This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

How-to guides

Users can create the service by entering the required information for the Certificate Manager service and selecting detailed options through the Samsung Cloud Platform Console.

Create Certificate Manager

You can create and use the Certificate Manager service in the Samsung Cloud Platform Console.

To request the creation of a Certificate Manager service, follow these steps.

  1. Click the All Services > Security > Certificate Manager menu. 1. Go to the Service Home page.
  2. On the Service Home page, click the Create Certificate Manager button. 2. Go to the Create Certificate Manager page.
  3. Create Certificate Manager page, enter the information needed to create the service, and choose detailed options.
    • In the Service Information Input area, enter or select the required information.
      Category
      required status
      Detailed description
      Certificate nameRequiredEnter the Certificate Manager name to use
      • Enter within 3-30 characters, including English letters, numbers, and special characters (-, _, .)
      • Cannot be the same as an existing name
      typeRequiredSelect the Certificate Manager type to use
      • User Certificate: a public certificate issued by a Certificate Authority (CA)
      • Self-issued Certificate: a certificate self-issued (Self-signed) by Samsung Cloud Platform
        • Since it is relatively less secure, it is recommended for development/testing use only.
      User Certificate > Certificate BodyRequiredEnter Server(Leaf) certificate information
      • Only one certificate can be entered in the certificate body
      • Enter the full content, including the lines from —–BEGIN CERTIFICATE—– to —–END CERTIFICATE—–
      User Certificate > Private KeyRequiredEnter the private key information
      • The Private Key supports the RSA encryption method
      • The Private Key can be entered in an unencrypted PEM format
      • Enter the entire content, including the lines from —–BEGIN RSA PRIVATE KEY—–to —–END RSA PRIVATE KEY—-
      User Certificate > Certificate ChainRequiredEnter the Certificate Chain information
      • Can be omitted when using a private certificate
      • The Certificate Chain should be entered in the order: Intermediate (Subordinate) certificate → Root certificate
      • For a public certificate, the Certificate Chain information must be entered; only when there is no intermediate certificate (Chain CA) should use be disabled
      • Enter the full content, including the lines from —–BEGIN CERTIFICATE—– —–END CERTIFICATE—–
      • If there are multiple Intermediate (Subordinate) certificates, enter each certificate’s content in order
      User Certificate > Certificate ValidationRequiredValidate the entered certificate’s validity
      Self-signed certificate > Common NameRequiredEnter the domain name to use the certificate
      Self-issued certificate > Organization UnitRequiredEnter the organization and department that will use the certificate
      Self-issued certificate > Start dateRequiredEnter the certificate start date (creation date)
      Self-issued certificate > Expiration dateRequiredEnter the certificate expiration date
      Expiration alertSelectionSet whether to receive pre‑expiration certificate alerts
      • Select Use to enable expiration alerts
      • If expiration alerts are set, an email is sent to the recipients 45, 30, 15, 7, and 1 days before the certificate expires
      Expiration Alert > Alert RecipientRequiredSelect notification recipients when using expiration alerts
      • Enter a user name in the search area to select notification recipients
      • Up to 100 recipients can be registered
      Table. Certificate Manager service information input items
      Reference
      • If the entered certificate information is invalid, you cannot create the Certificate Manager service.
      • If the Private Key is encrypted, enter the decrypted value using the openssl command below.
        • openssl rsa -in [Encrypted Private Key File name] -out [Decrypted Private Key File name]
      • For certificates issued via Let’s Encrypt, even if you already have a previously issued Certificate Chain value, extract it again and enter it.
    • In the Additional Information Input area, enter or select the required information.
      Category
      required status
      Detailed description
      tagSelectionAdd Tag
      • Up to 50 can be added per resource
      • After clicking the Add Tag button, input or select Key, Value values
      Table. Certificate Manager additional information input fields
  4. Review the entered service information and additional details, then click the Create button.
    • When creation is complete, check the created resource on the Certificate Manager List page.
      Reference

      To create a Load Balancer for use with the Certificate Manager service, click Load Balancer creation in Service Home.

Check Certificate Manager detailed information

The Certificate Manager service allows you to view and edit the full list of resources and detailed information. Certificate Manager Details page consists of Details, Connected Resources, Tags, Activity History tabs.

To view detailed information for Certificate Manager, follow these steps.

  1. All Services > Security > Certificate Manager Click the menu. 1. Go to the Service Home page of Certificate Manager.
  2. On the Service Home page, click the Certificate Manager menu. 2. Navigate to the Certificate Manager List page.
  3. On the Certificate Manager List page, click the resource to view its detailed information. 3. Navigate to the Certificate Manager Details page.
    • Certificate Manager Details page displays the status and detailed information of the Certificate Manager, and consists of Details, Connected Resources, Tags, Activity History tabs.
      CategoryDetailed description
      Service statusCertificate Manager status
      • Creating: In progress
      • Active/Valid: Certificate valid
      • Expired: Certificate expired
      • Editing: Changing settings
      • Terminating: Terminating
      • Error: Certificate error
      Service terminationButton to cancel Certificate Manager
      Table. Status information and additional features

Detailed Information

Certificate Manager List page lets you view detailed information of the selected resource and, if necessary, edit the information.

CategoryDetailed description
serviceService Name
Resource typeResource Type
SRNUnique resource ID in Samsung Cloud Platform
Resource nameResource Name
Resource IDUnique resource ID in the service
ConstructorUser who created the service
Creation date and timeService creation date and time
ModifierUser who edited the service information
Modification dateDate and time the service information was modified
Certificate nameCertificate Manager certificate name
typeCertificate type information
Issuing AuthorityUser Certificate Issuing Authority Information
Common NameSelf-issued certificate display of information entered when creating the service
Organization UnitSelf-issued certificate Display the information entered when creating the service
Additional domainUser Certificate’s registered SAN information, displayed up to a maximum of 250
Public Key informationUser Certificate’s key algorithm type and length display
Signature algorithmUser Certificate’s issuing authority signature method display
Use statusIndicates whether the connected resource is registered
Start date/time / Expiration date/timeDisplay the certificate’s start/expiration date
Number of days remaining until expirationDisplay the number of days remaining until expiration based on the current date
  • After the expiration date, display ‘-’
Expiration alertCertificate expiration alert settings details
  • Click the Edit button to modify the usage of expiration alerts and the alert recipients
  • For expired certificates, the edit button is disabled and cannot be modified
Table. Certificate Manager detailed information items

Connected resource

On the Certificate Manager List page, you can view the connected Load Balancer information.

CategoryDetailed description
Load BalancerLoad Balancer resource ID attached to the service
ListenerClick the name of the Listener resource ID
  • connected to the service to display the detail information window
statusDisplay the status of Listeners connected to the service
Table. Connected Resources tab items of Certificate Manager

Tag

On the Certificate Manager List page, you can view the tag information of the selected resource and add, modify, or delete it.

CategoryDetailed description
Tag listTag list
  • You can view the Key, Value information of the tag
  • Up to 50 tags can be added per resource
  • When entering a tag, you can search and select from the list of previously created Keys and Values
Table. Certificate Manager Tag tab items

Job History

You can view the operation history of the selected resource on the Certificate Manager List page.

CategoryDetailed description
Task History ListResource Change History
  • You can view operation details, operation time, resource type, resource name, operation result, and operator information
  • Operation History List When you click the corresponding resource in the list, the Operation History Details popup opens
Table. Certificate Manager operation history tab detailed information items

Terminate Certificate Manager

You can request the termination of the Certificate Manager service from the Samsung Cloud Platform Console.

Caution
You cannot delete it if there are resources connected to the Certificate Manager service. To cancel the service, first delete the connected resources.

To request termination of the Certificate Manager service, follow the steps below.

  1. Click the All Services > Security > Certificate Manager menu. 1. Go to the Service Home page of Certificate Manager.
  2. On the Service Home page, click the Certificate Manager menu. 2. Go to the Certificate Manager List page.
  3. On the Certificate Manager List page, click the resource to view its detailed information. 3. Navigate to the Certificate Manager Details page.
  4. On the Certificate Manager Details page, click the Cancel Service button.
  5. Once the termination is complete, verify the service termination status in the Certificate Manager list.

1 - Extract Certificate Chain

Users can extract and input the Certificate Chain certificate to be used when creating a Certificate Manager service.

Extract Certificate Chain

You can extract the Certificate Chain value required when creating a Certificate Manager.

Caution

The Certificate Chain consists of Intermediate (Subordinate) certificates issued by a trusted certification authority and the Root certificate.

  • Even if you already have a Certificate Chain value, extract and register the Intermediate (Subordinate) certificate through the Root certificate again using the Certificate Body file. (Recommended)

Extract Intermediate (Subordinate) Certificate Value

You can extract the intermediate (subordinate) certificate from the certificate chain required for user certificate enrollment.

Reference
If there are two or more Intermediate(Subordinate) certificates, extract the values for each certificate.

To extract the Intermediate(Subordinate) certificate value, follow these steps.

  1. Run the certificate file in crt format on the PC. The certificate window will appear.
  2. In the certificate window, click the Certificate Path tab.
    • If the file is in PEM format, convert it to a .crt file.
  3. Click the certificate under Root and click View Certificate.
  4. After clicking the Details tab, click Copy to file.
  5. When the certificate export wizard runs, click Next.
  6. Select the format Base 64-encoded X.509(.CER)(S) and click Next.
  7. Click Browse to select the folder where you want to save the file, then click Next.
  8. Click Finish. The certificate export wizard will complete.
  9. Open the exported file as a TEXT file and verify the values.
    • The extracted certificate value must start and end with —–BEGIN CERTIFICATE—– and —–END CERTIFICATE—-.

Extract Root certificate value

You can extract the root certificate of the certificate chain required for user certificate enrollment.

To extract the Root certificate value, follow these steps.

  1. Run the certificate file in crt format on the PC. The certificate window will appear.
  2. In the certificate window, click the Certificate Path tab.
    • If the file is in PEM format, convert it to a .crt file.
  3. Click the topmost Root certificate and click View Certificate.
  4. After clicking the Details tab, click Copy to File.
  5. When the certificate export wizard runs, click Next.
  6. Select the format Base 64-encoded X.509(.CER)(S) and click Next.
  7. Click Browse to select the path where you want to save the file, then click Next.
  8. Click Finish. The certificate export wizard will complete.
  9. Open the exported file in TEXT format and verify the values.
    • The start and end of the extracted certificate value must include the —–BEGIN CERTIFICATE—– and —–END CERTIFICATE—- entries.

Enter Certificate Chain value

This explains how to enter the extracted Intermediate (Subordinate) certificate and Root certificate values into the Certificate Chain field when creating a Certificate Manager.

Reference
For detailed instructions on creating a Certificate Manager, see Create Certificate Manager.

To enter the Intermediate (Subordinate) certificate and Root certificate values into the Certificate Chain field, follow these steps.

  1. Execute the Intermediate (Subordinate) certificate file and the Root certificate file as text files.
  2. Copy the entire value of the Intermediate (Subordinate) certificate file.
  3. Paste it into the Certificate Chain input area on the Certicafate Manager Creation page.
    • Paste it, including the —–BEGIN CERTIFICATE—– at the beginning and the —–END CERTIFICATE—- at the end of the certificate value.
  4. Copy the entire value of the Root certificate file.
  5. Paste it into the Certificate Chain input area on the Create Certicafate Manager page.
    • Paste it, including the —–BEGIN CERTIFICATE—– at the beginning and —–END CERTIFICATE—- at the end of the certificate value.
    • Paste the Root certificate value on the line below the Intermediate (Subordinate) certificate.