Turn on certificate validation
Protect your instance with certificate based validation.
Before you begin
Role required:
- codesigning_admin
- security_admin
- sn_kmf.cryptographic_manager
Procedure
- On your trusted instance, navigate to All > Code Signing > Configuration > Guided Setup to open the Code Signing configuration page.
- In the Instance type field, select trusted instance.
- Select the Next button.
- In the Action field under Select the action you’d like to accomplish, select Turn on Cert Validation.
- Select the Next button.
-
Next to Attachments in the Customer signing key pair and certificate section select +Add File to upload a cryptographic key pair (p12 file extension)
to use for customer signing.
Tip:If the +Add File option is not available, verify that you are in the Global scope, and that you have the sn_kmf.cryptographic_manager role.
- In the Password field, enter the password for the uploaded key pair.
- Select Import.
- Select Continue to move to the next section.
- Next to Attachments in the COT administration key pair and certificate section select +Add File to upload a cryptographic key pair (p12 file extension) to use for customer signing.
- In the Password field, enter the password for the uploaded key pair.
- Select Import.
- Select Continue to move to the next section.
-
In the Perform trusted instance tasks section, wait for
all tasks to be completed.
Your instance generates and executes these tasks automatically. If you used Code Signing prior to the Vancouver release, tasks are created and executed to update your signatures.
In some cases, no tasks are needed. No tasks needed displays on this page.
- Select Continue to move to the next section.
-
On the Export Configuration file page, select
Export to create and download a configuration file
used to turn on Code Signing on your protected instance.
The export process downloads an XML file to your local machine for use in the steps detailed in Configure Code Signing Enterprise on your protected instance.
- On your protected instance, navigate to All > System Update Sets > Retrieved Update Sets.
- Select Import Update Set from XML at the bottom of the Retrieved Update Sets list.
- Select Choose File, and select your configuration file (xml file extension).
- Select Upload.
- Return to the code signing configuration page at All > Code Signing > Code Signing Configuration.
- Use the wizard to complete your configuration, selecting the options for completing certificate validation activation.