21,"tag":54,"props":13502,"children":13503},{},[13504,13509,13511],{"type":21,"tag":42,"props":13505,"children":13506},{},[13507],{"type":27,"value":13508},"Set the permissions for End Entity.",{"type":27,"value":13510},"(Recommended):",{"type":21,"tag":50,"props":13512,"children":13513},{},[13514,13518,13523,13527,13531],{"type":21,"tag":54,"props":13515,"children":13516},{},[13517],{"type":27,"value":4815},{"type":21,"tag":54,"props":13519,"children":13520},{},[13521],{"type":27,"value":13522},"✅ Create certificates",{"type":21,"tag":54,"props":13524,"children":13525},{},[13526],{"type":27,"value":4828},{"type":21,"tag":54,"props":13528,"children":13529},{},[13530],{"type":27,"value":4833},{"type":21,"tag":54,"props":13532,"children":13533},{},[13534],{"type":27,"value":4838},{"type":21,"tag":54,"props":13536,"children":13537},{},[13538,13543,13544],{"type":21,"tag":42,"props":13539,"children":13540},{},[13541],{"type":27,"value":13542},"Set the permissions for End Entity Profiles.",{"type":27,"value":651},{"type":21,"tag":50,"props":13545,"children":13546},{},[13547],{"type":21,"tag":54,"props":13548,"children":13549},{},[13550,13552,13557,13559,13564],{"type":27,"value":13551},"Select ",{"type":21,"tag":141,"props":13553,"children":13555},{"className":13554},[],[13556],{"type":27,"value":4861},{"type":27,"value":13558}," from the Available list and click ",{"type":21,"tag":141,"props":13560,"children":13562},{"className":13561},[],[13563],{"type":27,"value":1831},{"type":27,"value":9486},{"type":21,"tag":54,"props":13566,"children":13567},{},[13568,13569,13574],{"type":27,"value":10637},{"type":21,"tag":141,"props":13570,"children":13572},{"className":13571},[],[13573],{"type":27,"value":1831},{"type":27,"value":13575}," to save the created role.",{"type":21,"tag":150,"props":13577,"children":13579},{"id":13578},"_62-creating-an-ra-commer-user-end-entity",[13580],{"type":27,"value":13581},"6.2 Creating an RA Commer User (End Entity)",{"type":21,"tag":546,"props":13583,"children":13584},{},[13585,13603,13764],{"type":21,"tag":54,"props":13586,"children":13587},{},[13588,13590,13595,13597,13602],{"type":27,"value":13589},"Access the ",{"type":21,"tag":42,"props":13591,"children":13592},{},[13593],{"type":27,"value":13594},"EJBCA Admin Web",{"type":27,"value":13596}," page and choose ",{"type":21,"tag":42,"props":13598,"children":13599},{},[13600],{"type":27,"value":13601},"RA Functions > Add End Entity",{"type":27,"value":9486},{"type":21,"tag":54,"props":13604,"children":13605},{},[13606,13608],{"type":27,"value":13607},"Enter the user details.",{"type":21,"tag":2192,"props":13609,"children":13610},{},[13611,13625],{"type":21,"tag":2196,"props":13612,"children":13613},{},[13614],{"type":21,"tag":2200,"props":13615,"children":13616},{},[13617,13621],{"type":21,"tag":2204,"props":13618,"children":13619},{},[13620],{"type":27,"value":13439},{"type":21,"tag":2204,"props":13622,"children":13623},{},[13624],{"type":27,"value":13444},{"type":21,"tag":2221,"props":13626,"children":13627},{},[13628,13639,13650,13661,13672,13684,13698,13709,13720,13731,13742,13753],{"type":21,"tag":2200,"props":13629,"children":13630},{},[13631,13635],{"type":21,"tag":2228,"props":13632,"children":13633},{},[13634],{"type":27,"value":4941},{"type":21,"tag":2228,"props":13636,"children":13637},{},[13638],{"type":27,"value":4861},{"type":21,"tag":2200,"props":13640,"children":13641},{},[13642,13646],{"type":21,"tag":2228,"props":13643,"children":13644},{},[13645],{"type":27,"value":4953},{"type":21,"tag":2228,"props":13647,"children":13648},{},[13649],{"type":27,"value":4958},{"type":21,"tag":2200,"props":13651,"children":13652},{},[13653,13657],{"type":21,"tag":2228,"props":13654,"children":13655},{},[13656],{"type":27,"value":4966},{"type":21,"tag":2228,"props":13658,"children":13659},{},[13660],{"type":27,"value":4971},{"type":21,"tag":2200,"props":13662,"children":13663},{},[13664,13668],{"type":21,"tag":2228,"props":13665,"children":13666},{},[13667],{"type":27,"value":4979},{"type":21,"tag":2228,"props":13669,"children":13670},{},[13671],{"type":27,"value":4971},{"type":21,"tag":2200,"props":13673,"children":13674},{},[13675,13679],{"type":21,"tag":2228,"props":13676,"children":13677},{},[13678],{"type":27,"value":4991},{"type":21,"tag":2228,"props":13680,"children":13681},{},[13682],{"type":27,"value":13683},"Not selected",{"type":21,"tag":2200,"props":13685,"children":13686},{},[13687,13691],{"type":21,"tag":2228,"props":13688,"children":13689},{},[13690],{"type":27,"value":5004},{"type":21,"tag":2228,"props":13692,"children":13693},{},[13694],{"type":21,"tag":5009,"props":13695,"children":13696},{"href":5011},[13697],{"type":27,"value":5014},{"type":21,"tag":2200,"props":13699,"children":13700},{},[13701,13705],{"type":21,"tag":2228,"props":13702,"children":13703},{},[13704],{"type":27,"value":5022},{"type":21,"tag":2228,"props":13706,"children":13707},{},[13708],{"type":27,"value":5027},{"type":21,"tag":2200,"props":13710,"children":13711},{},[13712,13716],{"type":21,"tag":2228,"props":13713,"children":13714},{},[13715],{"type":27,"value":5035},{"type":21,"tag":2228,"props":13717,"children":13718},{},[13719],{"type":27,"value":5040},{"type":21,"tag":2200,"props":13721,"children":13722},{},[13723,13727],{"type":21,"tag":2228,"props":13724,"children":13725},{},[13726],{"type":27,"value":5048},{"type":21,"tag":2228,"props":13728,"children":13729},{},[13730],{"type":27,"value":5022},{"type":21,"tag":2200,"props":13732,"children":13733},{},[13734,13738],{"type":21,"tag":2228,"props":13735,"children":13736},{},[13737],{"type":27,"value":2624},{"type":21,"tag":2228,"props":13739,"children":13740},{},[13741],{"type":27,"value":1799},{"type":21,"tag":2200,"props":13743,"children":13744},{},[13745,13749],{"type":21,"tag":2228,"props":13746,"children":13747},{},[13748],{"type":27,"value":5071},{"type":21,"tag":2228,"props":13750,"children":13751},{},[13752],{"type":27,"value":5076},{"type":21,"tag":2200,"props":13754,"children":13755},{},[13756,13760],{"type":21,"tag":2228,"props":13757,"children":13758},{},[13759],{"type":27,"value":5084},{"type":21,"tag":2228,"props":13761,"children":13762},{},[13763],{"type":27,"value":5089},{"type":21,"tag":54,"props":13765,"children":13766},{},[13767,13768,13772],{"type":27,"value":10637},{"type":21,"tag":42,"props":13769,"children":13770},{},[13771],{"type":27,"value":1831},{"type":27,"value":9486},{"type":21,"tag":36,"props":13774,"children":13775},{},[13776],{"type":27,"value":13777},"End Entity is created.",{"type":21,"tag":150,"props":13779,"children":13781},{"id":13780},"_63-downloading-the-user-certificate",[13782],{"type":27,"value":13783},"6.3 Downloading the User Certificate",{"type":21,"tag":546,"props":13785,"children":13786},{},[13787,13803,13829],{"type":21,"tag":54,"props":13788,"children":13789},{},[13790,13791,13796,13797,13802],{"type":27,"value":13589},{"type":21,"tag":42,"props":13792,"children":13793},{},[13794],{"type":27,"value":13795},"RA Web",{"type":27,"value":13596},{"type":21,"tag":42,"props":13798,"children":13799},{},[13800],{"type":27,"value":13801},"Enroll > Use Username",{"type":27,"value":9486},{"type":21,"tag":54,"props":13804,"children":13805},{},[13806,13808],{"type":27,"value":13807},"Use the created username and password to log in.",{"type":21,"tag":50,"props":13809,"children":13810},{},[13811,13820],{"type":21,"tag":54,"props":13812,"children":13813},{},[13814,13815],{"type":27,"value":5141},{"type":21,"tag":141,"props":13816,"children":13818},{"className":13817},[],[13819],{"type":27,"value":4958},{"type":21,"tag":54,"props":13821,"children":13822},{},[13823,13824],{"type":27,"value":5151},{"type":21,"tag":141,"props":13825,"children":13827},{"className":13826},[],[13828],{"type":27,"value":4971},{"type":21,"tag":54,"props":13830,"children":13831},{},[13832,13834],{"type":27,"value":13833},"Select a key algorithm after logging in.",{"type":21,"tag":50,"props":13835,"children":13836},{},[13837],{"type":21,"tag":54,"props":13838,"children":13839},{},[13840,13842,13847,13849,13854],{"type":27,"value":13841},"Select the ",{"type":21,"tag":141,"props":13843,"children":13845},{"className":13844},[],[13846],{"type":27,"value":1682},{"type":27,"value":13848}," algorithm, and generate and download the ",{"type":21,"tag":141,"props":13850,"children":13852},{"className":13851},[],[13853],{"type":27,"value":1198},{"type":27,"value":13855}," user certificate.",{"type":21,"tag":150,"props":13857,"children":13859},{"id":13858},"_64-adding-a-user-to-the-ra-role",[13860],{"type":27,"value":13861},"6.4 Adding a User to the RA Role",{"type":21,"tag":546,"props":13863,"children":13864},{},[13865,13880,13885,13900,13993,14003,14013],{"type":21,"tag":54,"props":13866,"children":13867},{},[13868,13869,13873,13874,13879],{"type":27,"value":13589},{"type":21,"tag":42,"props":13870,"children":13871},{},[13872],{"type":27,"value":13795},{"type":27,"value":13596},{"type":21,"tag":42,"props":13875,"children":13876},{},[13877],{"type":27,"value":13878},"Search > End Entities",{"type":27,"value":9486},{"type":21,"tag":54,"props":13881,"children":13882},{},[13883],{"type":27,"value":13884},"Copy the CN of the certificate created earlier.",{"type":21,"tag":54,"props":13886,"children":13887},{},[13888,13889,13893,13894,13899],{"type":27,"value":13589},{"type":21,"tag":42,"props":13890,"children":13891},{},[13892],{"type":27,"value":13795},{"type":27,"value":13596},{"type":21,"tag":42,"props":13895,"children":13896},{},[13897],{"type":27,"value":13898},"Role Management > Roles > Members > Add Role Member",{"type":27,"value":9486},{"type":21,"tag":54,"props":13901,"children":13902},{},[13903,13905],{"type":27,"value":13904},"Enter the information about the role member.",{"type":21,"tag":2192,"props":13906,"children":13907},{},[13908,13922],{"type":21,"tag":2196,"props":13909,"children":13910},{},[13911],{"type":21,"tag":2200,"props":13912,"children":13913},{},[13914,13918],{"type":21,"tag":2204,"props":13915,"children":13916},{},[13917],{"type":27,"value":13439},{"type":21,"tag":2204,"props":13919,"children":13920},{},[13921],{"type":27,"value":13444},{"type":21,"tag":2221,"props":13923,"children":13924},{},[13925,13936,13947,13958,13969,13981],{"type":21,"tag":2200,"props":13926,"children":13927},{},[13928,13932],{"type":21,"tag":2228,"props":13929,"children":13930},{},[13931],{"type":27,"value":5256},{"type":21,"tag":2228,"props":13933,"children":13934},{},[13935],{"type":27,"value":4758},{"type":21,"tag":2200,"props":13937,"children":13938},{},[13939,13943],{"type":21,"tag":2228,"props":13940,"children":13941},{},[13942],{"type":27,"value":5268},{"type":21,"tag":2228,"props":13944,"children":13945},{},[13946],{"type":27,"value":5273},{"type":21,"tag":2200,"props":13948,"children":13949},{},[13950,13954],{"type":21,"tag":2228,"props":13951,"children":13952},{},[13953],{"type":27,"value":5071},{"type":21,"tag":2228,"props":13955,"children":13956},{},[13957],{"type":27,"value":5076},{"type":21,"tag":2200,"props":13959,"children":13960},{},[13961,13965],{"type":21,"tag":2228,"props":13962,"children":13963},{},[13964],{"type":27,"value":5292},{"type":21,"tag":2228,"props":13966,"children":13967},{},[13968],{"type":27,"value":5297},{"type":21,"tag":2200,"props":13970,"children":13971},{},[13972,13976],{"type":21,"tag":2228,"props":13973,"children":13974},{},[13975],{"type":27,"value":5305},{"type":21,"tag":2228,"props":13977,"children":13978},{},[13979],{"type":27,"value":13980},"Paste the copied certificate CN.",{"type":21,"tag":2200,"props":13982,"children":13983},{},[13984,13988],{"type":21,"tag":2228,"props":13985,"children":13986},{},[13987],{"type":27,"value":2374},{"type":21,"tag":2228,"props":13989,"children":13990},{},[13991],{"type":27,"value":13992},"RA common user",{"type":21,"tag":54,"props":13994,"children":13995},{},[13996,13997,14001],{"type":27,"value":10637},{"type":21,"tag":42,"props":13998,"children":13999},{},[14000],{"type":27,"value":1831},{"type":27,"value":14002}," to add the role member.",{"type":21,"tag":54,"props":14004,"children":14005},{},[14006,14011],{"type":21,"tag":42,"props":14007,"children":14008},{},[14009],{"type":27,"value":14010},"Restart the EJBCA service",{"type":27,"value":14012}," for the permission to take effect (recommended).",{"type":21,"tag":54,"props":14014,"children":14015},{},[14016],{"type":27,"value":14017},"docker restart ejbca",{"type":21,"tag":150,"props":14019,"children":14021},{"id":14020},"_65-logging-in-to-the-ra-webui",[14022],{"type":27,"value":14023},"6.5 Logging In to the RA WebUI",{"type":21,"tag":546,"props":14025,"children":14026},{},[14027,14037,14042],{"type":21,"tag":54,"props":14028,"children":14029},{},[14030,14035],{"type":21,"tag":42,"props":14031,"children":14032},{},[14033],{"type":27,"value":14034},"Non-administrator",{"type":27,"value":14036}," roles import the downloaded · certificate to the browser.",{"type":21,"tag":54,"props":14038,"children":14039},{},[14040],{"type":27,"value":14041},"Access the RA Web page for automatic authentication and login.",{"type":21,"tag":54,"props":14043,"children":14044},{},[14045],{"type":27,"value":14046},"Perform authorized RA operations, such as creating and viewing certificates.",{"type":21,"tag":150,"props":14048,"children":14050},{"id":14049},"_66-important-notes-must-be-followed",[14051],{"type":27,"value":14052},"6.6 Important Notes (Must Be Followed)",{"type":21,"tag":36,"props":14054,"children":14055},{},[14056],{"type":27,"value":14057},"✅ You are advised to use the Chrome browser in incognito mode for the first login to quickly start the verification and avoid the error \"No OAuth providers configured. Please log in using a valid certificate\" caused by cache problems.",{"type":21,"tag":36,"props":14059,"children":14060},{},[14061,14062,14067,14069,14074],{"type":27,"value":1637},{"type":21,"tag":42,"props":14063,"children":14064},{},[14065],{"type":27,"value":14066},"Use HTTPS",{"type":27,"value":14068}," to access, for example, ",{"type":21,"tag":5009,"props":14070,"children":14072},{"href":5442,"rel":14071},[10481],[14073],{"type":27,"value":5442},{"type":27,"value":14075},", to avoid the error \"No OAuth providers configured. Please log in using a valid certificate.\"",{"type":21,"tag":65,"props":14077,"children":14078},{},[],{"type":21,"tag":29,"props":14080,"children":14082},{"id":14081},"_7-certificate-profile-settings",[14083],{"type":27,"value":14084},"7. Certificate Profile Settings",{"type":21,"tag":36,"props":14086,"children":14087},{},[14088],{"type":27,"value":14089},"This section describes the meanings and recommended usage of the Certificate Profile configuration items in the EJBCA. It is applicable to certificate issuance requirements for common devices such as HTTPS, web, device, and client.",{"type":21,"tag":65,"props":14091,"children":14092},{},[],{"type":21,"tag":150,"props":14094,"children":14096},{"id":14095},"_71-basic-information",[14097],{"type":27,"value":14098},"7.1 Basic Information",{"type":21,"tag":2192,"props":14100,"children":14101},{},[14102,14117],{"type":21,"tag":2196,"props":14103,"children":14104},{},[14105],{"type":21,"tag":2200,"props":14106,"children":14107},{},[14108,14113],{"type":21,"tag":2204,"props":14109,"children":14110},{},[14111],{"type":27,"value":14112},"Configuration Item",{"type":21,"tag":2204,"props":14114,"children":14115},{},[14116],{"type":27,"value":2374},{"type":21,"tag":2221,"props":14118,"children":14119},{},[14120,14135,14150,14165,14180,14196,14212,14227,14243,14258,14273],{"type":21,"tag":2200,"props":14121,"children":14122},{},[14123,14130],{"type":21,"tag":2228,"props":14124,"children":14125},{},[14126],{"type":21,"tag":42,"props":14127,"children":14128},{},[14129],{"type":27,"value":5506},{"type":21,"tag":2228,"props":14131,"children":14132},{},[14133],{"type":27,"value":14134},"Unique identifier of the profile in the database, which is used only for internal identification.",{"type":21,"tag":2200,"props":14136,"children":14137},{},[14138,14145],{"type":21,"tag":2228,"props":14139,"children":14140},{},[14141],{"type":21,"tag":42,"props":14142,"children":14143},{},[14144],{"type":27,"value":1909},{"type":21,"tag":2228,"props":14146,"children":14147},{},[14148],{"type":27,"value":14149},"Available end entity, subordinate CA, and root CA.",{"type":21,"tag":2200,"props":14151,"children":14152},{},[14153,14160],{"type":21,"tag":2228,"props":14154,"children":14155},{},[14156],{"type":21,"tag":42,"props":14157,"children":14158},{},[14159],{"type":27,"value":5538},{"type":21,"tag":2228,"props":14161,"children":14162},{},[14163],{"type":27,"value":14164},"Available key algorithms, such as RSA, ECDSA, Ed25519, and DILITHIUM.",{"type":21,"tag":2200,"props":14166,"children":14167},{},[14168,14175],{"type":21,"tag":2228,"props":14169,"children":14170},{},[14171],{"type":21,"tag":42,"props":14172,"children":14173},{},[14174],{"type":27,"value":5554},{"type":21,"tag":2228,"props":14176,"children":14177},{},[14178],{"type":27,"value":14179},"Available ECDSA curves. No curve is enabled currently.",{"type":21,"tag":2200,"props":14181,"children":14182},{},[14183,14191],{"type":21,"tag":2228,"props":14184,"children":14185},{},[14186],{"type":21,"tag":42,"props":14187,"children":14188},{},[14189],{"type":27,"value":14190},"Available bit length",{"type":21,"tag":2228,"props":14192,"children":14193},{},[14194],{"type":27,"value":14195},"Key size supported (for RSA), such as 2048 and 4096.",{"type":21,"tag":2200,"props":14197,"children":14198},{},[14199,14207],{"type":21,"tag":2228,"props":14200,"children":14201},{},[14202],{"type":21,"tag":42,"props":14203,"children":14204},{},[14205],{"type":27,"value":14206},"Signature algorithm",{"type":21,"tag":2228,"props":14208,"children":14209},{},[14210],{"type":27,"value":14211},"Signature hash algorithm used for certificate issuance, for example, SHA3-256withRSA.",{"type":21,"tag":2200,"props":14213,"children":14214},{},[14215,14222],{"type":21,"tag":2228,"props":14216,"children":14217},{},[14218],{"type":21,"tag":42,"props":14219,"children":14220},{},[14221],{"type":27,"value":5602},{"type":21,"tag":2228,"props":14223,"children":14224},{},[14225],{"type":27,"value":14226},"Whether to enable the alternative signature algorithm, such as ECDSA and EdDSA.",{"type":21,"tag":2200,"props":14228,"children":14229},{},[14230,14238],{"type":21,"tag":2228,"props":14231,"children":14232},{},[14233],{"type":21,"tag":42,"props":14234,"children":14235},{},[14236],{"type":27,"value":14237},"End date or end date of the certificate",{"type":21,"tag":2228,"props":14239,"children":14240},{},[14241],{"type":27,"value":14242},"Default validity period. For example, \"2y\" indicates two years.",{"type":21,"tag":2200,"props":14244,"children":14245},{},[14246,14253],{"type":21,"tag":2228,"props":14247,"children":14248},{},[14249],{"type":21,"tag":42,"props":14250,"children":14251},{},[14252],{"type":27,"value":5634},{"type":21,"tag":2228,"props":14254,"children":14255},{},[14256],{"type":27,"value":14257},"Offset of the issue date. The start time can be set forward or backward.",{"type":21,"tag":2200,"props":14259,"children":14260},{},[14261,14268],{"type":21,"tag":2228,"props":14262,"children":14263},{},[14264],{"type":21,"tag":42,"props":14265,"children":14266},{},[14267],{"type":27,"value":5650},{"type":21,"tag":2228,"props":14269,"children":14270},{},[14271],{"type":27,"value":14272},"Maximum expiration time, which is used for compliance control.",{"type":21,"tag":2200,"props":14274,"children":14275},{},[14276,14283],{"type":21,"tag":2228,"props":14277,"children":14278},{},[14279],{"type":21,"tag":42,"props":14280,"children":14281},{},[14282],{"type":27,"value":5666},{"type":21,"tag":2228,"props":14284,"children":14285},{},[14286],{"type":27,"value":14287},"Certificate profile description, which is used to note the purpose (for example, \"terminal device certificate\").",{"type":21,"tag":65,"props":14289,"children":14290},{},[],{"type":21,"tag":150,"props":14292,"children":14294},{"id":14293},"_72-permissions-control",[14295],{"type":27,"value":14296},"7.2 Permissions Control",{"type":21,"tag":2192,"props":14298,"children":14299},{},[14300,14319],{"type":21,"tag":2196,"props":14301,"children":14302},{},[14303],{"type":21,"tag":2200,"props":14304,"children":14305},{},[14306,14310,14314],{"type":21,"tag":2204,"props":14307,"children":14308},{},[14309],{"type":27,"value":14112},{"type":21,"tag":2204,"props":14311,"children":14312},{},[14313],{"type":27,"value":2374},{"type":21,"tag":2204,"props":14315,"children":14316},{},[14317],{"type":27,"value":14318},"Recommended Setting",{"type":21,"tag":2221,"props":14320,"children":14321},{},[14322,14339,14356,14373,14390,14407,14424,14441,14458,14474],{"type":21,"tag":2200,"props":14323,"children":14324},{},[14325,14329,14334],{"type":21,"tag":2228,"props":14326,"children":14327},{},[14328],{"type":27,"value":5713},{"type":21,"tag":2228,"props":14330,"children":14331},{},[14332],{"type":27,"value":14333},"Allow the default validity period to be overwritten when a certificate is issued.",{"type":21,"tag":2228,"props":14335,"children":14336},{},[14337],{"type":27,"value":14338},"✅ which is used when the validity period needs to be manually adjusted.",{"type":21,"tag":2200,"props":14340,"children":14341},{},[14342,14346,14351],{"type":21,"tag":2228,"props":14343,"children":14344},{},[14345],{"type":27,"value":5731},{"type":21,"tag":2228,"props":14347,"children":14348},{},[14349],{"type":27,"value":14350},"Allow the end time to be set to an expired time (for test or audit).",{"type":21,"tag":2228,"props":14352,"children":14353},{},[14354],{"type":27,"value":14355},"✅ (for debugging)",{"type":21,"tag":2200,"props":14357,"children":14358},{},[14359,14363,14368],{"type":21,"tag":2228,"props":14360,"children":14361},{},[14362],{"type":27,"value":5749},{"type":21,"tag":2228,"props":14364,"children":14365},{},[14366],{"type":27,"value":14367},"Allow the extension fields in the CSR to overwrite the predefined extension fields in the profile.",{"type":21,"tag":2228,"props":14369,"children":14370},{},[14371],{"type":27,"value":14372},"❌ Enabling this function can harm profile uniformity and create potential risks.",{"type":21,"tag":2200,"props":14374,"children":14375},{},[14376,14380,14385],{"type":21,"tag":2228,"props":14377,"children":14378},{},[14379],{"type":27,"value":5767},{"type":21,"tag":2228,"props":14381,"children":14382},{},[14383],{"type":27,"value":14384},"Allow the certificate serial number to be customized during issuance.",{"type":21,"tag":2228,"props":14386,"children":14387},{},[14388],{"type":27,"value":14389},"❌ Enable this function only under specific circumstances (for example, for certificate cloning and replacement).",{"type":21,"tag":2200,"props":14391,"children":14392},{},[14393,14397,14402],{"type":21,"tag":2228,"props":14394,"children":14395},{},[14396],{"type":27,"value":5785},{"type":21,"tag":2228,"props":14398,"children":14399},{},[14400],{"type":27,"value":14401},"Allow the subject information (such as CN\u002FO) in the CSR to overwrite the profile configuration.",{"type":21,"tag":2228,"props":14403,"children":14404},{},[14405],{"type":27,"value":14406},"✅ which is applicable to the automatic issuance process.",{"type":21,"tag":2200,"props":14408,"children":14409},{},[14410,14414,14419],{"type":21,"tag":2228,"props":14411,"children":14412},{},[14413],{"type":27,"value":5803},{"type":21,"tag":2228,"props":14415,"children":14416},{},[14417],{"type":27,"value":14418},"Allow the subject field to be specified based on the end entity information (user input).",{"type":21,"tag":2228,"props":14420,"children":14421},{},[14422],{"type":27,"value":14423},"(Recommended) ✅, which provides high flexibility.",{"type":21,"tag":2200,"props":14425,"children":14426},{},[14427,14431,14436],{"type":21,"tag":2228,"props":14428,"children":14429},{},[14430],{"type":27,"value":5821},{"type":21,"tag":2228,"props":14432,"children":14433},{},[14434],{"type":27,"value":14435},"Allow the keyUsage field in the CSR to overwrite the profile configuration.",{"type":21,"tag":2228,"props":14437,"children":14438},{},[14439],{"type":27,"value":14440},"❌ Enabling this function creates inconsistencies that compromise security.",{"type":21,"tag":2200,"props":14442,"children":14443},{},[14444,14448,14453],{"type":21,"tag":2228,"props":14445,"children":14446},{},[14447],{"type":27,"value":5839},{"type":21,"tag":2228,"props":14449,"children":14450},{},[14451],{"type":27,"value":14452},"Allow the revocation time to be set to a historical time for retrospective revocation.",{"type":21,"tag":2228,"props":14454,"children":14455},{},[14456],{"type":27,"value":14457},"✅ which is required in some audit\u002Fcompliance scenarios.",{"type":21,"tag":2200,"props":14459,"children":14460},{},[14461,14465,14470],{"type":21,"tag":2228,"props":14462,"children":14463},{},[14464],{"type":27,"value":2529},{"type":21,"tag":2228,"props":14466,"children":14467},{},[14468],{"type":27,"value":14469},"Enable the certificate to be stored in the database. This item must be enabled unless it is used for special offline purposes.",{"type":21,"tag":2228,"props":14471,"children":14472},{},[14473],{"type":27,"value":5866},{"type":21,"tag":2200,"props":14475,"children":14476},{},[14477,14481,14486],{"type":21,"tag":2228,"props":14478,"children":14479},{},[14480],{"type":27,"value":5874},{"type":21,"tag":2228,"props":14482,"children":14483},{},[14484],{"type":27,"value":14485},"Store the complete original certificate data (used with OCSP\u002FCRL).",{"type":21,"tag":2228,"props":14487,"children":14488},{},[14489],{"type":27,"value":14490},"✅ It is recommended that this function be enabled together with the storage function.",{"type":21,"tag":36,"props":14492,"children":14493},{},[14494,14496],{"type":27,"value":14495},"✅ Suggestion: ",{"type":21,"tag":42,"props":14497,"children":14498},{},[14499],{"type":27,"value":14500},"Keep profiles consistent in the production environment. Disable override permissions unless needed to stop CSR or End Entities from making unauthorized changes.",{"type":21,"tag":65,"props":14502,"children":14503},{},[],{"type":21,"tag":150,"props":14505,"children":14507},{"id":14506},"_73-x509v3-extensionbasic-information",[14508],{"type":27,"value":14509},"7.3 X.509v3 Extension—Basic Information",{"type":21,"tag":2192,"props":14511,"children":14512},{},[14513,14532],{"type":21,"tag":2196,"props":14514,"children":14515},{},[14516],{"type":21,"tag":2200,"props":14517,"children":14518},{},[14519,14524,14528],{"type":21,"tag":2204,"props":14520,"children":14521},{},[14522],{"type":27,"value":14523},"Extension Item",{"type":21,"tag":2204,"props":14525,"children":14526},{},[14527],{"type":27,"value":2374},{"type":21,"tag":2204,"props":14529,"children":14530},{},[14531],{"type":27,"value":14318},{"type":21,"tag":2221,"props":14533,"children":14534},{},[14535,14553,14571],{"type":21,"tag":2200,"props":14536,"children":14537},{},[14538,14543,14548],{"type":21,"tag":2228,"props":14539,"children":14540},{},[14541],{"type":27,"value":14542},"Basic constraints",{"type":21,"tag":2228,"props":14544,"children":14545},{},[14546],{"type":27,"value":14547},"Must be a CA certificate (the value must be FALSE for end entity certificates)",{"type":21,"tag":2228,"props":14549,"children":14550},{},[14551],{"type":27,"value":14552},"✅ Enabled; key setting",{"type":21,"tag":2200,"props":14554,"children":14555},{},[14556,14561,14566],{"type":21,"tag":2228,"props":14557,"children":14558},{},[14559],{"type":27,"value":14560},"CA key identifier",{"type":21,"tag":2228,"props":14562,"children":14563},{},[14564],{"type":27,"value":14565},"Information about the CA that issues the certificate.",{"type":21,"tag":2228,"props":14567,"children":14568},{},[14569],{"type":27,"value":14570},"✅ Enabled",{"type":21,"tag":2200,"props":14572,"children":14573},{},[14574,14579,14584],{"type":21,"tag":2228,"props":14575,"children":14576},{},[14577],{"type":27,"value":14578},"Subject key identifier",{"type":21,"tag":2228,"props":14580,"children":14581},{},[14582],{"type":27,"value":14583},"Unique ID of the certificate.",{"type":21,"tag":2228,"props":14585,"children":14586},{},[14587],{"type":27,"value":14570},{"type":21,"tag":65,"props":14589,"children":14590},{},[],{"type":21,"tag":150,"props":14592,"children":14594},{"id":14593},"_74-x509v3-extensionkey-usage",[14595],{"type":27,"value":14596},"7.4 X.509v3 Extension—Key Usage",{"type":21,"tag":2192,"props":14598,"children":14599},{},[14600,14615],{"type":21,"tag":2196,"props":14601,"children":14602},{},[14603],{"type":21,"tag":2200,"props":14604,"children":14605},{},[14606,14611],{"type":21,"tag":2204,"props":14607,"children":14608},{},[14609],{"type":27,"value":14610},"Item",{"type":21,"tag":2204,"props":14612,"children":14613},{},[14614],{"type":27,"value":2374},{"type":21,"tag":2221,"props":14616,"children":14617},{},[14618,14631,14644,14657,14670,14683,14696,14709,14722,14735],{"type":21,"tag":2200,"props":14619,"children":14620},{},[14621,14626],{"type":21,"tag":2228,"props":14622,"children":14623},{},[14624],{"type":27,"value":14625},"digitalSignature",{"type":21,"tag":2228,"props":14627,"children":14628},{},[14629],{"type":27,"value":14630},"Used for signature verification, such as identity authentication and code signature.",{"type":21,"tag":2200,"props":14632,"children":14633},{},[14634,14639],{"type":21,"tag":2228,"props":14635,"children":14636},{},[14637],{"type":27,"value":14638},"nonRepudiation",{"type":21,"tag":2228,"props":14640,"children":14641},{},[14642],{"type":27,"value":14643},"Indicates that the signature is non-repudiable (legal scenario).",{"type":21,"tag":2200,"props":14645,"children":14646},{},[14647,14652],{"type":21,"tag":2228,"props":14648,"children":14649},{},[14650],{"type":27,"value":14651},"dataEncipherment",{"type":21,"tag":2228,"props":14653,"children":14654},{},[14655],{"type":27,"value":14656},"Used to encrypt non-key data.",{"type":21,"tag":2200,"props":14658,"children":14659},{},[14660,14665],{"type":21,"tag":2228,"props":14661,"children":14662},{},[14663],{"type":27,"value":14664},"keyEncipherment",{"type":21,"tag":2228,"props":14666,"children":14667},{},[14668],{"type":27,"value":14669},"Used to encrypt key materials, such as symmetric keys.",{"type":21,"tag":2200,"props":14671,"children":14672},{},[14673,14678],{"type":21,"tag":2228,"props":14674,"children":14675},{},[14676],{"type":27,"value":14677},"keyAgreement",{"type":21,"tag":2228,"props":14679,"children":14680},{},[14681],{"type":27,"value":14682},"Key negotiation protocol (such as DH)",{"type":21,"tag":2200,"props":14684,"children":14685},{},[14686,14691],{"type":21,"tag":2228,"props":14687,"children":14688},{},[14689],{"type":27,"value":14690},"cRLSign",{"type":21,"tag":2228,"props":14692,"children":14693},{},[14694],{"type":27,"value":14695},"Used by the CA to sign CRLs.",{"type":21,"tag":2200,"props":14697,"children":14698},{},[14699,14704],{"type":21,"tag":2228,"props":14700,"children":14701},{},[14702],{"type":27,"value":14703},"keyCertSign",{"type":21,"tag":2228,"props":14705,"children":14706},{},[14707],{"type":27,"value":14708},"Used by the CA to sign certificates.",{"type":21,"tag":2200,"props":14710,"children":14711},{},[14712,14717],{"type":21,"tag":2228,"props":14713,"children":14714},{},[14715],{"type":27,"value":14716},"encipherOnly",{"type":21,"tag":2228,"props":14718,"children":14719},{},[14720],{"type":27,"value":14721},"Used with keyAgreement (only for encryption).",{"type":21,"tag":2200,"props":14723,"children":14724},{},[14725,14730],{"type":21,"tag":2228,"props":14726,"children":14727},{},[14728],{"type":27,"value":14729},"decipherOnly",{"type":21,"tag":2228,"props":14731,"children":14732},{},[14733],{"type":27,"value":14734},"Used with keyAgreement (only for decryption).",{"type":21,"tag":2200,"props":14736,"children":14737},{},[14738,14742],{"type":21,"tag":2228,"props":14739,"children":14740},{},[14741],{"type":27,"value":6136},{"type":21,"tag":2228,"props":14743,"children":14744},{},[14745],{"type":27,"value":14746},"Forbids encryption usage for ECC keys.",{"type":21,"tag":150,"props":14748,"children":14750},{"id":14749},"_75-x509v3-extensionextended-key-usage",[14751],{"type":27,"value":14752},"7.5 X.509v3 Extension—Extended Key Usage",{"type":21,"tag":2192,"props":14754,"children":14755},{},[14756,14770],{"type":21,"tag":2196,"props":14757,"children":14758},{},[14759],{"type":21,"tag":2200,"props":14760,"children":14761},{},[14762,14766],{"type":21,"tag":2204,"props":14763,"children":14764},{},[14765],{"type":27,"value":1850},{"type":21,"tag":2204,"props":14767,"children":14768},{},[14769],{"type":27,"value":2374},{"type":21,"tag":2221,"props":14771,"children":14772},{},[14773,14785,14797,14809,14821,14833,14845,14857,14869,14881,14893,14905,14917,14929,14941,14953,14965,14977,14990,15003,15015,15027,15039,15051,15063,15075,15087,15099,15112,15125,15138,15151,15164],{"type":21,"tag":2200,"props":14774,"children":14775},{},[14776,14780],{"type":21,"tag":2228,"props":14777,"children":14778},{},[14779],{"type":27,"value":6176},{"type":21,"tag":2228,"props":14781,"children":14782},{},[14783],{"type":27,"value":14784},"TLS authentication on the client",{"type":21,"tag":2200,"props":14786,"children":14787},{},[14788,14792],{"type":21,"tag":2228,"props":14789,"children":14790},{},[14791],{"type":27,"value":6189},{"type":21,"tag":2228,"props":14793,"children":14794},{},[14795],{"type":27,"value":14796},"TLS authentication on the server",{"type":21,"tag":2200,"props":14798,"children":14799},{},[14800,14804],{"type":21,"tag":2228,"props":14801,"children":14802},{},[14803],{"type":27,"value":6202},{"type":21,"tag":2228,"props":14805,"children":14806},{},[14807],{"type":27,"value":14808},"Enterprise identity authentication",{"type":21,"tag":2200,"props":14810,"children":14811},{},[14812,14816],{"type":21,"tag":2228,"props":14813,"children":14814},{},[14815],{"type":27,"value":6215},{"type":21,"tag":2228,"props":14817,"children":14818},{},[14819],{"type":27,"value":14820},"Point-to-Point Protocol (PPP) identity authentication",{"type":21,"tag":2200,"props":14822,"children":14823},{},[14824,14828],{"type":21,"tag":2228,"props":14825,"children":14826},{},[14827],{"type":27,"value":6228},{"type":21,"tag":2228,"props":14829,"children":14830},{},[14831],{"type":27,"value":14832},"ETSI TSL signing",{"type":21,"tag":2200,"props":14834,"children":14835},{},[14836,14840],{"type":21,"tag":2228,"props":14837,"children":14838},{},[14839],{"type":27,"value":6241},{"type":21,"tag":2228,"props":14841,"children":14842},{},[14843],{"type":27,"value":14844},"ICAO signing",{"type":21,"tag":2200,"props":14846,"children":14847},{},[14848,14852],{"type":21,"tag":2228,"props":14849,"children":14850},{},[14851],{"type":27,"value":6254},{"type":21,"tag":2228,"props":14853,"children":14854},{},[14855],{"type":27,"value":14856},"ICAO primary list signing",{"type":21,"tag":2200,"props":14858,"children":14859},{},[14860,14864],{"type":21,"tag":2228,"props":14861,"children":14862},{},[14863],{"type":27,"value":6267},{"type":21,"tag":2228,"props":14865,"children":14866},{},[14867],{"type":27,"value":14868},"Dedicated to Intel management certification",{"type":21,"tag":2200,"props":14870,"children":14871},{},[14872,14876],{"type":21,"tag":2228,"props":14873,"children":14874},{},[14875],{"type":27,"value":6280},{"type":21,"tag":2228,"props":14877,"children":14878},{},[14879],{"type":27,"value":14880},"IPsec key exchange",{"type":21,"tag":2200,"props":14882,"children":14883},{},[14884,14888],{"type":21,"tag":2228,"props":14885,"children":14886},{},[14887],{"type":27,"value":6293},{"type":21,"tag":2228,"props":14889,"children":14890},{},[14891],{"type":27,"value":14892},"Kerberos client authentication",{"type":21,"tag":2200,"props":14894,"children":14895},{},[14896,14900],{"type":21,"tag":2228,"props":14897,"children":14898},{},[14899],{"type":27,"value":6306},{"type":21,"tag":2228,"props":14901,"children":14902},{},[14903],{"type":27,"value":14904},"Kerberos key center",{"type":21,"tag":2200,"props":14906,"children":14907},{},[14908,14912],{"type":21,"tag":2228,"props":14909,"children":14910},{},[14911],{"type":27,"value":6319},{"type":21,"tag":2228,"props":14913,"children":14914},{},[14915],{"type":27,"value":14916},"Microsoft CA key exchange",{"type":21,"tag":2200,"props":14918,"children":14919},{},[14920,14924],{"type":21,"tag":2228,"props":14921,"children":14922},{},[14923],{"type":27,"value":6332},{"type":21,"tag":2228,"props":14925,"children":14926},{},[14927],{"type":27,"value":14928},"Microsoft commercial code signing",{"type":21,"tag":2200,"props":14930,"children":14931},{},[14932,14936],{"type":21,"tag":2228,"props":14933,"children":14934},{},[14935],{"type":27,"value":6345},{"type":21,"tag":2228,"props":14937,"children":14938},{},[14939],{"type":27,"value":14940},"Microsoft document signing",{"type":21,"tag":2200,"props":14942,"children":14943},{},[14944,14948],{"type":21,"tag":2228,"props":14945,"children":14946},{},[14947],{"type":27,"value":6358},{"type":21,"tag":2228,"props":14949,"children":14950},{},[14951],{"type":27,"value":14952},"Microsoft EFS recovery",{"type":21,"tag":2200,"props":14954,"children":14955},{},[14956,14960],{"type":21,"tag":2228,"props":14957,"children":14958},{},[14959],{"type":27,"value":6371},{"type":21,"tag":2228,"props":14961,"children":14962},{},[14963],{"type":27,"value":14964},"Microsoft encrypted file system",{"type":21,"tag":2200,"props":14966,"children":14967},{},[14968,14972],{"type":21,"tag":2228,"props":14969,"children":14970},{},[14971],{"type":27,"value":6384},{"type":21,"tag":2228,"props":14973,"children":14974},{},[14975],{"type":27,"value":14976},"Microsoft individual code signing",{"type":21,"tag":2200,"props":14978,"children":14979},{},[14980,14985],{"type":21,"tag":2228,"props":14981,"children":14982},{},[14983],{"type":27,"value":14984},"MS Smart Card Sign-in",{"type":21,"tag":2228,"props":14986,"children":14987},{},[14988],{"type":27,"value":14989},"Microsoft smart card login authentication",{"type":21,"tag":2200,"props":14991,"children":14992},{},[14993,14998],{"type":21,"tag":2228,"props":14994,"children":14995},{},[14996],{"type":27,"value":14997},"OCSP Issuer",{"type":21,"tag":2228,"props":14999,"children":15000},{},[15001],{"type":27,"value":15002},"Online Certificate Status Protocol (OCSP) signing certificate",{"type":21,"tag":2200,"props":15004,"children":15005},{},[15006,15010],{"type":21,"tag":2228,"props":15007,"children":15008},{},[15009],{"type":27,"value":6423},{"type":21,"tag":2228,"props":15011,"children":15012},{},[15013],{"type":27,"value":15014},"PDF signing",{"type":21,"tag":2200,"props":15016,"children":15017},{},[15018,15022],{"type":21,"tag":2228,"props":15019,"children":15020},{},[15021],{"type":27,"value":6436},{"type":21,"tag":2228,"props":15023,"children":15024},{},[15025],{"type":27,"value":15026},"PIV card authentication",{"type":21,"tag":2200,"props":15028,"children":15029},{},[15030,15034],{"type":21,"tag":2228,"props":15031,"children":15032},{},[15033],{"type":27,"value":6449},{"type":21,"tag":2228,"props":15035,"children":15036},{},[15037],{"type":27,"value":15038},"RFC9336-compliant document signing",{"type":21,"tag":2200,"props":15040,"children":15041},{},[15042,15046],{"type":21,"tag":2228,"props":15043,"children":15044},{},[15045],{"type":27,"value":6462},{"type":21,"tag":2228,"props":15047,"children":15048},{},[15049],{"type":27,"value":15050},"Simplified Certificate Verification Protocol (SCVP) client",{"type":21,"tag":2200,"props":15052,"children":15053},{},[15054,15058],{"type":21,"tag":2228,"props":15055,"children":15056},{},[15057],{"type":27,"value":6475},{"type":21,"tag":2228,"props":15059,"children":15060},{},[15061],{"type":27,"value":15062},"SCVP server",{"type":21,"tag":2200,"props":15064,"children":15065},{},[15066,15070],{"type":21,"tag":2228,"props":15067,"children":15068},{},[15069],{"type":27,"value":6488},{"type":21,"tag":2228,"props":15071,"children":15072},{},[15073],{"type":27,"value":15074},"VoIP\u002FSIP domain name authentication",{"type":21,"tag":2200,"props":15076,"children":15077},{},[15078,15082],{"type":21,"tag":2228,"props":15079,"children":15080},{},[15081],{"type":27,"value":6501},{"type":21,"tag":2228,"props":15083,"children":15084},{},[15085],{"type":27,"value":15086},"SSH client authentication",{"type":21,"tag":2200,"props":15088,"children":15089},{},[15090,15094],{"type":21,"tag":2228,"props":15091,"children":15092},{},[15093],{"type":27,"value":6514},{"type":21,"tag":2228,"props":15095,"children":15096},{},[15097],{"type":27,"value":15098},"SSH server authentication",{"type":21,"tag":2200,"props":15100,"children":15101},{},[15102,15107],{"type":21,"tag":2228,"props":15103,"children":15104},{},[15105],{"type":27,"value":15106},"codeSigning",{"type":21,"tag":2228,"props":15108,"children":15109},{},[15110],{"type":27,"value":15111},"Software\u002FDriver signing",{"type":21,"tag":2200,"props":15113,"children":15114},{},[15115,15120],{"type":21,"tag":2228,"props":15116,"children":15117},{},[15118],{"type":27,"value":15119},"Any EKU",{"type":21,"tag":2228,"props":15121,"children":15122},{},[15123],{"type":27,"value":15124},"Common EKU support",{"type":21,"tag":2200,"props":15126,"children":15127},{},[15128,15133],{"type":21,"tag":2228,"props":15129,"children":15130},{},[15131],{"type":27,"value":15132},"emailProtection",{"type":21,"tag":2228,"props":15134,"children":15135},{},[15136],{"type":27,"value":15137},"S\u002FMIME email signing\u002Fencryption",{"type":21,"tag":2200,"props":15139,"children":15140},{},[15141,15146],{"type":21,"tag":2228,"props":15142,"children":15143},{},[15144],{"type":27,"value":15145},"clientAuth",{"type":21,"tag":2228,"props":15147,"children":15148},{},[15149],{"type":27,"value":15150},"TLS client authentication",{"type":21,"tag":2200,"props":15152,"children":15153},{},[15154,15159],{"type":21,"tag":2228,"props":15155,"children":15156},{},[15157],{"type":27,"value":15158},"timeStamping",{"type":21,"tag":2228,"props":15160,"children":15161},{},[15162],{"type":27,"value":15163},"Timestamp signing",{"type":21,"tag":2200,"props":15165,"children":15166},{},[15167,15172],{"type":21,"tag":2228,"props":15168,"children":15169},{},[15170],{"type":27,"value":15171},"serverAuth",{"type":21,"tag":2228,"props":15173,"children":15174},{},[15175],{"type":27,"value":15176},"Server identity authentication (HTTPS, etc.)",{"type":21,"tag":150,"props":15178,"children":15180},{"id":15179},"_76-name-extension",[15181],{"type":27,"value":15182},"7.6 Name Extension",{"type":21,"tag":2192,"props":15184,"children":15185},{},[15186,15205],{"type":21,"tag":2196,"props":15187,"children":15188},{},[15189],{"type":21,"tag":2200,"props":15190,"children":15191},{},[15192,15196,15200],{"type":21,"tag":2204,"props":15193,"children":15194},{},[15195],{"type":27,"value":14610},{"type":21,"tag":2204,"props":15197,"children":15198},{},[15199],{"type":27,"value":2374},{"type":21,"tag":2204,"props":15201,"children":15202},{},[15203],{"type":27,"value":15204},"Suggestion",{"type":21,"tag":2221,"props":15206,"children":15207},{},[15208,15225,15242],{"type":21,"tag":2200,"props":15209,"children":15210},{},[15211,15216,15221],{"type":21,"tag":2228,"props":15212,"children":15213},{},[15214],{"type":27,"value":15215},"Subject Alt Name",{"type":21,"tag":2228,"props":15217,"children":15218},{},[15219],{"type":27,"value":15220},"IP address, DNS, and Uemail can be used as certificate identifiers.",{"type":21,"tag":2228,"props":15222,"children":15223},{},[15224],{"type":27,"value":14570},{"type":21,"tag":2200,"props":15226,"children":15227},{},[15228,15232,15237],{"type":21,"tag":2228,"props":15229,"children":15230},{},[15231],{"type":27,"value":6653},{"type":21,"tag":2228,"props":15233,"children":15234},{},[15235],{"type":27,"value":15236},"Additional CA name.\tOptional",{"type":21,"tag":2228,"props":15238,"children":15239},{},[15240],{"type":27,"value":15241},"Optional",{"type":21,"tag":2200,"props":15243,"children":15244},{},[15245,15249,15254],{"type":21,"tag":2228,"props":15246,"children":15247},{},[15248],{"type":27,"value":6671},{"type":21,"tag":2228,"props":15250,"children":15251},{},[15252],{"type":27,"value":15253},"Constraints for subject namespaces.",{"type":21,"tag":2228,"props":15255,"children":15256},{},[15257],{"type":27,"value":15258},"Optional (used in high-security scenarios)",{"type":21,"tag":150,"props":15260,"children":15262},{"id":15261},"_77-validation-data",[15263],{"type":27,"value":15264},"7.7 Validation Data",{"type":21,"tag":2192,"props":15266,"children":15267},{},[15268,15286],{"type":21,"tag":2196,"props":15269,"children":15270},{},[15271],{"type":21,"tag":2200,"props":15272,"children":15273},{},[15274,15278,15282],{"type":21,"tag":2204,"props":15275,"children":15276},{},[15277],{"type":27,"value":14610},{"type":21,"tag":2204,"props":15279,"children":15280},{},[15281],{"type":27,"value":2374},{"type":21,"tag":2204,"props":15283,"children":15284},{},[15285],{"type":27,"value":15204},{"type":21,"tag":2221,"props":15287,"children":15288},{},[15289,15306,15323],{"type":21,"tag":2200,"props":15290,"children":15291},{},[15292,15297,15302],{"type":21,"tag":2228,"props":15293,"children":15294},{},[15295],{"type":27,"value":15296},"CRL Distribution Point",{"type":21,"tag":2228,"props":15298,"children":15299},{},[15300],{"type":27,"value":15301},"CRL URL",{"type":21,"tag":2228,"props":15303,"children":15304},{},[15305],{"type":27,"value":14552},{"type":21,"tag":2200,"props":15307,"children":15308},{},[15309,15313,15318],{"type":21,"tag":2228,"props":15310,"children":15311},{},[15312],{"type":27,"value":6737},{"type":21,"tag":2228,"props":15314,"children":15315},{},[15316],{"type":27,"value":15317},"Incremental CRL",{"type":21,"tag":2228,"props":15319,"children":15320},{},[15321],{"type":27,"value":15322},"Enable on demand",{"type":21,"tag":2200,"props":15324,"children":15325},{},[15326,15330,15335],{"type":21,"tag":2228,"props":15327,"children":15328},{},[15329],{"type":27,"value":6755},{"type":21,"tag":2228,"props":15331,"children":15332},{},[15333],{"type":27,"value":15334},"OCSP\u002FCA information",{"type":21,"tag":2228,"props":15336,"children":15337},{},[15338],{"type":27,"value":5866},{"type":21,"tag":65,"props":15340,"children":15341},{},[],{"type":21,"tag":150,"props":15343,"children":15345},{"id":15344},"_78-private-key-validity-period",[15346],{"type":27,"value":15347},"7.8 Private Key Validity Period",{"type":21,"tag":2192,"props":15349,"children":15350},{},[15351,15365],{"type":21,"tag":2196,"props":15352,"children":15353},{},[15354],{"type":21,"tag":2200,"props":15355,"children":15356},{},[15357,15361],{"type":21,"tag":2204,"props":15358,"children":15359},{},[15360],{"type":27,"value":14610},{"type":21,"tag":2204,"props":15362,"children":15363},{},[15364],{"type":27,"value":2374},{"type":21,"tag":2221,"props":15366,"children":15367},{},[15368,15380],{"type":21,"tag":2200,"props":15369,"children":15370},{},[15371,15375],{"type":21,"tag":2228,"props":15372,"children":15373},{},[15374],{"type":27,"value":6801},{"type":21,"tag":2228,"props":15376,"children":15377},{},[15378],{"type":27,"value":15379},"Start offset time of the private key",{"type":21,"tag":2200,"props":15381,"children":15382},{},[15383,15387],{"type":21,"tag":2228,"props":15384,"children":15385},{},[15386],{"type":27,"value":6814},{"type":21,"tag":2228,"props":15388,"children":15389},{},[15390],{"type":27,"value":15391},"Validity period of the private key (independent of the certificate validity period)",{"type":21,"tag":65,"props":15393,"children":15394},{},[],{"type":21,"tag":150,"props":15396,"children":15398},{"id":15397},"_79-etsi-compliant-extensions-typically-for-high-compliance-pki-use-cases",[15399],{"type":27,"value":15400},"7.9 ETSI Compliant Extensions (Typically for High-compliance PKI Use Cases)",{"type":21,"tag":2192,"props":15402,"children":15403},{},[15404,15418],{"type":21,"tag":2196,"props":15405,"children":15406},{},[15407],{"type":21,"tag":2200,"props":15408,"children":15409},{},[15410,15414],{"type":21,"tag":2204,"props":15411,"children":15412},{},[15413],{"type":27,"value":14610},{"type":21,"tag":2204,"props":15415,"children":15416},{},[15417],{"type":27,"value":2374},{"type":21,"tag":2221,"props":15419,"children":15420},{},[15421,15434],{"type":21,"tag":2200,"props":15422,"children":15423},{},[15424,15429],{"type":21,"tag":2228,"props":15425,"children":15426},{},[15427],{"type":27,"value":15428},"Certifications Statement",{"type":21,"tag":2228,"props":15430,"children":15431},{},[15432],{"type":27,"value":15433},"Identifies certificates used for legal or compliance purposes.",{"type":21,"tag":2200,"props":15435,"children":15436},{},[15437,15441],{"type":21,"tag":2228,"props":15438,"children":15439},{},[15440],{"type":27,"value":6869},{"type":21,"tag":2228,"props":15442,"children":15443},{},[15444],{"type":27,"value":15445},"Ensures the validity of short-term certificates.",{"type":21,"tag":65,"props":15447,"children":15448},{},[],{"type":21,"tag":150,"props":15450,"children":15452},{"id":15451},"_710-other-extensions",[15453],{"type":27,"value":15454},"7.10 Other Extensions",{"type":21,"tag":2192,"props":15456,"children":15457},{},[15458,15474],{"type":21,"tag":2196,"props":15459,"children":15460},{},[15461],{"type":21,"tag":2200,"props":15462,"children":15463},{},[15464,15469],{"type":21,"tag":2204,"props":15465,"children":15466},{},[15467],{"type":27,"value":15468},"Extension",{"type":21,"tag":2204,"props":15470,"children":15471},{},[15472],{"type":27,"value":15473},"Usage",{"type":21,"tag":2221,"props":15475,"children":15476},{},[15477,15489,15502],{"type":21,"tag":2200,"props":15478,"children":15479},{},[15480,15484],{"type":21,"tag":2228,"props":15481,"children":15482},{},[15483],{"type":27,"value":6913},{"type":21,"tag":2228,"props":15485,"children":15486},{},[15487],{"type":27,"value":15488},"Disables OCSP check (useful only for OCSP responders).",{"type":21,"tag":2200,"props":15490,"children":15491},{},[15492,15497],{"type":21,"tag":2228,"props":15493,"children":15494},{},[15495],{"type":27,"value":15496},"Microsoft Profile",{"type":21,"tag":2228,"props":15498,"children":15499},{},[15500],{"type":27,"value":15501},"Value\tSpecial extensions for Windows AD integration",{"type":21,"tag":2200,"props":15503,"children":15504},{},[15505,15509],{"type":21,"tag":2228,"props":15506,"children":15507},{},[15508],{"type":27,"value":6939},{"type":21,"tag":2228,"props":15510,"children":15511},{},[15512],{"type":27,"value":15513},"Identifier extension for CA\u002FB-compliant organization",{"type":21,"tag":65,"props":15515,"children":15516},{},[],{"type":21,"tag":150,"props":15518,"children":15520},{"id":15519},"_711-approval-settings-and-additional-fields",[15521],{"type":27,"value":15522},"7.11 Approval Settings and Additional Fields",{"type":21,"tag":2192,"props":15524,"children":15525},{},[15526,15540],{"type":21,"tag":2196,"props":15527,"children":15528},{},[15529],{"type":21,"tag":2200,"props":15530,"children":15531},{},[15532,15536],{"type":21,"tag":2204,"props":15533,"children":15534},{},[15535],{"type":27,"value":14112},{"type":21,"tag":2204,"props":15537,"children":15538},{},[15539],{"type":27,"value":2374},{"type":21,"tag":2221,"props":15541,"children":15542},{},[15543,15555,15567,15580,15593],{"type":21,"tag":2200,"props":15544,"children":15545},{},[15546,15550],{"type":21,"tag":2228,"props":15547,"children":15548},{},[15549],{"type":27,"value":3152},{"type":21,"tag":2228,"props":15551,"children":15552},{},[15553],{"type":27,"value":15554},"Bound approval process",{"type":21,"tag":2200,"props":15556,"children":15557},{},[15558,15562],{"type":21,"tag":2228,"props":15559,"children":15560},{},[15561],{"type":27,"value":3173},{"type":21,"tag":2228,"props":15563,"children":15564},{},[15565],{"type":27,"value":15566},"Whether key recovery is supported (for example, for backup and restoration)",{"type":21,"tag":2200,"props":15568,"children":15569},{},[15570,15575],{"type":21,"tag":2228,"props":15571,"children":15572},{},[15573],{"type":27,"value":15574},"Revocation Approval",{"type":21,"tag":2228,"props":15576,"children":15577},{},[15578],{"type":27,"value":15579},"Whether approval is required for revocation",{"type":21,"tag":2200,"props":15581,"children":15582},{},[15583,15588],{"type":21,"tag":2228,"props":15584,"children":15585},{},[15586],{"type":27,"value":15587},"CN Suffix",{"type":21,"tag":2228,"props":15589,"children":15590},{},[15591],{"type":27,"value":15592},"A character string automatically added to the end of Subject CN",{"type":21,"tag":2200,"props":15594,"children":15595},{},[15596,15601],{"type":21,"tag":2228,"props":15597,"children":15598},{},[15599],{"type":27,"value":15600},"Subject Subset Restriction",{"type":21,"tag":2228,"props":15602,"children":15603},{},[15604],{"type":27,"value":15605},"Restriction on the Subject fields that can be used",{"type":21,"tag":65,"props":15607,"children":15608},{},[],{"type":21,"tag":150,"props":15610,"children":15612},{"id":15611},"_712-ca-release-settings",[15613],{"type":27,"value":15614},"7.12 CA & Release Settings",{"type":21,"tag":2192,"props":15616,"children":15617},{},[15618,15632],{"type":21,"tag":2196,"props":15619,"children":15620},{},[15621],{"type":21,"tag":2200,"props":15622,"children":15623},{},[15624,15628],{"type":21,"tag":2204,"props":15625,"children":15626},{},[15627],{"type":27,"value":14610},{"type":21,"tag":2204,"props":15629,"children":15630},{},[15631],{"type":27,"value":2374},{"type":21,"tag":2221,"props":15633,"children":15634},{},[15635,15648,15661,15674],{"type":21,"tag":2200,"props":15636,"children":15637},{},[15638,15643],{"type":21,"tag":2228,"props":15639,"children":15640},{},[15641],{"type":27,"value":15642},"Available CA",{"type":21,"tag":2228,"props":15644,"children":15645},{},[15646],{"type":27,"value":15647},"CA that can use the certificate profile",{"type":21,"tag":2200,"props":15649,"children":15650},{},[15651,15656],{"type":21,"tag":2228,"props":15652,"children":15653},{},[15654],{"type":27,"value":15655},"Publisher",{"type":21,"tag":2228,"props":15657,"children":15658},{},[15659],{"type":27,"value":15660},"Publishing to LDAP, databases, or external services",{"type":21,"tag":2200,"props":15662,"children":15663},{},[15664,15669],{"type":21,"tag":2228,"props":15665,"children":15666},{},[15667],{"type":27,"value":15668},"Single Certificate Limit",{"type":21,"tag":2228,"props":15670,"children":15671},{},[15672],{"type":27,"value":15673},"Whether an end entity can have only one valid certificate",{"type":21,"tag":2200,"props":15675,"children":15676},{},[15677,15681],{"type":21,"tag":2228,"props":15678,"children":15679},{},[15680],{"type":27,"value":7114},{"type":21,"tag":2228,"props":15682,"children":15683},{},[15684],{"type":27,"value":15685},"Device account binding (for example, IoT)",{"type":21,"tag":65,"props":15687,"children":15688},{},[],{"type":21,"tag":36,"props":15690,"children":15691},{},[15692],{"type":27,"value":15693},"To configure the code signing certificate profile, adjust the keyUsage and extendedKeyUsage fields.",{"type":21,"tag":531,"props":15695,"children":15696},{},[15697],{"type":21,"tag":36,"props":15698,"children":15699},{},[15700],{"type":27,"value":15701},"📌 You are advised to create different profiles for different applications (such as VPN, HTTPS, code signing, and client authentication) to facilitate management and compliance control.",{"type":21,"tag":65,"props":15703,"children":15704},{},[],{"type":21,"tag":29,"props":15706,"children":15708},{"id":15707},"_8-approval-configuration-and-management",[15709],{"type":27,"value":15710},"8. Approval Configuration and Management",{"type":21,"tag":150,"props":15712,"children":15714},{"id":15713},"_81-creating-an-approval-profile-approval-configuration",[15715],{"type":27,"value":15716},"8.1 Creating an Approval Profile (Approval Configuration)",{"type":21,"tag":546,"props":15718,"children":15719},{},[15720,15730,15746],{"type":21,"tag":54,"props":15721,"children":15722},{},[15723,15724,15729],{"type":27,"value":10600},{"type":21,"tag":42,"props":15725,"children":15726},{},[15727],{"type":27,"value":15728},"Watchdog > Approval Profiles",{"type":27,"value":9486},{"type":21,"tag":54,"props":15731,"children":15732},{},[15733,15735,15739,15741,15745],{"type":27,"value":15734},"Type a name (for example, ",{"type":21,"tag":42,"props":15736,"children":15737},{},[15738],{"type":27,"value":5040},{"type":27,"value":15740},") at the bottom and click ",{"type":21,"tag":42,"props":15742,"children":15743},{},[15744],{"type":27,"value":1831},{"type":27,"value":9486},{"type":21,"tag":54,"props":15747,"children":15748},{},[15749,15750,15755],{"type":27,"value":10637},{"type":21,"tag":42,"props":15751,"children":15752},{},[15753],{"type":27,"value":15754},"Edit",{"type":27,"value":15756}," in the list to enter the detailed settings.",{"type":21,"tag":150,"props":15758,"children":15760},{"id":15759},"_82-basic-parameter-settings",[15761],{"type":27,"value":15762},"8.2 Basic Parameter Settings",{"type":21,"tag":2192,"props":15764,"children":15765},{},[15766,15781],{"type":21,"tag":2196,"props":15767,"children":15768},{},[15769],{"type":21,"tag":2200,"props":15770,"children":15771},{},[15772,15776],{"type":21,"tag":2204,"props":15773,"children":15774},{},[15775],{"type":27,"value":13439},{"type":21,"tag":2204,"props":15777,"children":15778},{},[15779],{"type":27,"value":15780},"Suggestion\u002FExample",{"type":21,"tag":2221,"props":15782,"children":15783},{},[15784,15796,15808,15820,15832],{"type":21,"tag":2200,"props":15785,"children":15786},{},[15787,15791],{"type":21,"tag":2228,"props":15788,"children":15789},{},[15790],{"type":27,"value":7236},{"type":21,"tag":2228,"props":15792,"children":15793},{},[15794],{"type":27,"value":15795},"Accumulative Approval Partitioned Approval (can be used in cross-department cases)",{"type":21,"tag":2200,"props":15797,"children":15798},{},[15799,15803],{"type":21,"tag":2228,"props":15800,"children":15801},{},[15802],{"type":27,"value":7249},{"type":21,"tag":2228,"props":15804,"children":15805},{},[15806],{"type":27,"value":15807},"8h (The request will be voided if not approved within the expiration period.)",{"type":21,"tag":2200,"props":15809,"children":15810},{},[15811,15815],{"type":21,"tag":2228,"props":15812,"children":15813},{},[15814],{"type":27,"value":7268},{"type":21,"tag":2228,"props":15816,"children":15817},{},[15818],{"type":27,"value":15819},"8h (Re-approval is required after the expiration period.)",{"type":21,"tag":2200,"props":15821,"children":15822},{},[15823,15827],{"type":21,"tag":2228,"props":15824,"children":15825},{},[15826],{"type":27,"value":7286},{"type":21,"tag":2228,"props":15828,"children":15829},{},[15830],{"type":27,"value":15831},"0d (The period cannot be extended.)",{"type":21,"tag":2200,"props":15833,"children":15834},{},[15835,15839],{"type":21,"tag":2228,"props":15836,"children":15837},{},[15838],{"type":27,"value":7305},{"type":21,"tag":2228,"props":15840,"children":15841},{},[15842],{"type":27,"value":15843},"Deselected (Self-approval is prohibited in production.)",{"type":21,"tag":150,"props":15845,"children":15847},{"id":15846},"_83-approval-steps",[15848],{"type":27,"value":15849},"8.3 Approval Steps",{"type":21,"tag":546,"props":15851,"children":15852},{},[15853,15891],{"type":21,"tag":54,"props":15854,"children":15855},{},[15856,15858,15863,15864],{"type":27,"value":15857},"Set ",{"type":21,"tag":141,"props":15859,"children":15861},{"className":15860},[],[15862],{"type":27,"value":7330},{"type":27,"value":9486},{"type":21,"tag":50,"props":15865,"children":15866},{},[15867,15879],{"type":21,"tag":54,"props":15868,"children":15869},{},[15870,15872,15877],{"type":27,"value":15871},"Development\u002FTest: ",{"type":21,"tag":141,"props":15873,"children":15875},{"className":15874},[],[15876],{"type":27,"value":7345},{"type":27,"value":15878}," (1-of-1).",{"type":21,"tag":54,"props":15880,"children":15881},{},[15882,15884,15889],{"type":27,"value":15883},"Production\u002FSensitive operations: ",{"type":21,"tag":141,"props":15885,"children":15887},{"className":15886},[],[15888],{"type":27,"value":7358},{"type":27,"value":15890}," (2-of-2) or partitioned approval.",{"type":21,"tag":54,"props":15892,"children":15893},{},[15894,15896],{"type":27,"value":15895},"Notification email:",{"type":21,"tag":50,"props":15897,"children":15898},{},[15899,15913,15927,15939],{"type":21,"tag":54,"props":15900,"children":15901},{},[15902,15907,15908],{"type":21,"tag":141,"props":15903,"children":15905},{"className":15904},[],[15906],{"type":27,"value":7377},{"type":27,"value":675},{"type":21,"tag":141,"props":15909,"children":15911},{"className":15910},[],[15912],{"type":27,"value":7384},{"type":21,"tag":54,"props":15914,"children":15915},{},[15916,15921,15922],{"type":21,"tag":141,"props":15917,"children":15919},{"className":15918},[],[15920],{"type":27,"value":7393},{"type":27,"value":675},{"type":21,"tag":141,"props":15923,"children":15925},{"className":15924},[],[15926],{"type":27,"value":7400},{"type":21,"tag":54,"props":15928,"children":15929},{},[15930,15932],{"type":27,"value":15931},"Example theme profile:\n",{"type":21,"tag":182,"props":15933,"children":15934},{"code":7408},[15935],{"type":21,"tag":141,"props":15936,"children":15937},{"__ignoreMap":7},[15938],{"type":27,"value":7408},{"type":21,"tag":54,"props":15940,"children":15941},{},[15942,15944,15949,15950,15955,15957,15962],{"type":27,"value":15943},"Variables that can be referenced in the body: ",{"type":21,"tag":141,"props":15945,"children":15947},{"className":15946},[],[15948],{"type":27,"value":7424},{"type":27,"value":10673},{"type":21,"tag":141,"props":15951,"children":15953},{"className":15952},[],[15954],{"type":27,"value":7431},{"type":27,"value":15956},", and ",{"type":21,"tag":141,"props":15958,"children":15960},{"className":15959},[],[15961],{"type":27,"value":7438},{"type":27,"value":9486},{"type":21,"tag":150,"props":15964,"children":15966},{"id":15965},"_84-binding-to-a-specific-action",[15967],{"type":27,"value":15968},"8.4 Binding to a Specific Action",{"type":21,"tag":36,"props":15970,"children":15971},{},[15972],{"type":21,"tag":42,"props":15973,"children":15974},{},[15975],{"type":27,"value":15976},"End Entity Profile:",{"type":21,"tag":36,"props":15978,"children":15979},{},[15980,15981,15992,15994,15999],{"type":27,"value":10600},{"type":21,"tag":42,"props":15982,"children":15983},{},[15984,15986],{"type":27,"value":15985},"CA Functions > End Entity Profiles > ",{"type":21,"tag":15987,"props":15988,"children":15989},"profile",{},[15990],{"type":27,"value":15991}," > Approval Settings>",{"type":27,"value":15993}," Add\u002FEdit End Entity to be approved > Approval Profile and then click ",{"type":21,"tag":42,"props":15995,"children":15996},{},[15997],{"type":27,"value":15998},"Save",{"type":27,"value":9486},{"type":21,"tag":36,"props":16001,"children":16002},{},[16003,16005,16009,16011,16015],{"type":27,"value":16004},"Common options: ",{"type":21,"tag":42,"props":16006,"children":16007},{},[16008],{"type":27,"value":3152},{"type":27,"value":16010}," and ",{"type":21,"tag":42,"props":16012,"children":16013},{},[16014],{"type":27,"value":3173},{"type":27,"value":16016}," (if enabled)",{"type":21,"tag":36,"props":16018,"children":16019},{},[16020],{"type":21,"tag":42,"props":16021,"children":16022},{},[16023],{"type":27,"value":16024},"Certificate Profile:",{"type":21,"tag":36,"props":16026,"children":16027},{},[16028,16029,16039,16041,16045],{"type":27,"value":10600},{"type":21,"tag":42,"props":16030,"children":16031},{},[16032,16034],{"type":27,"value":16033},"CA Functions > Certificate Profiles > ",{"type":21,"tag":15987,"props":16035,"children":16036},{},[16037],{"type":27,"value":16038}," > Approval Settings > Operation > Approval Profile",{"type":27,"value":16040}," and then click ",{"type":21,"tag":42,"props":16042,"children":16043},{},[16044],{"type":27,"value":15998},{"type":27,"value":9486},{"type":21,"tag":36,"props":16047,"children":16048},{},[16049,16054],{"type":21,"tag":42,"props":16050,"children":16051},{},[16052],{"type":27,"value":16053},"Sensitive administrator actions",{"type":27,"value":16055},": It is recommended that 2-of-2 or partitioned approval be used for intermediate CA change and revocation.",{"type":21,"tag":150,"props":16057,"children":16059},{"id":16058},"_85-testing-and-verification",[16060],{"type":27,"value":16061},"8.5 Testing and Verification",{"type":21,"tag":546,"props":16063,"children":16064},{},[16065,16070,16075],{"type":21,"tag":54,"props":16066,"children":16067},{},[16068],{"type":27,"value":16069},"Use a common RA account to start an operation (for example, creating an end entity) that requires approval on the RA WebUI.",{"type":21,"tag":54,"props":16071,"children":16072},{},[16073],{"type":27,"value":16074},"Choose Inspector Function > Approvals to check the approval queue, and use another approver account to complete the approval.",{"type":21,"tag":54,"props":16076,"children":16077},{},[16078],{"type":27,"value":16079},"Confirm that the operation was executed automatically and the email notification was received successfully.",{"type":21,"tag":150,"props":16081,"children":16083},{"id":16082},"_86-faqs",[16084],{"type":27,"value":16085},"8.6 FAQs",{"type":21,"tag":50,"props":16087,"children":16088},{},[16089,16094,16099,16104],{"type":21,"tag":54,"props":16090,"children":16091},{},[16092],{"type":27,"value":16093},"No email received: Check the SMTP configuration, firewall, and recipient name, and view container logs.",{"type":21,"tag":54,"props":16095,"children":16096},{},[16097],{"type":27,"value":16098},"Stuck in pending status: Number of Required Approvals is set too high or the approver does not have the permission.",{"type":21,"tag":54,"props":16100,"children":16101},{},[16102],{"type":27,"value":16103},"Can be self-approved: Allow Self Approved Request Editing is selected by mistake. This function should be disabled in production.",{"type":21,"tag":54,"props":16105,"children":16106},{},[16107],{"type":27,"value":16108},"Expired: Request\u002FApproval Expiration is set too short. The value can be changed to 8h to 24h.",{"type":21,"tag":29,"props":16110,"children":16112},{"id":16111},"_9-end-entity-profile-settings",[16113],{"type":27,"value":16114},"9. End Entity Profile Settings",{"type":21,"tag":36,"props":16116,"children":16117},{},[16118,16120,16125],{"type":27,"value":16119},"Path: ",{"type":21,"tag":42,"props":16121,"children":16122},{},[16123],{"type":27,"value":16124},"RA Functions > End Entity Profiles",{"type":27,"value":16126},". The End Entity Profile defines the fields that can be populated, specifies which are mandatory or modifiable, and determines the default Certificate Profile, CA, and Token.",{"type":21,"tag":150,"props":16128,"children":16130},{"id":16129},"_91-creating-and-opening-an-end-entity-profile",[16131],{"type":27,"value":16132},"9.1 Creating and Opening an End Entity Profile",{"type":21,"tag":546,"props":16134,"children":16135},{},[16136,16141,16146],{"type":21,"tag":54,"props":16137,"children":16138},{},[16139],{"type":27,"value":16140},"Choose RA Functions > End Entity Profiles.",{"type":21,"tag":54,"props":16142,"children":16143},{},[16144],{"type":27,"value":16145},"Enter the profile name (for example, test) at the bottom and click Add Profile.",{"type":21,"tag":54,"props":16147,"children":16148},{},[16149],{"type":27,"value":16150},"Select the profile from the list and click Edit Endpoint Entity Profile.",{"type":21,"tag":150,"props":16152,"children":16154},{"id":16153},"_92-basic-information-usernamepasswordemail",[16155],{"type":27,"value":16156},"9.2 Basic Information (Username\u002FPassword\u002FEmail)",{"type":21,"tag":36,"props":16158,"children":16159},{},[16160,16162,16167,16169,16174,16176,16181],{"type":27,"value":16161},"Generally, the ",{"type":21,"tag":42,"props":16163,"children":16164},{},[16165],{"type":27,"value":16166},"username\u002Fpassword",{"type":27,"value":16168}," does not need to be specified in the profile. The profile only sets the rules and methods. The ",{"type":21,"tag":42,"props":16170,"children":16171},{},[16172],{"type":27,"value":16173},"username\u002Fpassword\u002Fenrollment code",{"type":27,"value":16175}," can be specified ",{"type":21,"tag":42,"props":16177,"children":16178},{},[16179],{"type":27,"value":16180},"during end entity creation or application submission",{"type":27,"value":9486},{"type":21,"tag":36,"props":16183,"children":16184},{},[16185],{"type":21,"tag":42,"props":16186,"children":16187},{},[16188],{"type":27,"value":16189},"Recommended practice",{"type":21,"tag":50,"props":16191,"children":16192},{},[16193,16198,16203,16208,16213,16218],{"type":21,"tag":54,"props":16194,"children":16195},{},[16196],{"type":27,"value":16197},"Username: Select Auto-generated (for auto and batch operations), or manually specify the username when creating an end entity.",{"type":21,"tag":54,"props":16199,"children":16200},{},[16201],{"type":27,"value":16202},"Password (or Enrollment Code): Select Required to use the one-off Enrollment Code. Enter the specific value when creating an end entity or submitting the application on the RA.",{"type":21,"tag":54,"props":16204,"children":16205},{},[16206],{"type":27,"value":16207},"Minimum password strength\u002Flength: Retain the policy (for example, the length is greater than or equal to 8), but do not enter the specific password.",{"type":21,"tag":54,"props":16209,"children":16210},{},[16211],{"type":27,"value":16212},"Maximum number of failed login attempts: Set the number as needed. Select Modifiable if you need to temporarily change this limit.",{"type":21,"tag":54,"props":16214,"children":16215},{},[16216],{"type":27,"value":16217},"Batch generation: Disable this function. Avoid storing enrollment codes in plaintext.",{"type":21,"tag":54,"props":16219,"children":16220},{},[16221],{"type":27,"value":16222},"E-mail: Set it based on the Required\u002FModifiable setting. It is used for notification and identification.",{"type":21,"tag":36,"props":16224,"children":16225},{},[16226],{"type":21,"tag":42,"props":16227,"children":16228},{},[16229],{"type":27,"value":16230},"Impact of different application paths on username\u002Fpassword",{"type":21,"tag":50,"props":16232,"children":16233},{},[16234,16239,16244],{"type":21,"tag":54,"props":16235,"children":16236},{},[16237],{"type":27,"value":16238},"RA Web > Enroll > Use Username: Username and Password\u002FEnrollment Code are specified when an end entity is created. The user uses this account to log in to the system and obtain the certificate.",{"type":21,"tag":54,"props":16240,"children":16241},{},[16242],{"type":27,"value":16243},"RA Web > Enroll > Use Request ID: The system allocates Request ID. Password\u002FEnrollment Code is set when the request is created. The applicant uses the ID and code to obtain the certificate.",{"type":21,"tag":54,"props":16245,"children":16246},{},[16247],{"type":27,"value":16248},"User Generated (CSR): Token=User Generated. Retain Required to generate a one-off code. The applicant uses the CSR and code to complete the issuance.",{"type":21,"tag":36,"props":16250,"children":16251},{},[16252],{"type":21,"tag":42,"props":16253,"children":16254},{},[16255],{"type":27,"value":16256},"Directives",{"type":21,"tag":50,"props":16258,"children":16259},{},[16260,16265,16270],{"type":21,"tag":54,"props":16261,"children":16262},{},[16263],{"type":27,"value":16264},"Reverse Subject DN and Subject Alt Name Checks: You can also deselect this option.",{"type":21,"tag":54,"props":16266,"children":16267},{},[16268],{"type":27,"value":16269},"Allow merge DN for all interfaces: Generally, this option is not selected. It is selected only when DN combination is required for multiple APIs.",{"type":21,"tag":54,"props":16271,"children":16272},{},[16273],{"type":27,"value":16274},"Allow multi-value RDNs: This option is selected only when special requirements are met. (It is disabled by default, which is more secure.)",{"type":21,"tag":150,"props":16276,"children":16278},{"id":16277},"_93-subject-dn-attributessetting-by-users",[16279],{"type":27,"value":16280},"9.3 Subject DN Attributes—(Setting by Users)",{"type":21,"tag":36,"props":16282,"children":16283},{},[16284,16286,16291],{"type":27,"value":16285},"Available attributes are displayed on the left, and selected attributes are displayed on the right. Add the required fields to the right and set ",{"type":21,"tag":42,"props":16287,"children":16288},{},[16289],{"type":27,"value":16290},"Required\u002FModifiable\u002FValidation",{"type":27,"value":16292}," for each field.",{"type":21,"tag":36,"props":16294,"children":16295},{},[16296],{"type":21,"tag":42,"props":16297,"children":16298},{},[16299],{"type":27,"value":16300},"Common recommendations (client\u002Fgeneral):",{"type":21,"tag":2192,"props":16302,"children":16303},{},[16304,16318],{"type":21,"tag":2196,"props":16305,"children":16306},{},[16307],{"type":21,"tag":2200,"props":16308,"children":16309},{},[16310,16314],{"type":21,"tag":2204,"props":16311,"children":16312},{},[16313],{"type":27,"value":13439},{"type":21,"tag":2204,"props":16315,"children":16316},{},[16317],{"type":27,"value":15204},{"type":21,"tag":2221,"props":16319,"children":16320},{},[16321,16333,16345,16358],{"type":21,"tag":2200,"props":16322,"children":16323},{},[16324,16328],{"type":21,"tag":2228,"props":16325,"children":16326},{},[16327],{"type":27,"value":8044},{"type":21,"tag":2228,"props":16329,"children":16330},{},[16331],{"type":27,"value":16332},"Required; Modifiable is determined by the RA.",{"type":21,"tag":2200,"props":16334,"children":16335},{},[16336,16340],{"type":21,"tag":2228,"props":16337,"children":16338},{},[16339],{"type":27,"value":8071},{"type":21,"tag":2228,"props":16341,"children":16342},{},[16343],{"type":27,"value":16344},"Optional. To bind with the email system, set it to Required.",{"type":21,"tag":2200,"props":16346,"children":16347},{},[16348,16353],{"type":21,"tag":2228,"props":16349,"children":16350},{},[16351],{"type":27,"value":16352},"O, Organization \u002F OU, Org. Unit",{"type":21,"tag":2228,"props":16354,"children":16355},{},[16356],{"type":27,"value":16357},"Service-dependent. You are advised to disable Modifiable to prevent arbitrary input.",{"type":21,"tag":2200,"props":16359,"children":16360},{},[16361,16365],{"type":21,"tag":2228,"props":16362,"children":16363},{},[16364],{"type":27,"value":8123},{"type":21,"tag":2228,"props":16366,"children":16367},{},[16368],{"type":27,"value":16369},"The value is fixed to CN or the country where the user is located. Generally, the value cannot be changed.",{"type":21,"tag":36,"props":16371,"children":16372},{},[16373,16375,16379],{"type":27,"value":16374},"If stricter verification is required, you can specify a regular expression or format rule in ",{"type":21,"tag":42,"props":16376,"children":16377},{},[16378],{"type":27,"value":8148},{"type":27,"value":9486},{"type":21,"tag":150,"props":16381,"children":16383},{"id":16382},"_94-other-subject-attributessetting-by-users",[16384,16386,16390],{"type":27,"value":16385},"9.4 ",{"type":21,"tag":42,"props":16387,"children":16388},{},[16389],{"type":27,"value":8257},{"type":27,"value":16391},"—(Setting by Users)",{"type":21,"tag":36,"props":16393,"children":16394},{},[16395],{"type":21,"tag":42,"props":16396,"children":16397},{},[16398],{"type":27,"value":16399},"Subject Alternative Name (SAN) :",{"type":21,"tag":50,"props":16401,"children":16402},{},[16403,16408,16413],{"type":21,"tag":54,"props":16404,"children":16405},{},[16406],{"type":27,"value":16407},"Client certificate: RFC 822 Name (e-mail address) (same as the account email address)",{"type":21,"tag":54,"props":16409,"children":16410},{},[16411],{"type":27,"value":16412},"Server certificate: DNS Name and IP Address (added by domain name\u002FIP address)",{"type":21,"tag":54,"props":16414,"children":16415},{},[16416],{"type":27,"value":16417},"Device certificate: OtherName (written into the device ID\u002FOID)",{"type":21,"tag":36,"props":16419,"children":16420},{},[16421,16423],{"type":27,"value":16422},"(Optional) **",{"type":21,"tag":42,"props":16424,"children":16425},{},[16426],{"type":27,"value":16427},"Subject Directory Attributes:",{"type":21,"tag":36,"props":16429,"children":16430},{},[16431,16433,16437],{"type":27,"value":16432},"Attributes such as ",{"type":21,"tag":42,"props":16434,"children":16435},{},[16436],{"type":27,"value":8242},{"type":27,"value":16438}," are used only for archiving or compliance needs. You are advised not to enable multiple directory attributes.",{"type":21,"tag":36,"props":16440,"children":16441},{},[16442,16444,16448,16450,16454,16456,16460],{"type":27,"value":16443},"Addition method: Select an item in the ",{"type":21,"tag":42,"props":16445,"children":16446},{},[16447],{"type":27,"value":8257},{"type":27,"value":16449}," area and click ",{"type":21,"tag":42,"props":16451,"children":16452},{},[16453],{"type":27,"value":1831},{"type":27,"value":16455},". You can also mark it as ",{"type":21,"tag":42,"props":16457,"children":16458},{},[16459],{"type":27,"value":7842},{"type":27,"value":16461}," if supported by the interface.",{"type":21,"tag":150,"props":16463,"children":16465},{"id":16464},"_95-main-certificate-data",[16466],{"type":27,"value":16467},"9.5 Main Certificate Data",{"type":21,"tag":2192,"props":16469,"children":16470},{},[16471,16486],{"type":21,"tag":2196,"props":16472,"children":16473},{},[16474],{"type":21,"tag":2200,"props":16475,"children":16476},{},[16477,16481],{"type":21,"tag":2204,"props":16478,"children":16479},{},[16480],{"type":27,"value":13439},{"type":21,"tag":2204,"props":16482,"children":16483},{},[16484],{"type":27,"value":16485},"Suggestion\u002FDescription",{"type":21,"tag":2221,"props":16487,"children":16488},{},[16489,16501,16513,16526],{"type":21,"tag":2200,"props":16490,"children":16491},{},[16492,16496],{"type":21,"tag":2228,"props":16493,"children":16494},{},[16495],{"type":27,"value":8309},{"type":21,"tag":2228,"props":16497,"children":16498},{},[16499],{"type":27,"value":16500},"Select a certificate profile (for example, ENDUSER or SERVER).",{"type":21,"tag":2200,"props":16502,"children":16503},{},[16504,16508],{"type":21,"tag":2228,"props":16505,"children":16506},{},[16507],{"type":27,"value":8338},{"type":21,"tag":2228,"props":16509,"children":16510},{},[16511],{"type":27,"value":16512},"Select only the allowed profiles.",{"type":21,"tag":2200,"props":16514,"children":16515},{},[16516,16521],{"type":21,"tag":2228,"props":16517,"children":16518},{},[16519],{"type":27,"value":16520},"Default CA \u002F Available CAs",{"type":21,"tag":2228,"props":16522,"children":16523},{},[16524],{"type":27,"value":16525},"Specify the CAs that can issue the certificate. Note: Changing the available CAs impacts which roles can access the profile.",{"type":21,"tag":2200,"props":16527,"children":16528},{},[16529,16534],{"type":21,"tag":2228,"props":16530,"children":16531},{},[16532],{"type":27,"value":16533},"Default Token \u002F Available Tokens",{"type":21,"tag":2228,"props":16535,"children":16536},{},[16537],{"type":27,"value":16538},"P12 file (downloaded directly on the RA) or User Generated (CSR created by the user)",{"type":21,"tag":150,"props":16540,"children":16542},{"id":16541},"_96-other-certificate-data",[16543],{"type":27,"value":16544},"9.6 Other Certificate Data",{"type":21,"tag":50,"props":16546,"children":16547},{},[16548,16557,16566,16575],{"type":21,"tag":54,"props":16549,"children":16550},{},[16551,16555],{"type":21,"tag":42,"props":16552,"children":16553},{},[16554],{"type":27,"value":8423},{"type":27,"value":16556},": disabled by default",{"type":21,"tag":54,"props":16558,"children":16559},{},[16560,16564],{"type":21,"tag":42,"props":16561,"children":16562},{},[16563],{"type":27,"value":8434},{"type":27,"value":16565},": controlled by Certificate Profile by default. If a temporary certificate is required, enable this item and select Modifiable.",{"type":21,"tag":54,"props":16567,"children":16568},{},[16569,16573],{"type":21,"tag":42,"props":16570,"children":16571},{},[16572],{"type":27,"value":8456},{"type":27,"value":16574},": used for intermediate CAs. Generally, this item is disabled in end entity profiles.",{"type":21,"tag":54,"props":16576,"children":16577},{},[16578,16583],{"type":21,"tag":42,"props":16579,"children":16580},{},[16581],{"type":27,"value":16582},"Custom certificate extension data \u002F ETSI PSD2 QC Statement \u002F CA\u002FB Forum Organization Identifier",{"type":27,"value":16584},": Enable it as required for compliance.",{"type":21,"tag":150,"props":16586,"children":16588},{"id":16587},"_97-other-datarestrictions",[16589],{"type":27,"value":16590},"9.7 Other Data\u002FRestrictions",{"type":21,"tag":2192,"props":16592,"children":16593},{},[16594,16608],{"type":21,"tag":2196,"props":16595,"children":16596},{},[16597],{"type":21,"tag":2200,"props":16598,"children":16599},{},[16600,16604],{"type":21,"tag":2204,"props":16601,"children":16602},{},[16603],{"type":27,"value":13439},{"type":21,"tag":2204,"props":16605,"children":16606},{},[16607],{"type":27,"value":15204},{"type":21,"tag":2221,"props":16609,"children":16610},{},[16611,16632,16662,16683,16699],{"type":21,"tag":2200,"props":16612,"children":16613},{},[16614,16622],{"type":21,"tag":2228,"props":16615,"children":16616},{},[16617],{"type":21,"tag":141,"props":16618,"children":16620},{"className":16619},[],[16621],{"type":27,"value":8521},{"type":21,"tag":2228,"props":16623,"children":16624},{},[16625,16630],{"type":21,"tag":141,"props":16626,"children":16628},{"className":16627},[],[16629],{"type":27,"value":7345},{"type":27,"value":16631}," (preventing repeated issuance)",{"type":21,"tag":2200,"props":16633,"children":16634},{},[16635,16643],{"type":21,"tag":2228,"props":16636,"children":16637},{},[16638],{"type":21,"tag":141,"props":16639,"children":16641},{"className":16640},[],[16642],{"type":27,"value":8543},{"type":21,"tag":2228,"props":16644,"children":16645},{},[16646,16648,16653,16655,16660],{"type":27,"value":16647},"Example: ",{"type":21,"tag":141,"props":16649,"children":16651},{"className":16650},[],[16652],{"type":27,"value":8553},{"type":27,"value":16654}," days. ",{"type":21,"tag":141,"props":16656,"children":16658},{"className":16657},[],[16659],{"type":27,"value":8561},{"type":27,"value":16661}," indicates no limit.",{"type":21,"tag":2200,"props":16663,"children":16664},{},[16665,16673],{"type":21,"tag":2228,"props":16666,"children":16667},{},[16668],{"type":21,"tag":141,"props":16669,"children":16671},{"className":16670},[],[16672],{"type":27,"value":8573},{"type":21,"tag":2228,"props":16674,"children":16675},{},[16676,16681],{"type":21,"tag":141,"props":16677,"children":16679},{"className":16678},[],[16680],{"type":27,"value":1975},{"type":27,"value":16682}," by default (typically left unchanged)",{"type":21,"tag":2200,"props":16684,"children":16685},{},[16686,16694],{"type":21,"tag":2228,"props":16687,"children":16688},{},[16689],{"type":21,"tag":141,"props":16690,"children":16692},{"className":16691},[],[16693],{"type":27,"value":8597},{"type":21,"tag":2228,"props":16695,"children":16696},{},[16697],{"type":27,"value":16698},"Enable this feature only for strict privacy or compliance needs.",{"type":21,"tag":2200,"props":16700,"children":16701},{},[16702,16710],{"type":21,"tag":2228,"props":16703,"children":16704},{},[16705],{"type":21,"tag":141,"props":16706,"children":16708},{"className":16707},[],[16709],{"type":27,"value":8614},{"type":21,"tag":2228,"props":16711,"children":16712},{},[16713],{"type":27,"value":16714},"Enable it when needed for SMTP settings.",{"type":21,"tag":150,"props":16716,"children":16718},{"id":16717},"_98-saving-and-authorization",[16719],{"type":27,"value":16720},"9.8 Saving and Authorization",{"type":21,"tag":546,"props":16722,"children":16723},{},[16724,16733,16744],{"type":21,"tag":54,"props":16725,"children":16726},{},[16727,16728,16732],{"type":27,"value":10637},{"type":21,"tag":42,"props":16729,"children":16730},{},[16731],{"type":27,"value":15998},{"type":27,"value":9486},{"type":21,"tag":54,"props":16734,"children":16735},{},[16736,16737,16742],{"type":27,"value":10600},{"type":21,"tag":42,"props":16738,"children":16739},{},[16740],{"type":27,"value":16741},"RA Web > Role Management",{"type":27,"value":16743}," and check that the related role has been authorized to use the end entity profile (visible\u002Fcreatable).",{"type":21,"tag":54,"props":16745,"children":16746},{},[16747,16748,16752,16754],{"type":27,"value":10600},{"type":21,"tag":42,"props":16749,"children":16750},{},[16751],{"type":27,"value":13878},{"type":27,"value":16753}," and use the profile to create a test user to check the following:\n",{"type":21,"tag":50,"props":16755,"children":16756},{},[16757,16762,16772],{"type":21,"tag":54,"props":16758,"children":16759},{},[16760],{"type":27,"value":16761},"Check whether the DN\u002FSAN is added to the database according to the rules.",{"type":21,"tag":54,"props":16763,"children":16764},{},[16765,16767,16771],{"type":27,"value":16766},"Check whether the certificate uses the expected ",{"type":21,"tag":42,"props":16768,"children":16769},{},[16770],{"type":27,"value":8678},{"type":27,"value":9486},{"type":21,"tag":54,"props":16773,"children":16774},{},[16775],{"type":27,"value":16776},"Check whether the download or import is successful (P12\u002FPEM\u002FCSR process).",{"type":21,"tag":65,"props":16778,"children":16779},{},[],{"type":21,"tag":29,"props":16781,"children":16783},{"id":16782},"_10-applying-for-an-end-entity-certificate-as-an-ra-common-user",[16784],{"type":27,"value":16785},"10. Applying for an End Entity Certificate as an RA Common User",{"type":21,"tag":531,"props":16787,"children":16788},{},[16789,16798],{"type":21,"tag":36,"props":16790,"children":16791},{},[16792,16793,16797],{"type":27,"value":10600},{"type":21,"tag":42,"props":16794,"children":16795},{},[16796],{"type":27,"value":8705},{"type":27,"value":1732},{"type":21,"tag":36,"props":16799,"children":16800},{},[16801,16803,16807],{"type":27,"value":16802},"By default, you are advised to use ",{"type":21,"tag":42,"props":16804,"children":16805},{},[16806],{"type":27,"value":8721},{"type":27,"value":16808}," (the CA generates the key) for stability and fewer errors; no CSR is needed.",{"type":21,"tag":150,"props":16810,"children":16812},{"id":16811},"_101-path-and-prerequisites",[16813],{"type":27,"value":16814},"10.1 Path and Prerequisites",{"type":21,"tag":50,"props":16816,"children":16817},{},[16818,16835],{"type":21,"tag":54,"props":16819,"children":16820},{},[16821,16823,16827,16829,16833],{"type":27,"value":16822},"Profiles have been prepared in ",{"type":21,"tag":42,"props":16824,"children":16825},{},[16826],{"type":27,"value":8742},{"type":27,"value":16828}," (Section 9) and ",{"type":21,"tag":42,"props":16830,"children":16831},{},[16832],{"type":27,"value":8749},{"type":27,"value":16834},". Users have access permission.",{"type":21,"tag":54,"props":16836,"children":16837},{},[16838],{"type":27,"value":16839},"When approval is enabled (see Section 8), submissions go into the pending queue. Certificates are issued once they are approved.",{"type":21,"tag":150,"props":16841,"children":16843},{"id":16842},"_102-recommended-by-the-ca-no-csr-required",[16844],{"type":27,"value":16845},"10.2 Recommended: By the CA (No CSR Required)",{"type":21,"tag":546,"props":16847,"children":16848},{},[16849,16859,16875,16891,16908],{"type":21,"tag":54,"props":16850,"children":16851},{},[16852,16853,16858],{"type":27,"value":10600},{"type":21,"tag":42,"props":16854,"children":16855},{},[16856],{"type":27,"value":16857},"Enroll > Make New Request",{"type":27,"value":9486},{"type":21,"tag":54,"props":16860,"children":16861},{},[16862,16863,16867,16869,16873],{"type":27,"value":13551},{"type":21,"tag":42,"props":16864,"children":16865},{},[16866],{"type":27,"value":8790},{"type":27,"value":16868}," (End Entity Profile) and ",{"type":21,"tag":42,"props":16870,"children":16871},{},[16872],{"type":27,"value":8797},{"type":27,"value":16874}," (Certificate Profile).",{"type":21,"tag":54,"props":16876,"children":16877},{},[16878,16879,16884,16886,16890],{"type":27,"value":15857},{"type":21,"tag":42,"props":16880,"children":16881},{},[16882],{"type":27,"value":16883},"Keypair generation",{"type":27,"value":16885}," to ",{"type":21,"tag":42,"props":16887,"children":16888},{},[16889],{"type":27,"value":8721},{"type":27,"value":9486},{"type":21,"tag":54,"props":16892,"children":16893},{},[16894,16896,16900,16902,16906],{"type":27,"value":16895},"Expand ",{"type":21,"tag":42,"props":16897,"children":16898},{},[16899],{"type":27,"value":8825},{"type":27,"value":16901}," and enter ",{"type":21,"tag":42,"props":16903,"children":16904},{},[16905],{"type":27,"value":8832},{"type":27,"value":16907}," (such as CN, email address, DNS, and IP address) as required.",{"type":21,"tag":54,"props":16909,"children":16910},{},[16911,16913,16918],{"type":27,"value":16912},"Download the ",{"type":21,"tag":141,"props":16914,"children":16916},{"className":16915},[],[16917],{"type":27,"value":8845},{"type":27,"value":16919}," file.",{"type":21,"tag":150,"props":16921,"children":16923},{"id":16922},"_103-optional-provided-by-user-uploading-a-csr",[16924],{"type":27,"value":16925},"10.3 Optional: Provided by user (Uploading a CSR)",{"type":21,"tag":531,"props":16927,"children":16928},{},[16929],{"type":21,"tag":36,"props":16930,"children":16931},{},[16932],{"type":27,"value":16933},"This option is used only when the key must be generated on the client or server for reasons like compliance, using an HSM or dedicated device, or migrating an existing key.",{"type":21,"tag":546,"props":16935,"children":16936},{},[16937,16942,16959],{"type":21,"tag":54,"props":16938,"children":16939},{},[16940],{"type":27,"value":16941},"Generate a private key and CSR locally.",{"type":21,"tag":54,"props":16943,"children":16944},{},[16945,16946,16950,16952,16957],{"type":27,"value":13551},{"type":21,"tag":42,"props":16947,"children":16948},{},[16949],{"type":27,"value":8884},{"type":27,"value":16951}," and paste the complete CSR, including ",{"type":21,"tag":141,"props":16953,"children":16955},{"className":16954},[],[16956],{"type":27,"value":8892},{"type":27,"value":16958},", into the text box.",{"type":21,"tag":54,"props":16960,"children":16961},{},[16962],{"type":27,"value":16963},"Submit the CSR and download the certificate as prompted (the private key is not included).",{"type":21,"tag":150,"props":16965,"children":16967},{"id":16966},"_104-approval-association-and-notification",[16968],{"type":27,"value":16969},"10.4 Approval Association and Notification",{"type":21,"tag":50,"props":16971,"children":16972},{},[16973,16984],{"type":21,"tag":54,"props":16974,"children":16975},{},[16976,16978,16982],{"type":27,"value":16977},"If a profile is bound to an ",{"type":21,"tag":42,"props":16979,"children":16980},{},[16981],{"type":27,"value":8918},{"type":27,"value":16983},", the profile will be pending approval upon submission. After the profile is approved, the profile will be automatically issued or available for download.",{"type":21,"tag":54,"props":16985,"children":16986},{},[16987],{"type":27,"value":16988},"The email subject and body comply with the notification requirements in Section 8.",{"type":21,"tag":150,"props":16990,"children":16992},{"id":16991},"_105-faqs",[16993],{"type":27,"value":16994},"10.5 FAQs",{"type":21,"tag":50,"props":16996,"children":16997},{},[16998,17008,17018,17033],{"type":21,"tag":54,"props":16999,"children":17000},{},[17001,17006],{"type":21,"tag":42,"props":17002,"children":17003},{},[17004],{"type":27,"value":17005},"Field failure",{"type":27,"value":17007},": The DN\u002FSAN is inconsistent with that in the profile. Adjust the DN\u002FSAN according to Section 9.",{"type":21,"tag":54,"props":17009,"children":17010},{},[17011,17016],{"type":21,"tag":42,"props":17012,"children":17013},{},[17014],{"type":27,"value":17015},"Unable to download P12",{"type":27,"value":17017},": Download is blocked by the browser, or password policies conflict. Use another browser or check the password length and character set.",{"type":21,"tag":54,"props":17019,"children":17020},{},[17021,17026,17028,17032],{"type":21,"tag":42,"props":17022,"children":17023},{},[17024],{"type":27,"value":17025},"CSR rejected",{"type":27,"value":17027},": The Subject\u002FSAN in the CSR conflicts with that in the profile. Rebuild the CSR using the profile or use ",{"type":21,"tag":42,"props":17029,"children":17030},{},[17031],{"type":27,"value":8721},{"type":27,"value":9486},{"type":21,"tag":54,"props":17034,"children":17035},{},[17036,17041],{"type":21,"tag":42,"props":17037,"children":17038},{},[17039],{"type":27,"value":17040},"Approval suspended",{"type":27,"value":17042},": The number of approvers does not meet the requirement, or the approver does not have the required permission. Check the status under Monitor > Approvals.",{"type":21,"tag":8981,"props":17044,"children":17045},{},[17046],{"type":27,"value":8985},{"title":7,"searchDepth":279,"depth":279,"links":17048},[17049,17050,17051,17052,17065,17094,17102,17116,17124,17135],{"id":9106,"depth":222,"text":9109},{"id":9129,"depth":222,"text":9132},{"id":9160,"depth":222,"text":9163},{"id":9182,"depth":222,"text":9185,"children":17053},[17054,17059,17060,17061,17062,17063,17064],{"id":9193,"depth":270,"text":9196,"children":17055},[17056,17057,17058],{"id":9211,"depth":279,"text":9214},{"id":9303,"depth":279,"text":9306},{"id":9388,"depth":279,"text":9391},{"id":9468,"depth":270,"text":9471},{"id":9529,"depth":270,"text":9532},{"id":10053,"depth":270,"text":10056},{"id":10088,"depth":270,"text":10091},{"id":10099,"depth":270,"text":10102},{"id":10500,"depth":270,"text":10503},{"id":10578,"depth":222,"text":10581,"children":17066},[17067,17068,17072,17073,17074,17075,17085],{"id":10584,"depth":270,"text":10587},{"id":10609,"depth":270,"text":10612,"children":17069},[17070,17071],{"id":10615,"depth":279,"text":10618},{"id":10646,"depth":279,"text":10649},{"id":10687,"depth":270,"text":10690},{"id":10795,"depth":270,"text":10798},{"id":10867,"depth":270,"text":10870},{"id":10984,"depth":270,"text":10987,"children":17076},[17077,17078,17079,17080,17081,17082,17083,17084],{"id":10990,"depth":279,"text":10993},{"id":11175,"depth":279,"text":11178},{"id":11322,"depth":279,"text":11325},{"id":11570,"depth":279,"text":11573},{"id":11858,"depth":279,"text":11861},{"id":11978,"depth":279,"text":11981},{"id":12091,"depth":279,"text":12094},{"id":12156,"depth":279,"text":12159},{"id":12432,"depth":270,"text":12435,"children":17086},[17087,17088,17089,17090,17091,17092,17093],{"id":12438,"depth":279,"text":10993},{"id":12582,"depth":279,"text":11178},{"id":12691,"depth":279,"text":11325},{"id":12890,"depth":279,"text":11573},{"id":13109,"depth":279,"text":13112},{"id":13197,"depth":279,"text":13200},{"id":13302,"depth":279,"text":13305},{"id":13387,"depth":222,"text":13390,"children":17095},[17096,17097,17098,17099,17100,17101],{"id":13393,"depth":270,"text":13396},{"id":13578,"depth":270,"text":13581},{"id":13780,"depth":270,"text":13783},{"id":13858,"depth":270,"text":13861},{"id":14020,"depth":270,"text":14023},{"id":14049,"depth":270,"text":14052},{"id":14081,"depth":222,"text":14084,"children":17103},[17104,17105,17106,17107,17108,17109,17110,17111,17112,17113,17114,17115],{"id":14095,"depth":270,"text":14098},{"id":14293,"depth":270,"text":14296},{"id":14506,"depth":270,"text":14509},{"id":14593,"depth":270,"text":14596},{"id":14749,"depth":270,"text":14752},{"id":15179,"depth":270,"text":15182},{"id":15261,"depth":270,"text":15264},{"id":15344,"depth":270,"text":15347},{"id":15397,"depth":270,"text":15400},{"id":15451,"depth":270,"text":15454},{"id":15519,"depth":270,"text":15522},{"id":15611,"depth":270,"text":15614},{"id":15707,"depth":222,"text":15710,"children":17117},[17118,17119,17120,17121,17122,17123],{"id":15713,"depth":270,"text":15716},{"id":15759,"depth":270,"text":15762},{"id":15846,"depth":270,"text":15849},{"id":15965,"depth":270,"text":15968},{"id":16058,"depth":270,"text":16061},{"id":16082,"depth":270,"text":16085},{"id":16111,"depth":222,"text":16114,"children":17125},[17126,17127,17128,17129,17131,17132,17133,17134],{"id":16129,"depth":270,"text":16132},{"id":16153,"depth":270,"text":16156},{"id":16277,"depth":270,"text":16280},{"id":16382,"depth":270,"text":17130},"9.4 Other Subject Attributes—(Setting by Users)",{"id":16464,"depth":270,"text":16467},{"id":16541,"depth":270,"text":16544},{"id":16587,"depth":270,"text":16590},{"id":16717,"depth":270,"text":16720},{"id":16782,"depth":222,"text":16785,"children":17136},[17137,17138,17139,17140,17141],{"id":16811,"depth":270,"text":16814},{"id":16842,"depth":270,"text":16845},{"id":16922,"depth":270,"text":16925},{"id":16966,"depth":270,"text":16969},{"id":16991,"depth":270,"text":16994},"content:en:blogs:pki-cert-service-guide.md","en\u002Fblogs\u002Fpki-cert-service-guide.md","en\u002Fblogs\u002Fpki-cert-service-guide","PKI Practice: Building a Complete Certificate Service System (openubmc.cn) 1. Introduction This tutorial provides a hands-on guide based on EJBCA, designed to compliance the CA\u002FRA workflow in a demo environment. It walks through key operational steps including certificate profile creation, end entity profile configuration, approval process activation, and RA certificate issuance and download. This tutorial focuses on practical execution, making it ideal for experiments, proof-of-concept (PoC) setups, or internal demonstrations. Please note that this tutorial does not cover production-level security hardening or compliance requirements. Objective : Master the core operations of EJBCA and complete the entire process from template configuration to certificate issuance.  2. Terms RA : registers end entities and reviews their identities. Certificate profile : presets key usages, SANs, and validity periods.  3. Experiment Environment and Prerequisites OS: Ubuntu 20.04 Server (installed offline) Software to be preset: Docker and docker-compose (apt package)  4. EJBCA Docker Deployment and Persistence This chapter explains how to deploy the EJBCA certificate service using Docker, with a focus on ensuring persistent data storage on a dedicated drive. This setup helps prevent data loss in the event of container or virtual machine restarts. Key topics cover configuring data persistence of the internal database (H2 by default), running containers using docke-compose, and setting up remote access through appropriate configuration parameters. 4.1 Environment Setup and Proxy Configuration Some EJBCA Docker images (such as  keyfactor\u002Fejbca-ce ) need to be pulled from the public network. To ensure environment availability, configure the HTTP\u002FHTTPS proxy of Docker Daemon. Step 1 Configure the systemd proxy. Docker Daemon runs under the systemd management. You need to add the following configurations to inherit the system proxy. sudo  mkdir  -p  \u002Fetc\u002Fsystemd\u002Fsystem\u002Fdocker.service.d\n sudo  nano  \u002Fetc\u002Fsystemd\u002Fsystem\u002Fdocker.service.d\u002Fhttp-proxy.conf\n Content: [Service]\n Environment=\"HTTP_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\n Environment=\"HTTPS_PROXY=http:\u002F\u002F192.168.xxx.xxx:7890\"\n Environment=\"NO_PROXY=127.0.0.1,localhost,192.168.13.119\" \u002F\u002F Change the IP address to the host IP address of your virtual machine.\n Step 2 Reload and restart Docker. sudo  systemctl  daemon-reload\n sudo  systemctl  restart  docker\n sudo  systemctl  status  docker  --no-pager  -l\n If the output contains  Active: active (running) , the proxy configuration takes effect. Step 3 Check whether the proxy has taken effect. docker  info  |  grep  -i  proxy\n If the following information is displayed, the proxy has taken effect: HTTP  Proxy:  http:\u002F\u002F192.168.xxx.xxx:7890\n HTTPS  Proxy:  http:\u002F\u002F192.168.xxx.xxx:7890\n 4.2 Data Persistence Configuration Save the H2 database in files, and set the database as follows:  jdbc:h2:\u002Fmnt\u002Fpersistent\u002Fejbcadb;DB_CLOSE_DELAY=-1 . Host mount path:  \u002Fopt\u002Fejbca-data:\u002Fmnt\u002Fpersistent Do not use  --rm  to start the container. Set the host permission:  chown -R 10001:10001 \u002Fopt\u002Fejbca-data 📌 Note: In a formal environment, it is recommended to use external database, such as PostgreSQL or MySQL, to improve system reliability and disaster recovery capabilities. Deployment Using Docker Compose Create a directory structure. mkdir  -p  \u002Fopt\u002Fejbca-compose\n cd  \u002Fopt\u002Fejbca-compose\n mkdir  -p  \u002Fopt\u002Fejbca-data\n chown  -R  10001:10001  \u002Fopt\u002Fejbca-data\n Create and compile  docker-compose.yml  in the current directory. version :  \"3.3\"  # Use Docker Compose v3.3.\n \n services :\n   ejbca :  # Define the service ejbca.\n     image :  keyfactor\u002Fejbca-ce:latest  # Use the latest EJBCA image (community-edition) provided by Keyfactor.\n     container_name :  ejbca  # Set the container name to ejbca.\n     hostname :  myejbca.test.local  # Set the internal host name of the container, which affects fields such as CN in the certificate.\n \n     environment :  # Set environment variables to configure the EJBCA startup behavior.\n       -  DATABASE_JDBC_URL=jdbc:h2:\u002Fmnt\u002Fpersistent\u002Fejbcadb;DB_CLOSE_DELAY=-1  # Use the embedded H2 database. The data is stored in the mount directory.\n       -  TLS_SETUP_ENABLED=true  # Enable automatic TLS settings (for HTTPS access).\n       -  SMTP_DESTINATION=192.168.xx.xx  # Set the SMTP email server address (for sending notification emails).\n       -  SMTP_DESTINATION_PORT=25  # Set SMTP service port. The default value is 25. (Encryption is disabled.)\n       -  SMTP_FROM=ejbca@example.local  # Set the email sender address.\n       -  SMTP_TLS_ENABLED=false  # Do not enable STARTTLS for SMTP.\n       -  SMTP_SSL_ENABLED=false  # Do not enable SSL\u002FTLS encryption for SMTP.\n \n     ports :  # Map the container port to the host.\n       -  \"80:8080\"  # Map the host port 80 to the container port 8080 (HTTP).\n       -  \"443:8443\"  # Map the host port 443 to the container port 8443 (HTTPS).\n \n     volumes :  # Mount the data volume to map the directory in the container to the host for data persistence.\n       -  \u002Fopt\u002Fejbca-data:\u002Fmnt\u002Fpersistent  # Mount the \u002Fopt\u002Fejbca-data directory on the host to the container to persist data such as the database.\n \n     restart :  unless-stopped  # If the container exits abnormally, the container is automatically restarted unless you manually stop the container.\n Start the container service.： docker-compose  up  -d\n docker-compose  logs  -f\n ⚙️ You can use Compose to easily manage configuration versions, facilitating team collaboration and version recovery. 4.4 Remote Access Configuration Set the container's hostname in advance, which affects CN of the TLS certificate. hostname :  myejbca.test.local\n 4.5 Certificate Trust Management After downloading the super administrator certificate ·, double-click to import it. 4.6 Login Process Summary Run  docker-compose logs -f  to search for SuperAdmin URL and one-time password in the container logs. ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *                                                                                                     *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *    URL:      https:\u002F\u002Fmyejbca.test.local:443\u002Fejbca\u002Fra\u002Fenrollwithusername.xhtml ? username = superadmin  *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *    Password: urAMy0He5c\u002FhHy+DYyDFNy4E                                                                *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *                                                                                                     *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *  Once the P12 is downloaded, use  \"urAMy0He5c\u002FhHy+DYyDFNy4E\"  to import it.                            *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  *                                                                                                     *\n ejbca     |  2025-08-05  09:11:31,656+0000  INFO   [\u002Fopt\u002Fkeyfactor\u002Fbin\u002Fstart.sh] ( process:1 )  ******************************************************************************************************\n Access the URL, enter the password, set the export password, and download the  .p12  certificate. Import the certificate and access  https:\u002F\u002Fmyejbca.test.local\u002Fejbca\u002Fadminweb . If the system displays a message indicating that the client certificate is not provided, check whether the certificate is successfully imported, the proxy is disabled, and the domain name is correctly resolved. ✅ So far, the EJBCA deployment, persistence, and management login process is completed. Important Notes (Must Be Followed) ✅  You must  add  myejbca.test.local  to the hosts file or set up a local DNS server. Otherwise, the browser may fail to resolve the domain name.  \n✅ The default algorithm for the super administrator certificate is DILITHIUM2, which may vary by version. However, Windows probably cannot recognize DILITHIUM2. To ensure compatibility, it is advised to switch the algorithm to RSA 4096.  \n✅  No proxy should be enabled . Otherwise, EJBCA may fail to correctly process client certificate authentication.  \n✅  Ensure that the Windows\u002FmacOS\u002FLinux certificate is correctly imported  to avoid the \" No client certificate was presented \" error.  \n✅  It is recommended that you use the Chrome browser in Incognito mode for the first time  to avoid the \" No client certificate was presented \" error caused by cache problems.  5. Initial CA Creation and Certificate Level Setup 5.1 Managing Certificate Profiles Log in to the EJBCA management console. Choose  CA Functions > Certificate Profiles . 5.2 Creating a Certificate Profile Method 1: Cloning an Existing Profile Find an appropriate profile (for example,  ENDUSER ) in the list. Click  Clone , enter the new name, and save the profile. Method 2: Manually Creating a Profile Click  Add  and enter the name. The editing page is displayed. Set necessary information as required, including  Key Usage ,  Extended Key Usage , validity period, and Subject DN. Save the settings and return to the list for check. 5.3 Creating a Crypto Token Choose  CA Functions → Crypto Tokens 。 Click  Create new  and enter the following information: Name ：Enter the name of your crypto token. Type ：Select  SOFT 。 Auto-activation(Optional) ：If selected, the crypto token can be automatically activated. Allow export of private keys ：Select  Allow  if you want to export the private key. Authentication Code ：Enter the authentication code and confirm it.  dd if=\u002Fdev\u002Frandom bs=1 count=128 2>&1| sha256sum | awk '{print $1} Save the settings and ensure that the status is  Active  in the list。 5.4 Generating a Key Pair Access the x Crypto Token  details page. Enter the key name, for example,  signKey , in  Crypto Token currently does not contain any key pairs . Select a key algorithm, for example,  RSA 4096 . Click  Generate new key pair . Note : The default profile cannot be modified. You need to clone it before creating a new one. 5.5 Creating a CA Choose  CA Functions → Certification Authorities 。 The default  ManagementCA (Active)  is displayed in the list on the top.  You do not need to select it 。 Scroll to the  Add CA  area at the bottom of the page.\n Enter the new CA name, for example,  DemoCA , in the text box. Click  Create…  on the right. The CA configuration wizard is displayed. Enter necessary fields on the  Create CA  page. Click  Create  at the bottom to save the CA. If the configuration is correct, the CA list is displayed and the  DemoSubCA (Active)  status is displayed. (Optional) If you want to manually upload the certificate issued by the root CA, select the new CA in the list and select  Import CA certificate…  to upload the chain file. The intermediate CA is created. You can use it to issue end-entity certificates. 5.6 (Example) Creating a Root CA 1️⃣ CA type and key configuration Parameter Description CA Type ✅  X.509 CA ; Standard X.509 CA Crypto Token ✅ Select the created  Crypto Token , for example,  demoCrypto . Signing Algorithm ✅  SHA256WithRSA ; Secure signature algorithm Alternative Signing Algorithm ❌  None ; No backup signature algorithm is required. Key Sequence Format ✅  Numeric (0-9) ; Serial number of the CA certificate Key Sequence ✅  00000  ; Initial serial number, which can be changed. Description ✅ Root CA description, including the purpose and management unit.  2️⃣ Certificate policies (Directives) Parameter Description Enforce unique public keys ✅ Enforces the public key to be unique. Enforce key renewal ❌ Not required for the root CA. Enforce unique DN ✅ Ensures  DN  uniqueness (applicable to small-scale CAs). Enforce unique Subject DN SerialNumber ❌ Applicable only to large-scale CAs (not required for CAs with fewer than 20 certificates). Use Certificate Request History ❌ Records certificate request history (not required for the root CA). Use User Storage ✅ Stores user information. Use Certificate Storage ✅ Stores issued certificates.  3️⃣ CA certificate data Parameter Description Subject DN ✅  CN=test EnterpriseIT Root CA Signed By ✅  Self Signed ; Root CA must be self-signed. Certificate Profile ✅  ITROOTCA_profile ; Select the cloned root CA.   This parameter can be modified. Validity ✅  20y ; The certificate validity period is 20 years. Subject Alternative Name ❌ Not required for the root CA. Certificate Policy OID ❌ (Optional) By default, this parameter is left blank. Use UTF-8 in policy notice text ✅ Ensures international character support. PrintableString encoding in DN ❌ Do not select this parameter to avoid affecting internationalization. LDAP DN order ✅ Ensures that  DN  is sorted according to the LDAP specifications. Serial Number Octet Size ✅  20 ; 20-byte is recommended to ensure uniqueness. Name Constraints, Permitted ❌ Disabled for the root CA. Leave this parameter empty. Name Constraints, Excluded ❌ Disabled for the root CA. Leave this parameter empty.  4️⃣ CRL configuration Parameter Description Microsoft CA Compatibility Mode ❌ Disabled for the root CA. This parameter is applicable only to Windows AD CS. Authority Key ID ✅ Enabled and marked as  Critical . This parameter is used to identify the CRL issuer. It is recommended that it be enabled for the root CA and intermediate CA. CRL Number ✅ Enabled and marked as  Critical . This parameter is used to ensure that the CRL version is unique. It is recommended that it be enabled for the root CA and intermediate CA. Issuing Distribution Point on CRLs ❌ Disabled for the root CA. This parameter is applicable only to large-scale CAs with hierarchical CRL structures. CA issuer URI ❌ Left empty. Users provide this URI during final certificate download stage. Keep expired certificates on CRL ❌ Disabled for the root CA. Determine if this parameter should be enabled for the intermediate CA based on actual requirements. After this parameter is enabled, the certificate is still displayed in the CRL even if it expires. Use CRL partitions ❌ Not required for the root CA due to its low load. This parameter is applicable to CA that manages a large number of certificates. CRL Expire Period ✅  30d . Set the period to a longer one for the root CA and to a shorter one for the intermediate CA. CRL Issue Interval ✅  7d . Periodically updates the CRL. It is recommended that the active CA use  7d . CRL Overlap Time ✅  12h . The old CRL and new CRL overlap for 12 hours to prevent certificate verification failures. Delta CRL Period ❌  0m . Delta CRL is not used for the root CA. It is enabled only for CAs that require high real-time performance. Generate CRL Upon Revocation ❌ Disabled for the root CA, and enabled for the intermediate CA as required. A new CRL is generated immediately after a certificate is revoked. Allow changing revocation reason ✅ Enabled. This parameter allows to change the reason for certificate revocation. It is applicable to all CAs. Allow invalidity date ✅ Enabled. This parameter allows to set the certificate invalidity date. It is applicable to all CAs.  5️⃣ Approval settings Parameter Description Add\u002FEdit End Entity ❌ None . Root CA does not manage end entities. Key Recovery ❌ None . Root CA does not provide key recovery. Revocation ❌ None . Root CA rarely revokes its own certificates. CA Service Activation ❌ None . Root CA is manually activated.  6️⃣ Other data Parameter Description Validators ✅  Finish User . Enable the certificate verification policy. CMP RA Authentication Secret ❌ Leave this parameter empty. This parameter needs to be configured only when the CMP protocol is used. Monitor if CA active (healthcheck) ✅  Activate . Enable CA running monitoring, which applies to all CAs. Request Processor ❌  None . Root CA usually does not need to process external requests.  7️⃣ Creation\u002FRenewal of Externally Signed CAs Parameter Description Renew CA ❌ Creates a new root CA instead of regenerating the key and re-signing the existing CA. This avoids problems caused by root CA certificates with the same name. CA Chain Certificates ✅ Uploads the certificate chain file (in PEM\u002FDER format) only when the CA is signed externally. If the root CA has been installed locally, you do not need to upload the file.  8️⃣ CA Creation After confirming all parameters are correct, click  Create  to generate a CA. 1. Download and verify the root CA certificate. Run the following OpenSSL commands to verify the certificate format and validity: # Verify PEM certificates.\n openssl  x509  -in  rootca.pem  -text  -noout\n \n # Verify DER certificates.\n openssl  x509  -in  rootca.der  -inform  DER  -text  -noout\n \n # Check the certificate's SHA256 fingerprint information.\n openssl  x509  -noout  -fingerprint  -sha256  -in  rootca.pem\n \n # Verify the self-signed certificate validity.\n openssl  verify  -CAfile  rootca.pem  rootca.pem\n 2. Deploy and verify the CRL. If the CRL URL is configured, run the following command: # Verify the CRL file.\n openssl  crl  -in  rootca.crl  -text  -noout\n Ensure that the CRL can be accessed through the web. 🚀  The root CA has been created and can be used to issue intermediate CAs!  🎉 5.7 Creating an Intermediate CA Certificate 1️⃣ CA type and key configuration Parameter Description CA Type ✅  X.509 CA ; Standard X.509 CA Crypto Token ✅ Select the created Crypto Token, for example,  demoCrypto . Signing Algorithm ✅  SHA256WithRSA ; Secure signature algorithm Alternative Signing Algorithm ❌  None ; No backup signature algorithm is required. Key Sequence Format ✅  Numeric (0-9) ; Serial number of the CA certificate Key Sequence ✅  00001 ; Initial serial number, which should be different from that of the root CA. Description ✅ Intermediate CA description, including the purpose and management unit.  2️⃣ Certificate policies (Directives) Parameter Description Enforce unique public keys ✅ Enforces the public key to be unique. Enforce key renewal ✅ Recommended to be enabled for intermediate CAs to ensure security. Enforce unique DN ✅ Ensures the DN to be unique. Enforce unique Subject DN SerialNumber ❌ Not required when the number of certificates is fewer than 20. Use Certificate Request History ✅ Records certificate request history. Use User Storage ✅ Stores user information. Use Certificate Storage ✅ Stores issued certificates.  3️⃣ CA certificate data Parameter Description\u002FExample Value Subject DN ✅  CN=test Intermediate CA   Signed By ✅  test EnterpriseIT Root CA  The intermediate CA must be signed by the root CA. Certificate Profile ✅  INTERMEDIATE_CA_profile  Configured for the intermediate CA after cloning. Validity ✅  10y  Generally, the validity period is 10 years, which is shorter than that of the root CA. Subject Alternative Name ❌ Not required for the intermediate CA. Certificate Policy OID ❌ Leave this parameter empty by default or enter a value as required. Use UTF-8 in policy notice text ✅ Ensures international character support. PrintableString encoding in DN ❌ Do not select this parameter to avoid affecting internationalization. LDAP DN order ✅ Arranges the DN according to LDAP specifications. Serial Number Octet Size ✅  20  20-byte is recommended. Name Constraints, Permitted ❌ Disabled by default. Leave this parameter empty. Name Constraints, Excluded ❌ Disabled by default. Leave this parameter empty.  4️⃣ CRL configuration Parameter Description Microsoft CA Compatibility Mode ❌ Disabled, typically. This parameter is used only in the Windows AD environment. Authority Key ID ✅ Enabled and marked as Critical. CRL Number ✅ Enabled and marked as Critical. Issuing Distribution Point on CRLs ❌ Disabled, typically. CA issuer URI ❌ Leave this parameter empty or enter a download address as required. Keep expired certificates on CRL ❌ Recommended to be enabled for the intermediate CA and retain expired certificates. This parameter is disabled currently; otherwise, the CRL size will become large. Use CRL partitions ❌ Not required, typically. CRL Expire Period ✅  7d  7-day is recommended to ensure timely update. CRL Issue Interval ✅  1d  The CRL is issued every day to ensure timely update. CRL Overlap Time ✅  12h  The new CRL overlaps with the old CRL for 12 hours to ensure smooth transition. Delta CRL Period ❌  0m  Delta CRL is not used. Generate CRL Upon Revocation ✅ Enabled. The CRL is updated immediately after the certificate is revoked. Allow changing revocation reason ✅ This parameter allows to change the reason for certificate revocation. Allow invalidity date ✅ This parameter allows to set the certificate invalidity date.  5️⃣ Default CA defined validation data Parameter Description Default CRL Distribution Point ❌ Leave this parameter empty or enter a value as required to distribute CRLs. Default CRL Issuer ❌ Leave this parameter empty. Typically, this parameter does not need to be set. Default Freshest CRL Distribution Point ❌ Leave this parameter empty. Typically, this parameter does not need to be set. OCSP Service Default URI ❌ Leave this parameter empty or enter an OCSP address as required. CA Issuer Default URI ❌ Leave this parameter empty or provide a URI later.  6️⃣ Approval settings and other data Currently, only  None  is available for approval settings, indicating that no additional approval process is required. If it is required, check the global approval policy Supervision Functions of EJBCA. Parameter Description Validators ✅  Finish User . Enable the certificate verification policy. CMP RA Authentication Secret ❌ Leave this parameter empty. This parameter needs to be configured only when the CMP protocol is used. Monitor if CA active (healthcheck) ✅  Activate . Enable running monitoring. Request Processor ❌  None . Generally, external request processing is not required.  7️⃣ Intermediate CA creation After confirming all parameters are correct, click  Create  to generate a CSR. Submit the CSR to the root CA for signature, download the signed certificate, and verify it. openssl  x509  -in  intermediate_ca.pem  -text  -noout\n openssl  verify  -CAfile  rootca.pem  intermediate_ca.pem\n 🚀 The intermediate CA has been created and can be used to issue end entity certificates! 🎉  6. RA Common User Creation and Permission Configuration 6.1 Creating an RA Role Access the RA Web page  and choose Role Management > Roles > Create New Role. Role Management →Roles →Create New Role\n Enter role information. ： Field Recommended Value Namespace No namespace Role name test RA Users Set the permissions for Certificate Authorities. ： Select a CA, for example,  Intermediate CA  or Root CA, from the Available list and click  Add . Set the permissions for End Entity. (Recommended): ✅ Create end entities ✅ Create certificates ✅ ...by using username and password ✅ ...by using a request ID ✅ View end entities and certificates Set the permissions for End Entity Profiles. ： Select  EMPTY  from the Available list and click  Add . Click  Add  to save the created role. 6.2 Creating an RA Commer User (End Entity) Access the  EJBCA Admin Web  page and choose  RA Functions > Add End Entity . Enter the user details. Field Recommended Value End Entity Profile EMPTY Username test_signuser Password 123 Confirm Password 123 Batch generation Not selected E-mail cert-user@example.com CN test RA user S1 O test C CN Certificate Profile ENDUSER CA test Intermediate CA Token P12 file Click  Add . End Entity is created. 6.3 Downloading the User Certificate Access the  RA Web  page and choose  Enroll > Use Username . Use the created username and password to log in. Username:  test_signuser Password:  123 Select a key algorithm after logging in. Select the  RSA 4096  algorithm, and generate and download the  .p12  user certificate. 6.4 Adding a User to the RA Role Access the  RA Web  page and choose  Search > End Entities . Copy the CN of the certificate created earlier. Access the  RA Web  page and choose  Role Management > Roles > Members > Add Role Member . Enter the information about the role member. Field Recommended Value Role test RA Users Token Type Certificate CA test Intermediate CA Match with CN Common Name Match Value Paste the copied certificate CN. Description RA common user Click  Add  to add the role member. Restart the EJBCA service  for the permission to take effect (recommended). docker restart ejbca 6.5 Logging In to the RA WebUI Non-administrator  roles import the downloaded · certificate to the browser. Access the RA Web page for automatic authentication and login. Perform authorized RA operations, such as creating and viewing certificates. 6.6 Important Notes (Must Be Followed) ✅ You are advised to use the Chrome browser in incognito mode for the first login to quickly start the verification and avoid the error \"No OAuth providers configured. Please log in using a valid certificate\" caused by cache problems. ✅  Use HTTPS  to access, for example,  https:\u002F\u002F192.168.xxx.xxx\u002Fejbca\u002Fra\u002F , to avoid the error \"No OAuth providers configured. Please log in using a valid certificate.\"  7. Certificate Profile Settings This section describes the meanings and recommended usage of the Certificate Profile configuration items in the EJBCA. It is applicable to certificate issuance requirements for common devices such as HTTPS, web, device, and client.  7.1 Basic Information Configuration Item Description Certificate Profile ID Unique identifier of the profile in the database, which is used only for internal identification. Type Available end entity, subordinate CA, and root CA. Available Key Algorithms Available key algorithms, such as RSA, ECDSA, Ed25519, and DILITHIUM. Available ECDSA curves Available ECDSA curves. No curve is enabled currently. Available bit length Key size supported (for RSA), such as 2048 and 4096. Signature algorithm Signature hash algorithm used for certificate issuance, for example, SHA3-256withRSA. Alternative Signature Whether to enable the alternative signature algorithm, such as ECDSA and EdDSA. End date or end date of the certificate Default validity period. For example, \"2y\" indicates two years. Validity Offset Offset of the issue date. The start time can be set forward or backward. Expiration Restrictions Maximum expiration time, which is used for compliance control. Profile Description Certificate profile description, which is used to note the purpose (for example, \"terminal device certificate\").  7.2 Permissions Control Configuration Item Description Recommended Setting Allow Validity Override Allow the default validity period to be overwritten when a certificate is issued. ✅ which is used when the validity period needs to be manually adjusted. Allow Expired Validity End Date Allow the end time to be set to an expired time (for test or audit). ✅ (for debugging) Allow Extension Override Allow the extension fields in the CSR to overwrite the predefined extension fields in the profile. ❌ Enabling this function can harm profile uniformity and create potential risks. Allow certificate serial number override Allow the certificate serial number to be customized during issuance. ❌ Enable this function only under specific circumstances (for example, for certificate cloning and replacement). Allow Subject DN Override by CSR Allow the subject information (such as CN\u002FO) in the CSR to overwrite the profile configuration. ✅ which is applicable to the automatic issuance process. Allow Subject DN Override by End Entity Information Allow the subject field to be specified based on the end entity information (user input). (Recommended) ✅, which provides high flexibility. Allow Key Usage Override Allow the keyUsage field in the CSR to overwrite the profile configuration. ❌ Enabling this function creates inconsistencies that compromise security. Allow Backdated Revocation Allow the revocation time to be set to a historical time for retrospective revocation. ✅ which is required in some audit\u002Fcompliance scenarios. Use Certificate Storage Enable the certificate to be stored in the database. This item must be enabled unless it is used for special offline purposes. ✅ Store Certificate Data Store the complete original certificate data (used with OCSP\u002FCRL). ✅ It is recommended that this function be enabled together with the storage function. ✅ Suggestion:  Keep profiles consistent in the production environment. Disable override permissions unless needed to stop CSR or End Entities from making unauthorized changes.  7.3 X.509v3 Extension—Basic Information Extension Item Description Recommended Setting Basic constraints Must be a CA certificate (the value must be FALSE for end entity certificates) ✅ Enabled; key setting CA key identifier Information about the CA that issues the certificate. ✅ Enabled Subject key identifier Unique ID of the certificate. ✅ Enabled  7.4 X.509v3 Extension—Key Usage Item Description digitalSignature Used for signature verification, such as identity authentication and code signature. nonRepudiation Indicates that the signature is non-repudiable (legal scenario). dataEncipherment Used to encrypt non-key data. keyEncipherment Used to encrypt key materials, such as symmetric keys. keyAgreement Key negotiation protocol (such as DH) cRLSign Used by the CA to sign CRLs. keyCertSign Used by the CA to sign certificates. encipherOnly Used with keyAgreement (only for encryption). decipherOnly Used with keyAgreement (only for decryption). Forbid encryption usage for ECC keys Forbids encryption usage for ECC keys. 7.5 X.509v3 Extension—Extended Key Usage Extended Key Usage Description TLS client TLS authentication on the client TLS server TLS authentication on the server EAP over LAN (EAPOL) Enterprise identity authentication EAP over PPP Point-to-Point Protocol (PPP) identity authentication ETSI TSL Signing ETSI TSL signing ICAO Deviation List Signing ICAO signing ICAO Master List Signing ICAO primary list signing Intel AMT management Dedicated to Intel management certification Internet Key Exchange for IPsec IPsec key exchange Kerberos Client Authentication Kerberos client authentication Kerberos KDC Kerberos key center MS CA Key Exchange Microsoft CA key exchange MS Commercial Code Signing Microsoft commercial code signing MS Document Signing Microsoft document signing MS EFS Recovery Microsoft EFS recovery MS Encrypted File System Microsoft encrypted file system MS Individual Code Signing Microsoft individual code signing MS Smart Card Sign-in Microsoft smart card login authentication OCSP Issuer Online Certificate Status Protocol (OCSP) signing certificate PDF Signing PDF signing PIV Card Authentication PIV card authentication RFC9336 Document Signing RFC9336-compliant document signing SCVP Client Simplified Certificate Verification Protocol (SCVP) client SCVP Server SCVP server SIP Domain VoIP\u002FSIP domain name authentication SSH Client SSH client authentication SSH Server SSH server authentication codeSigning Software\u002FDriver signing Any EKU Common EKU support emailProtection S\u002FMIME email signing\u002Fencryption clientAuth TLS client authentication timeStamping Timestamp signing serverAuth Server identity authentication (HTTPS, etc.) 7.6 Name Extension Item Description Suggestion Subject Alt Name IP address, DNS, and Uemail can be used as certificate identifiers. ✅ Enabled Issuer Alternative Name Additional CA name.\tOptional Optional Name Constraints Constraints for subject namespaces. Optional (used in high-security scenarios) 7.7 Validation Data Item Description Suggestion CRL Distribution Point CRL URL ✅ Enabled; key setting Delta CRL（Freshest CRL） Incremental CRL Enable on demand Authority Information Access (AIA) OCSP\u002FCA information ✅  7.8 Private Key Validity Period Item Description Start Offset Start offset time of the private key Period Length Validity period of the private key (independent of the certificate validity period)  7.9 ETSI Compliant Extensions (Typically for High-compliance PKI Use Cases) Item Description Certifications Statement Identifies certificates used for legal or compliance purposes. Assured validity Ensures the validity of short-term certificates.  7.10 Other Extensions Extension Usage OCSP No Check Disables OCSP check (useful only for OCSP responders). Microsoft Profile Value\tSpecial extensions for Windows AD integration CA\u002FB Forum OID Identifier extension for CA\u002FB-compliant organization  7.11 Approval Settings and Additional Fields Configuration Item Description Add\u002FEdit End Entity Bound approval process Key Recovery Whether key recovery is supported (for example, for backup and restoration) Revocation Approval Whether approval is required for revocation CN Suffix A character string automatically added to the end of Subject CN Subject Subset Restriction Restriction on the Subject fields that can be used  7.12 CA & Release Settings Item Description Available CA CA that can use the certificate profile Publisher Publishing to LDAP, databases, or external services Single Certificate Limit Whether an end entity can have only one valid certificate Account Binding Namespace Device account binding (for example, IoT)  To configure the code signing certificate profile, adjust the keyUsage and extendedKeyUsage fields. 📌 You are advised to create different profiles for different applications (such as VPN, HTTPS, code signing, and client authentication) to facilitate management and compliance control.  8. Approval Configuration and Management 8.1 Creating an Approval Profile (Approval Configuration) Choose  Watchdog > Approval Profiles . Type a name (for example,  test ) at the bottom and click  Add . Click  Edit  in the list to enter the detailed settings. 8.2 Basic Parameter Settings Field Suggestion\u002FExample Approval Profile Type Accumulative Approval Partitioned Approval (can be used in cross-department cases) Request Expiration Period 8h (The request will be voided if not approved within the expiration period.) Approval Expiration Period 8h (Re-approval is required after the expiration period.) Max Extension Time 0d (The period cannot be extended.) Allow Self Approved Request Editing Deselected (Self-approval is prohibited in production.) 8.3 Approval Steps Set  Number of Required Approvals . Development\u002FTest:  1  (1-of-1). Production\u002FSensitive operations:  2  (2-of-2) or partitioned approval. Notification email: Notification message email recipient :  approval-admin-group@example.org supervisor@example.org Notification message email sender :  no-reply@192.168.xxx.xx Example theme profile:\n [AR-${approvalRequest.ID}-${approvalRequest.STEP_ID}-${approvalRequest.PARTITION_ID}] Approval Request\n Variables that can be referenced in the body:  ${approvalRequest.TYPE} ,  ${approvalRequest.REQUESTOR} , and  ${approvalRequest.WORKFLOWSTATE} . 8.4 Binding to a Specific Action End Entity Profile: Choose  CA Functions > End Entity Profiles >   > Approval Settings>  Add\u002FEdit End Entity to be approved > Approval Profile and then click  Save . Common options:  Add\u002FEdit End Entity  and  Key Recovery  (if enabled) Certificate Profile: Choose  CA Functions > Certificate Profiles >   > Approval Settings > Operation > Approval Profile  and then click  Save . Sensitive administrator actions : It is recommended that 2-of-2 or partitioned approval be used for intermediate CA change and revocation. 8.5 Testing and Verification Use a common RA account to start an operation (for example, creating an end entity) that requires approval on the RA WebUI. Choose Inspector Function > Approvals to check the approval queue, and use another approver account to complete the approval. Confirm that the operation was executed automatically and the email notification was received successfully. 8.6 FAQs No email received: Check the SMTP configuration, firewall, and recipient name, and view container logs. Stuck in pending status: Number of Required Approvals is set too high or the approver does not have the permission. Can be self-approved: Allow Self Approved Request Editing is selected by mistake. This function should be disabled in production. Expired: Request\u002FApproval Expiration is set too short. The value can be changed to 8h to 24h. 9. End Entity Profile Settings Path:  RA Functions > End Entity Profiles . The End Entity Profile defines the fields that can be populated, specifies which are mandatory or modifiable, and determines the default Certificate Profile, CA, and Token. 9.1 Creating and Opening an End Entity Profile Choose RA Functions > End Entity Profiles. Enter the profile name (for example, test) at the bottom and click Add Profile. Select the profile from the list and click Edit Endpoint Entity Profile. 9.2 Basic Information (Username\u002FPassword\u002FEmail) Generally, the  username\u002Fpassword  does not need to be specified in the profile. The profile only sets the rules and methods. The  username\u002Fpassword\u002Fenrollment code  can be specified  during end entity creation or application submission . Recommended practice Username: Select Auto-generated (for auto and batch operations), or manually specify the username when creating an end entity. Password (or Enrollment Code): Select Required to use the one-off Enrollment Code. Enter the specific value when creating an end entity or submitting the application on the RA. Minimum password strength\u002Flength: Retain the policy (for example, the length is greater than or equal to 8), but do not enter the specific password. Maximum number of failed login attempts: Set the number as needed. Select Modifiable if you need to temporarily change this limit. Batch generation: Disable this function. Avoid storing enrollment codes in plaintext. E-mail: Set it based on the Required\u002FModifiable setting. It is used for notification and identification. Impact of different application paths on username\u002Fpassword RA Web > Enroll > Use Username: Username and Password\u002FEnrollment Code are specified when an end entity is created. The user uses this account to log in to the system and obtain the certificate. RA Web > Enroll > Use Request ID: The system allocates Request ID. Password\u002FEnrollment Code is set when the request is created. The applicant uses the ID and code to obtain the certificate. User Generated (CSR): Token=User Generated. Retain Required to generate a one-off code. The applicant uses the CSR and code to complete the issuance. Directives Reverse Subject DN and Subject Alt Name Checks: You can also deselect this option. Allow merge DN for all interfaces: Generally, this option is not selected. It is selected only when DN combination is required for multiple APIs. Allow multi-value RDNs: This option is selected only when special requirements are met. (It is disabled by default, which is more secure.) 9.3 Subject DN Attributes—(Setting by Users) Available attributes are displayed on the left, and selected attributes are displayed on the right. Add the required fields to the right and set  Required\u002FModifiable\u002FValidation  for each field. Common recommendations (client\u002Fgeneral): Field Suggestion CN, Common name Required; Modifiable is determined by the RA. emailAddress, E-mail address in DN Optional. To bind with the email system, set it to Required. O, Organization \u002F OU, Org. Unit Service-dependent. You are advised to disable Modifiable to prevent arbitrary input. C, Country The value is fixed to CN or the country where the user is located. Generally, the value cannot be changed. If stricter verification is required, you can specify a regular expression or format rule in  Validation . 9.4  Other Subject Attributes —(Setting by Users) Subject Alternative Name (SAN) : Client certificate: RFC 822 Name (e-mail address) (same as the account email address) Server certificate: DNS Name and IP Address (added by domain name\u002FIP address) Device certificate: OtherName (written into the device ID\u002FOID) (Optional) ** Subject Directory Attributes: Attributes such as  Date of birth (YYYYMMDD)  are used only for archiving or compliance needs. You are advised not to enable multiple directory attributes. Addition method: Select an item in the  Other Subject Attributes  area and click  Add . You can also mark it as  Required\u002FModifiable  if supported by the interface. 9.5 Main Certificate Data Field Suggestion\u002FDescription Default Certificate Profile Select a certificate profile (for example, ENDUSER or SERVER). Available Certificate Profiles Select only the allowed profiles. Default CA \u002F Available CAs Specify the CAs that can issue the certificate. Note: Changing the available CAs impacts which roles can access the profile. Default Token \u002F Available Tokens P12 file (downloaded directly on the RA) or User Generated (CSR created by the user) 9.6 Other Certificate Data Custom certificate serial number : disabled by default Certificate Validity Start\u002FEnd Time : controlled by Certificate Profile by default. If a temporary certificate is required, enable this item and select Modifiable. Name Constraints (Permitted\u002FExcluded) : used for intermediate CAs. Generally, this item is disabled in end entity profiles. Custom certificate extension data \u002F ETSI PSD2 QC Statement \u002F CA\u002FB Forum Organization Identifier : Enable it as required for compliance. 9.7 Other Data\u002FRestrictions Field Suggestion Number of allowed requests 1  (preventing repeated issuance) Allow renewal before expiration Example:  30  days.  -1  indicates no limit. Revocation reason to set after certificate issuance Active  by default (typically left unchanged) Redact Subject Name from logs Enable this feature only for strict privacy or compliance needs. Send Notification Enable it when needed for SMTP settings. 9.8 Saving and Authorization Click  Save . Choose  RA Web > Role Management  and check that the related role has been authorized to use the end entity profile (visible\u002Fcreatable). Choose  Search > End Entities  and use the profile to create a test user to check the following:\n Check whether the DN\u002FSAN is added to the database according to the rules. Check whether the certificate uses the expected  Certificate Profile\u002FCA\u002FToken . Check whether the download or import is successful (P12\u002FPEM\u002FCSR process).  10. Applying for an End Entity Certificate as an RA Common User Choose  RA Web → Enroll 。 By default, you are advised to use  By the CA  (the CA generates the key) for stability and fewer errors; no CSR is needed. 10.1 Path and Prerequisites Profiles have been prepared in  End Entity Profiles  (Section 9) and  Certificate Profiles . Users have access permission. When approval is enabled (see Section 8), submissions go into the pending queue. Certificates are issued once they are approved. 10.2 Recommended: By the CA (No CSR Required) Choose  Enroll > Make New Request . Select  Certificate Type  (End Entity Profile) and  Certificate subtype  (Certificate Profile). Set  Keypair generation  to  By the CA . Expand  Provide request info  and enter  Subject DN \u002F SAN  (such as CN, email address, DNS, and IP address) as required. Download the  *.p12  file. 10.3 Optional: Provided by user (Uploading a CSR) This option is used only when the key must be generated on the client or server for reasons like compliance, using an HSM or dedicated device, or migrating an existing key. Generate a private key and CSR locally. Select  Provided by user  and paste the complete CSR, including  BEGIN\u002FEND CERTIFICATE REQUEST , into the text box. Submit the CSR and download the certificate as prompted (the private key is not included). 10.4 Approval Association and Notification If a profile is bound to an  Approval Profile , the profile will be pending approval upon submission. After the profile is approved, the profile will be automatically issued or available for download. The email subject and body comply with the notification requirements in Section 8. 10.5 FAQs Field failure : The DN\u002FSAN is inconsistent with that in the profile. Adjust the DN\u002FSAN according to Section 9. Unable to download P12 : Download is blocked by the browser, or password policies conflict. Use another browser or check the password length and character set. CSR rejected : The Subject\u002FSAN in the CSR conflicts with that in the profile. Rebuild the CSR using the profile or use  By the CA . Approval suspended : The number of approvers does not meet the requirement, or the approver does not have the required permission. Check the status under Monitor > Approvals. html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html .sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}html.sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}",[15],[17148,17148],null,1784971460899]