Client Certificates

The final step in the enrollment workflow is to migrate the user to the secure network and assign a certificate to the user device. This section describes how to specify which certificate template to use when assigning a client certificate to the user device.

You can set up different certificate templates for different user types. An employee or staff certificate template might be valid for 120 days, and a guest template might be valid for 1 day or until the end of the week.

After you set up a device configuration for the workflow, you can configure and assign a new certificate template.

  1. Select A new certificate template.
  2. Select Use an onboard certificate authority.
  3. Select Use an existing CA. Choose the default Root CA that was created during the initial system setup.
  4. Set up the Client certificate template. This template is used to issue a certificate to the client device.

    Client Certificate Template

  5. Select or enter a Username Decoration. The decoration of the username within the certificate allows RADIUS policies to be applied appropriately.

    The domain for the Username Decoration fields is taken from the Company Information that was entered during the initial account setup. Go to Administration > Company Information to change the default domain.

  6. Grant access for the appropriate amount of time.
    For example, you might have a client certificate template for a guest user that is valid for one, or a few days, another for a contractor that is valid for 6 months, and one for employees that is good for a year.
    Note: To configure pattern attributes, certificate strength, and EKUs, check the Configure Advanced Options box before you click Next.
  7. Select any email notifications to be sent to the user related to the life-cycle of the certificate.
    Additional certificate notifications can be configured after the template is created.
  8. Optional. Enter RADIUS Options to assign a VLAN ID or Filter ID to certificates that use this template. These settings only applies if you are using the Cloudpath onboard RADIUS server.
  9. Click Next. The completed workflow shows all enrollment paths. The last step shows the device configuration which is applied to the user device and the certificate template being used to assign a certificate to the user device.

    Completed Workflow

After you have finished configuring a enrollment workflow, create and deploy a snapshot of the workflow configuration to test before deploying to users.