Requirements for Requesting a Certificate

The following requirements must be satisfied before a requester can request a certificate.

  • The requester must have at least one appropriate key pair (for example, an EC key pair). This key pair is used to sign the SCEP pkiMessage, which must be completed before a certificate can be issued.
  • The following information must be configured locally on the requester (client).
    • The CA IP address, or fully qualified domain name (FQDN).
    • The CA HTTP Computer Gateway Interface (CGI) script path.
    • The identifying information used to authenticate the CA. This information can be obtained from the user or provided (presented) to the end user for manual authorization during the exchange.
    • The one-time challenge password that is sent as part of the Certificate request. This password is used by the CA to validate the local certificate request before signing.
Note: Multiple independent configurations that contain this information can be maintained by the requester, if needed, to enable interactions with multiple CAs.