To create an Issuing CA Certificate Profile, do the following.

  1. Click Certificate Profiles under CA Functions to open the Manage Certificate Profiles page
  2. Click Clone next to the SUBCA profile to use that profile as a template.
  3. Specify Corporate Issuing CA Certificate Profile and click Create from template in Name of new certificate profile.
  4. Click Edit on the Corporate Issuing CA Certificate Profile and specify the following.
    1. Available key algorithms: Select desired key algorithm, for example, RSA.
    2. Available bit lengths: Select desired bit lengths, for example, 2048-4096.
    3. Validity or end date of the certificate: Specify the validity 15y7d.
  5. Select CRL Distribution Points, if desired.
    NOTE To allow clients to fetch the CRL from the CA directly and have Apache in front of EJBCA, remove port 8080 from the URL and change the DNS name as required. EJBCA does not know if Apache exists and internally responds to 8080 in most cases.
    Example URLs:
  6. Clear LDAP DN order (to get X509 DN ordering) for greater compatibility with systems that use certificates.
  7. Click Save to save the Issuing CA Profile.