Set up the routing policy for automated certificate management
Set up a routing policy to automate your Certificate Inventory and Management. Creating a policy based on Certificate Authority (CA), environment, and other features ensures efficient TLS certificate management.
Before you begin
Role required: pki_admin or admin
About this task
The routing policy decides which CA must be contacted for certificate operations. It contains the CA, CA URL, Credential, Approval Group, Assignment Group, and CSR attributes. The routing policy triggers the flow for requesting certificates for specific CAs.
Procedure
Result
The approval group is assigned to the routing policy and contains the role: pki_approver and at least one of the active group members available in that group. If the routing policy requires manual approval, then approval is requested from those in the approval group.
What to do next
The following knowledge base articles guide you through the process of producing the credentials required and configuring routing policies for different certificate authorities:
For Digicert, see [Digicert] Configure automated certificate management for TLS certificates [KB2166364].
For Entrust, see [Entrust] Configure automated certificate management for TLS certificates [KB2173533].
For Let's Encrypt, see [Let's Encrypt - ACME] Configure automated certificate management for TLS certificates [KB2197962].
For Microsoft CA, see [Microsoft CA] Configure automated certificate management for TLS certificates [KB2198094].