Purpose
How to obtain a X.509 certificate from the InCommon CA via the UW Certificate Services website.
Prerequisites
To obtain a certificate from the InCommon CA you must fulfill these prerequisites:
- For DNS names managed in UW DNS:
- The DNS name used for your certificate "common name" is registered in UW DNS.
- Any DNS names used for your certificate "subject alternative names" are registered in UW DNS.
- The UW NetID of the person submitting the certificate signing request (CSR) is registered in UW DNS as a contact for the common name and any subject alternative names in the CSR.
- For DNS names managed outside of UW DNS:
- The UW NetID of the person submitting the certificate signing request (CSR) is registered in the UW groups service as an owner for the common name and any subject alternative names in the CSR.
- Approval is required for DNS names outside of washington.edu and uw.edu. To add support for a domain you own, you can Request a New Domain for InCommon CA Certificates.
Procedure
1. Generate your certificate signing request (CSR). The procedure to generate a CSR varies from platform to platform. Consult your platform documentation if you need assistance.
2. Browse to the UW Certificate Services website (authentication required): https://iam-tools.u.washington.edu/cs/
3. Test ownership of your DNS name(s) by clicking the "Verify DNS Ownership" link, entering your hostname in the "DNS name" box, and clicking the "Verify ownership" button. Refer to the prerequisites above if the test fails.
4. Click the "New InCommon certificate" link. This displays the "Request InCommon certificate" form.
5. Paste the contents of your CSR into the "CSR (PEM)" box.
6. Optional: Add subject alternative names to your request by entering them in the "AltNames" box.
7. Select "SSL" as the Cert type.
8. Select the appropriate option from the "Server" menu.
9. Select the appropriate option from the "Number of servers" menu.
10. Select the desired option from the "Lifetime" menu.
11. Click the "Submit request" button. A valid CSR submission will indicate success.
12. Wait for the certificate to be issued.
13. UW Certificate Services will check the status of your request and notify you via email when your InCommon certificate has been issued.
14. Browse to the UW Certificate Services website (same location as step 2 above).
15. Locate your request by browsing the list under "Favorites" or by using the "Search" control to find certificates by common name (CN) or alternative names (altName).
16. Click any of the table cells in the row corresponding with your request to view your request.
17. Select and copy the PEM version of your certificate, download the PKCS7 bundle, or use the "Other download" option to retrieve your certificate.
18. Install the certificate on your platform, using whatever methods it provides for this. Consult your platform documentation as needed.
19. That's it! If you encountered a problem please report it to iam-support@uw.edu.