Configure certificate authorities (CAs) that your organization trusts and activate the certificate authority trust policy so that certificates from other authorities are flagged as untrusted.
Before you begin
Role required: Cryptographic Asset admin (sn_itom_cac.admin)
Procedure
-
Navigate to .
-
Select the Settings icon
.
-
In the Settings tab, select Policies if it is not already selected.
-
In the Policy page, select Certificate authority trust.
-
Select the Policy builder tab.
-
In the Data sources panel, select Add.
-
In the Add API Variable dialog box, fill in the fields.
| Field |
Description |
| Label |
Display name for the variable, for exampleTrusted CA List. |
| Name |
Internal name that the policy uses to reference the variable. |
| Type |
Data type of the variable, which should be Data Array. |
| Mandatory |
Option that determines whether a value is required for the variable. |
| Description |
Optional notes about the variable. |
| Default value |
The CAs that your organization trusts, as a list of quoted names. For example, ["Test CA 1","Test CA 2"]. |
-
Select Save.
-
Publish the policy version by selecting Publish.
-
Activate the policy by selecting Activate.
-
Confirm the activation by selecting Activate in the Activate Policy dialog box.
Result
The Certificate authority trust policy is active with the list of CAs that your organization trusts. Certificates issued by an authority not in your trusted list are flagged with the trusted CA
risk indicator.