The Digi-CA™ Certificate Enrolment API

PDF The user will browse to a fully customized Digi-ID™ Application Form Enrolment page. They will complete the details in the web form and click the ‘submit’ button. Depending on the chosen Certificate delivery method (Process/Package), a VB script or Java applet on the webpage can then initiate the chosen Cryptographic Service Provider [CSP] engine to generate the Private Key and Certification request (PKCS#10), before submitting all data (with the exception of the Private Key if the Process Method is chosen) to the Digi-CA™ Certificate Engine core system.


Allowed Subject Attributes

You will need to decide the type and order of the attributes that will appear in the "Subject" field of your Digi-ID™ Certificate. You may have multiple attributes of the same type (e.g. multiple ‘OU’s are common). You will also need to consider what attributes are required and which of these, if any, are optional. These settings may also be overwritten by the Digi-Policy™ applied on the Digi-CA™ Certificate Engine Core system for the specific RA API. The following table is a list of the common attribute types that are currently recognized by the Digi-CA™ Certificate Engine core system:



Full Name



Windows Name



OID



Minimum



Length



Maximum



Length



Defined by



Notes


commonName

CN


2.5.4.3

1

64


X.520



RA controlled value


Surname

SN


2.5.4.4

1

64


X.520



RA controlled value


serialNumber


2.5.4.5


2.5.4.5

1

64


X.520

 


countryName

C


2.5.4.6

2

2


X.520


Must be a valid ISO-3166 country code


localityName

L


2.5.4.7

1


128


X.520



RA controlled value


stateOrProvinceName

S


2.5.4.8

1


128


X.520



RA controlled value


streetAddress


STREET


2.5.4.9

1


128


X.520



RA controlled value


organizationName

O


2.5.4.10

1

64


X.520



RA controlled value


organizationalUnitName

OU


2.5.4.11

1

64


X.520



RA controlled value


Title

T


2.5.4.12

1

64


X.520



RA controlled value


Description


Description


2.5.4.13

1


1024


X.520



RA controlled value


PostalCode


PostalCode


2.5.4.17

1

40


X.520



RA controlled value


postOfficeBox


POBox


2.5.4.18

1

40


X.520



RA controlled value


telephoneNumber


Phone


2.5.4.20

1

32


X.520


Must comply with

ITU-T Rec. E.123


(e.g. +44 582 10101)



GivenName

G


2.5.4.42

1

64


X.520

 


Initials

I


2.5.4.43

1

64


X.520

 


emailAddress

E


1.2.840.113549.1.9.1

1


255


PKCS#9


Must be a valid RFC822 email address