Certificate request form

  • Release version: Zurich
  • Updated March 12, 2026
  • 1 minute to read
  • The Request New Certificate (Automated) and Renew Certificate (Automated) forms enable you to submit or update a Certificate Signing Request (CSR) to be submitted to a certificate authority.

    Field Description
    Certificate Purpose Determines whether the Certificate is internal or external.
    • Internal: Requires a completed form
    • External: Requires importing the CSR and private key from an external source
    Environment Environment where the certificate must be deployed or installed. The available options are Development, Disaster recovery, Production, or Sub-Production.
    Validity Period for Certificate (In Days) The number of days the certificate is valid. This field appears only when External is selected from the Certificate Purpose field.
    Choose how to generate CSR Determines which CSR is used to generate the certificate. The available values are:
    • Use external CSR
    • Generate CSR in CyberArk: Available only when CyberArk Certificate Manager SaaS is selected as the Select how to manage your certificate value when requesting or revoking a certificate.
    Certificate Signing Request (CSR) CSR sent to the external Certificate Authority (CA) to request the certificate.
    Subject Common Name Entity or domain name the certificate is issued to.
    Subject Alternative Name Domain or subdomain included in the Subject Common Name.
    Organization Organization submitting the CSR.
    Organizational Unit Organizational unit submitting the CSR.
    Locality/City Locality (city) of the organization submitting the CSR.
    Province State or province of the organization submitting the CSR.
    Country Country of the organization submitting the CSR.
    Email Address Email address of the administrator in the organization submitting the CSR.
    Key Algorithm Cryptographic algorithm for generating the certificate key pair, based on algorithms supported by CyberArk. The available options are RSA 1024, RSA 2048, RSA 3072, RSA 4096, EC P256, EC P384, EC P521, and EC ED25519.
    Application Services Application services for the certificate.
    Servers Servers the certificate can be hosted on.
    Application Names Specific application the certificate is issued for.
    Application Servers Application servers the certificate is hosted on.
    Certificate Owner Group Certificate owner group for the certificate.
    Certificate Owner Specific entity that the certificate is issued to.
    Renewal Tracking Determines whether to track certificate renewal automatically. The available options are Create priority 1 tasks, Create prioirty 3 tasks, and Do not create renewal tasks.
    Renew Automatically Option to automatically renew the certificate.
    How many days before expiry does the certificate need to be renewed? Number of days before certificate expiration to trigger renewal.