Issue a New Server Certificate from a CSR
The following covers how to issue a certificate suitable for SSL/TLS servers from a Certificate Signing Request (CSR) generated by the server.
Before you begin, you should previously have created a certificate profile and end entity profile for SSL servers. For more information, see:
To request a certificate:
Access EJBCA RA Web and click Make new request.
In the Certificate Type field, select SSLServerEndEntityProfile.
Under Certificate subtype, you should not be able to choose anything but the default SSLServerCertificateProfile.
Under CA, you should not be able to choose anything but the default ManagementCA.
Select the Key-pair generation option Provided by user.
Upload the CSR.
In CN, Common Name, verify
testsrv.domain.com
.In DNS Name, verify
testsrv.domain.com
.At Username, enter
testsrv.domain.com
.Click the preferred Download button (PEM, DER) to download and save the newly created certificate file.
A new certificate is generated and downloaded to your desktop.