Entrust PKI as a Service

Certifying a CA with an external root CA

After Creating an intermediate subordinate CA or Creating an issuing subordinate CA, follow the steps below if the parent CA is a root external CA.

To certify a CA with an external root CA:

  1. Follow the steps described in Accessing your partitions to log into the PKIaaS interface as a user with any of these roles:

  2. Click Certificate Authorities in the sidebar.

    PNG

  3. In the CA grid, select the name of the intermediate or issuing CA.

  4. Click the three dots to the right of the CA name.

    PNG

  5. Select Download Certificate Request to download the Certificate Signing Request (CSR) generated for the subordinate CA.

  6. Issue the subordinate CA certificate by signing the downloaded CSR with the private key of the external root CA. Make sure this certificate meets the RFC5280 requirements – for example:

    • The certificate includes the Basic Constraints extension with the ca boolean set to TRUE.
    • The certificate includes the Key Usage extension with the keyCertSign bit set.
    • The certificate includes other enabled bits, such as cRLSign for signing Certificate Revocation Lists (CRLs).
  7. Select Import Issuing Certificate Authority to upload the subordinate CA certificate.