Certificate Manager Entitlement Management


Entitlement Authorization for Certificate Requests

 
Entitlements may be used to authorize a person to request certificates in a domain that you, as a Network Liaison, manage. The benefit of using entitlements for this authorization is that you can authorize a person to request certificates for a specific name or domain indefinitely, rather than having to approve each certificate request made for a person. If you do choose to use entitlements for this authorization, you should periodically review them.
 
For example, as a network liaison of foo.vt.edu, you may create entitlements to authorize specific names in the foo.vt.edu domain:
Or, you may create wildcard entitlements to authorize any name in the foo.vt.edu domain or subdomain:
Follow these steps to create an entitlement:
  1. Go to https://certs.it.vt.edu
  2. Click Entitlements in the navigation menu. (if you do not see this option, you are not a network liaison for any domains)
  3. Click on a domain to manage entitlements for.
  4. Enter the pid(s) of the person(s) you are granting an entitlement to.
  5. Enter a name to create an entitlement for. 
    1. If you are creating an entitlement for bar.foo.vt.edu, enter bar in this field.
    2. If you are creating an entitlement for only the domain, leave this field blank.
  6. Click the Wildcard Prefix? checkbox if the entitlement is for any name in the domain or subdomain.
  7. Finish creating the entitlement by clicking Create Entitlement. 
If at any time you wish to delete an entitlement for a person in a domain you manage, follow these steps to delete an entitlement:
  1. Go to https://certs.it.vt.edu
  2. Click Entitlements in the navigation menu. (if you do not see this option, you likely are not a network liaison for any domains)
  3. Click on a domain to manage entitlements for.
  4. In the Entitlement data section, click the Delete button next to the entitlement you want to delete. If you do not see this section, no entitlements exist for the domain.
 
Note that: