menu menu
  • language
back icon Back
Choose your language
Content Type

 

Knowledge Base

Troubleshooting

Troubleshooting MPIC Domain Validation Failures

During domain control validation (DCV), DigiCert performs checks from multiple globallocations using our MPIC (Multi-Perspective Issuance Corroboration) agents. In somecases, these validation attempts fail or produce inconsistent results.

Adding your Slack Workspace to TLM Notification Center

Stay up to date with your certificate activity by connecting your Slack Workspace DigiCert ONE’s Notification Center.

How to identify which SafeNet USB token you are using

Disabling Browser Support for the SSL 3.0 Protocol

Depending on how your browser is configured, you may want to disable SSL v3 and enable TLS 1.0, TLS 1.1, and TLS 1.2.

Windows | Verifying Your Code Signing Certificate Installation

After generating your code signing certificate, we recommend verifying that your certificate is installed in the browser’s Certificate Store.

Office 2013, 2010, and 2007 | Adding an Invisible Digital Signature to a Microsoft Word Document, Excel Workbook, or PowerPoint Presentation

You can use your DigiCert® Document Signing Certificate to add an invisible digital signature to a Word document, Excel workbook, and PowerPoint presentation.

Office 2013, 2010, and 2007 | Adding a Visible Digital Signature inside a Microsoft Word Document or Excel Workbook

You can use your DigiCert® Document Signing Certificate to add a visible digital signature inside a Word document or Excel workbook.

DigiCert Certificate Utility | Repair Intermediate SSL Certificate Errors

1. On the Windows server where your SSL Certificate is installed, download and save the DigiCert® Certificate Utility for Windows executable

OCSP, CRL and Revoked SSL Certificates

To check the revocation status of an SSL Certificate, the client connects to the URLs and downloads the CA's CRLs.

Sign your code using your DigiCert-provided hardware token and the DigiCert Certificate Utility for Windows

1. On your Windows server or workstation, download and save the DigiCert® Certificate Utility for Windows executable

Windows | Exporting Your Code Signing Certificate

After installing your code signing certificate, you may need to export the certificate for use on a different computer, for signing code, etc.

How to sign a document in Adobe Acrobat

2. From Acrobat home (on the left), select All tools

Troubleshooting Security Certificate Errors

Though Wildcards are compatibile with Exchange, they can cause issues with POP3 and IMAP. For more information, see our page on Exchange 2007 Widlcard compatability.

Generic Top-Level Domains (gTLDs) and SSL Certificates

In June 2011, ICANN approved the New Generic Top-Level Domain Program (gTLD), which allows organizations, individuals, and governments to apply for top-level namespaces.

Certificate Signing Request (CSR) Is Missing a NULL Value

The CSR is missing a NULL value in the OBJECT IDENTIFIER rsaEncryption (1 2 840 113549 1 1 1) field. To be compliant with RFC 3279, this field must contain a NULL value.

Redirect Internal Names to use a Registered Domain

To update your Exchange 2007, Exchange 2010, or Exchange 2013 server, you will need to run the following commands from the Exchange Management Shell and replace the Server running the Client Access Role with your external domain name.

How to fix SSL Problems | Guide for General Users and Administrators

DigiCert® Software Trust Manager | “Error creating certificate. Check logs for more information.”

When generating a certificate from an online keypair in DigiCert® Software Trust Manager, users may encounter the status message “Error creating certificate.

Microsoft Exchange 2007 | DigiCert® Wildcard Plus™ Certificates

Microsoft ended support for Exchange 2007 on April 11, 2017. It is recommended to upgrade.

F5 FirePass | Replacing an Intermediate Certificate

Step 1: Copy the Certificate files to your server.

Disabling the CBC-Mode Ciphers with SSL 3.0

By disabling the CBC-mode ciphers, you are forced to rely on the RC4 stream cipher, which has its own biases (RC4-biases).

Mac | Removing the 'This certificate was signed by an unknown authority' Warning Message

The reason that you are receiving this message is that the Intermediate Certificate was not included in the Certificate Chain.

Name Mismatch in Web Browser

DigiCert's Multi-Domain Certificates allow one certificate to be issued to multiple names

Mac OS | Signing Code from the Command Line

You can use a DigiCert Code Signing Certificate to sign your Mac OS software, tools, updates, utilities, and applications.

How to generate your client authentication certificate and decrypt the SMPB batch file from DigiCert ONE IOT Manager

The following tutorial is meant to walk you through the process of generating your client authentication certificate and decrypting the SMPB batch file from DigiCert ONE IOT Manager.

Sun Java Web Server 7.0 | CSR Creation

When choosing your server type during the online order process, make sure to choose Java Tomcat to get the files in the most helpful format for command line installation.

Baracuda | How to replace Intermediate Certificate when intermediate certificate chain error occurs

To update the intermediate certificate on your Barracuda device, you will first download a copy of your existing DigiCert SSL Certificate

Firefox for macOS | How to backup / export your DigiCert Personal ID certificate

7. Click OK to save the file, making sure to verify that it is in the location you specified.

Replacing a cPanel Intermediate Certificate

3. In the box labeled CA Bundle, paste the contents of the DigiCertCA.crt file that you downloaded in Step 1.

Google's Gmail | Troubleshooting Gmail’s Strict SSL Security Change

As of December 2012, Google's Gmail servers are configured not to connect to remote POP3 servers that have either no certificate or a self-signed certificate.

Microsoft Exchange 2007 | Security Certificate Errors

Microsoft ended support for Exchange 2007 on April 11, 2017. It is recommended to upgrade.

DigiCert Code Signing Compatibility

DigiCert Code Signing Certificates can be used to sign code, including Microsoft Authenticode, Microsoft Office VBA, Java, Adobe AIR, Apple's Mac OS, and Mozilla objects.

Microsoft Store | Sign Your EV Verification XML File using EV Code Signing Certificate

To sign your EV verification XML file, you must have an EV Code Signing Certificate with a SHA-2 signature algorithm.

Configuring SSL Host Headers in IIS 6

Host headers can be used to host multiple secure websites on one IP address.

Wildcard Certificate Errors

These issues are not specific to DigiCert® certificates—they are caused by the way wildcard characters are handled.

Keychain Access | How to Export Your DigiCert® Personal ID

1. Open Keychain Access and select the certificate(s) you want to export.

Not Receiving Domain Control Validation (DCV) Emails

Before DigiCert can issue your SSL/TLS certificate, you must prove control over the domains on the order.

DigiCert Document Signing Certificate | Rekey Instructions

When rekeying a Document Signing Certificate, DigiCert must generate a new initialization code.

Mac OS X | Using an EV Code Signing Certificate to sign Code

To use an EV Code Signing Certificate with Mac OS X, you will need to have DigiCert preinstall the certificate to a token and ship it to you.

Windows | Delete a Certificate from a Server with the DigiCert Certificate Utility

Before deleting any certificate, make sure that the certificate has expired or is not being used.

F5 Big IP | How to replace an Intermediate Certificate when Chain Errors occur

Step 1: Copy the Certificate files to your server. Download your DigiCert intermediate certificate.

Nginx | Enabling OCSP Stapling on Your Server

These instructions were created using Nginx 1.6.2. Depending on which version of Nginx you are using, you may need to modify the instructions accordingly.

How to Edit a Domain’s DNS CAA RR to Get DigiCert Certificate Brands

Create one record, which authorizes DigiCert to issue any of the DigiCert-owned certificate brands.

IIS 8 and IIS 8.5 | SNI Browser Support

SNI is a transport layer security extension that enables you to use a virtual domain name or a hostname to identify the network endpoint.

Windows | Enabling OCSP Stapling on Your Server

If you are running Windows Server pre-2008, to enable OCSP stapling, upgrade to Windows Server 2008 or later.

Winqual.exe File | Code Sign using the DigiCert Certificate Utility

After installing your code signing certificate or activating your EV code signing token, you can use the DigiCert® Certificate Utility for Windows to sign your code and winqual.exe file.

Bluebeam Revu | How to Sign PDFs with Your DigiCert Document Signing Certificate

In Bluebeam Revu, open the PDF that you need to sign.

Windows | Intermediate Certificate Troubleshooting

Windows automatically determines which intermediate certificates to send to clients based on which root certificates it finds in its root certificate authorities certificate store.

DigiCert Certificate Status IP Addresses

This page contains the DigiCert dedicated IP addresses for DigiCert Online Certificate Status Protocol (OCSP), Certificate Revocation List (CRL), and a few other DigiCert services.

Nginx | Replacing an Intermediate Certificate

Download the intermediate certificate and copy the file to the directory on your server where you will keep your certificate and key files.

How to Sign OpenOffice and LibreOffice Documents

OpenOffice and LibreOffice programs record the time the document is signed and the certificate validity period

IIS 8 and IIS 8.5 | Configuring SSL Host Headers

In IIS 7, if you used host headers with an SSL Certificate, the same certificate had to be used for every secured site.

DigiCert Certificate Utility | Check If SSL Certificate Is Revoked

The DigiCert Certificate Utility® for Windows detects if an SSL Certificate installed on your Windows server has been revoked.

DigiCert Certificate Utility : Check SSL Certificate for Matching Private Key

The DigiCert Certificate Utility® for Windows has a feature that lets you find out if an SSL Certificate installed on your Windows server has a matching private key.

DigiCert Certificate Utility | Check a Server Feature

The Query Server feature can be very helpful for testing your SSL Certificate installation for a certificate that's installed in your Local Area Network

DigiCert Certificate Utility | Edit Friendly Name

In environments that require multiple SSL Certificates, the lack of friendly names can make managing your SSL certificates more difficult.

Nginx | Disabling the SSL v3 Protocol

Older versions of Internet Explorer may not have the TLS protocol enabled by default.

CertCentral | Setting up your DigiCert Hardware token for Document Signing

Learn how to set up your DigiCert-provided hardware token for Document signing

MacOS Catalina Certificate pickup fails | PKI Platform

Run the following command with Admin rights: sudo defaults write /Library/Preferences/com.apple.security.smartcard Legacy -bool true

Mac: Exporting Your Code Signing Certificate

This page provides instruction on how to export your Code Signing Certificate on Safari or Firefox in Mac.

IIS 7 | Configuring SSL Host Headers

Using host headers in combination with certificates that can cover more than one website, you can secure multiple sites on one IP.

Apache | Enabling OCSP Stapling on Your Server

Depending on which version of Apache you are using, you may need to modify these instructions accordingly.

Mac | Verifying Your Code Signing Certificate Installation

If you used Safari or Chrome to install your Code Signing Certificate, the certificate should be located in the login keychain.

Apache: Disabling the SSL v3 Protocol

Older versions of Internet Explorer may not have the TLS protocol enabled by default.

Enabling Perfect Forward Secrecy

This page provides instructions on how to configure Apache and Nginx for Perfect Forward Secrecy.

Authenticode® Program Signing & Timestamping Using SignTool

If you have more than one Code Signing Certificate on your computer, we recommend that you manually select which certificate to use for signing code.

Microsoft IIS: Disabling the SSL v3 Protocol

This page provides instruction on how to disable the SSL V3 protocol.

How to remove your certificates and private key and merge them into a Java, Oracle, or Keytool SSL Keystore.

To convert your certificates to a format that is usable by a Java-based server, you need to extract the certificates and keys from the .pfx file using OpenSSL.

Send a digitally signed or encrypted message via Outlook on MacOS

S/MIME allows you to encrypt email content using the recipient's public key, so only the intended recipient with the matching private key can read the message.

Configure KeyLocker for SMCTL

Configure KeyLocker for Click-to-Sign

Jarsigner signing with a token on Linux

The following article outlines the process of Jarsigner signing with a token on Linux.

CHANGE YOUR ETOKEN PASSWORD

Use these instructions to change your eToken password.

Sign Adobe AIR® applications with a hardware token-based code signing certificate

To run your applications on Adobe AIR or publish your Adobe Flash code on your Adobe Air applications, you must digitally sign them first.

Export Your SSL Certificate Using the DigiCert Certificate Utility (PFX Format)

Export your SSL/TLS certificate from one Microsoft server to import on another Microsoft server

Java code signing certificate guide

If you already set up your code signing certificate and are ready to sign your Java .jar files, go to our Sign Java .jar files with jarsigner instructions below.

Adobe AIR® application signing guide

To run your applications on Adobe AIR, you must digitally sign them first.

Sign Java .jar files with a hardware token-based code signing certificate in Windows

These instructions are for signing Java .jar files with a code signing or EV code signing installed on a hardware token.

Sign a Windows App on Linux Using osslsigncode

This article walks you through the steps to set up a Token on a Linux system and guides you on how to use the token once set up.

Apache : Replacing an Intermediate Certificate

Download your intermediate certificate, then copy it to the directory on your server where you will keep your certificate and key files.

How to resolve common ssl-related errors in Apache

The first step when experiencing issues trying to get Apache started is to check your log file for an error that might point to the problem.

How to resolve “The Certificate need to be installed” or “The private key for this certificate could not be found” error.

Use the DigiCert® Certificate Utility for Windows to repair your certificate installation and ensure it's installed correctly for use in IIS, Exchange, and other Windows server types.

Exporting a .pfx using MMC

In some instances, you may want to move a certificate from one server to another. You may also want to back up the certificate that you have installed. The best way to do this is to create a .pfx file.

VBA Signing with DigiCert Provided Hardware Token

There is a problem with the digital certificate. The VBA project could not be signed. The signature will be canceled.

DigiCert® Software Trust Manager REST API | Filtering Audit and Signature Log GET Requests

The ‘/audit-log’ and ‘/signatures’ endpoints of the DigiCert® Software Trust Manager REST API both make provision for filtering the returned data (in CSV format) in the endpoint URL targeted by the GET request.

DigiCert® Software Trust Manager | Jarsigner Self-Signed Certificate Warning

When signing Java files with jarsigner, using a DigiCert® Software Trust Manager certificate created with Java keytool, the “jar signed” success message may include a warning.

Initialize a SafeNet eToken 5110+ FIPS

The token uses various passwords for authentication. If an Administrator Password is entered incorrectly 5 times, the eToken locks permanently.

A901 An Exception occurred in the PKI Enterprise Gateway

During enrollments, users recieve a Service_Internal_Error A901

How do I Contact DigiCert | DigiCert® Document Trust Manager & DSS-Engine Support

If you are having issues with DSS-Engine or DigiCert® Document Trust Manager please use the following phone numbers and email alias to contact support.

ACME Supported Cipher Suites

Error 12029 calling WINHTTP_CALLBACK_STATUS_REQUEST_ERROR, 'A connection with the server could not be established'.

BIMI Logo Error: Element 'metadata' is a simple type, so it must have no element information item [children]

When uploading your BIMI logo to CertCentral for a Verified Mark Certificate (VMC) order, you may encounter the following error message:

Discovery and Automation capabilities when SAML is enabled on CertCentral Account

Scenario: Automation is behaving erratic when user tries to create profile or perform an automation task. Discovery notifications are not working even when enabled.

New Automation Profile Disappearing after Configuration

Automation profile disappears after it has been configured.

Not Found Error when Activating Discovery Sensor on Linux

You might receive a “./start.sh: source: not found” error when activating a sensor on Linux machine.

DC1 EST Enrollments via Client auth cert generated in Account Manager

When testing IOT Enrollment with EST using the client auth certificate generated in Account Manager, enrollments will fail.

Timestamp JAR file with DigiCert Code Signing Certificate for Sun Java using JDK 1.6.0

To Timestamp a Java Applet with a DigiCert Code Signing Certificate for Sun Java using JDK 1.6.0, perform the following steps:

Enable TLS 1.2 as default protocols in WinHTTP | Windows 2008 and 2012 standard Server

Digicert PKI Platform 8 ended support for TLS 1.0 and TLS 1.1 on August 30, 2021

DC 1 EST Enrollment via Passcode fails

When testing IOT Enrollment with EST using passcode, the enrollments fail.

Adding Exception to MS Defender, if its blocking DigiCert PKI Client application

End-users may not be able to launch the DigiCert PKI Client as the PKI Client console application is based on Microsoft HTML application (HTA).

Managed PKI 8.10.1 | Unclear error message for invalid FASCN value

If an invalid FASCN value is passed for an IDOD certificate request, PKI Web Services may return a generic A601 error.

Authenticode Signature Verification Fails with New Timestamping Cross-Root

In June 2022, DigiCert introduced the new cross root "DigiCert Trusted Root G4" to resolve compatibility issues with legacy timestamp clients.

Settings that could break ACME implementation with Cert-manager on Kubernetes

Platform: CertCentral ACME Automation Error: Failed to update ACME account:405: Method Not Allowed

DigiCert Log4j Sensor Response

DigiCert sensors included a version of Apache Log4j identified in the Log4j zero-day exploit.

API graph option is no longer available | PKI Platform

Microsoft deprecating AAD Graph in June of 2022. Making this graph option is no longer available.

Local Key Escrow and Recovery Service updated WAR package | DigiCert PKI Enterprise Gateway

DigiCert PKI Enterprise Gateway - Local Key Escrow and Recovery Service (LKMS) has been updated with the below changes:

Configure cert-manager and DigiCert ACME service with Kubernetes

1. Create an ACME Directory URL from CertCentral.

How to Install the SafeNet Drivers and Client Software (Windows)

Enable code signer authentication. Once enabled, SafeNet pops up before you sign code and requires you to enter your password to verify you.

CMS with Key Escrow KMS - A400 - Request failed due to internal error. Try again later

When enrolling for a certificate using MPKI Web Services, you receive the following error:

Troubleshooting Instructions | DigiCert Desktop Client

Gatekeeper certificate installation Steps requires the corresponding browser enabled in DigiCert Desktop Client application.

Initialize a SafeNet eToken 5110CC

The token uses various passwords for authentication. If an Administrator Password or PUK is entered incorrectly 5 times, the eToken locks permanently.

Delays During Scans of Larger IP Address Ranges

When scanning a large IP address range scan results may be delayed due to varying factors, including but not limited to network speeds on your and ISP’s environments.

Firefox 64-bit not working with PKI Client

Background: Customers running the 64-bit version of Firefox are experiencing issues accessing the PKI Manager portal via PKI Client.

Error: ASN1 bad tag value met. 0X80009310b (ASN:267) during certificate installation with Microsoft IIS 7.0

When Completing the Certificate Request in Internet Information Services (IIS) 7.0 Manager using a PKCS#7 file, the server may give the following error message:

Troubleshooting Timestamping Problems

The most common timestamping problems and the troubleshooting instructions are:

Certificates Missing from Discovery Scan Results

Sometimes certificates might be installed on your environment but not appear on the scan results.

Managed PKI 8.x | Error: Unable to install your certificate

The following error occurs when attempting to retrieve your certificate with a usb token: Product name: eToken PRO Java 72K OS755

CSR Generation Failed | CertCentral

CSR generation failed (User does not have access to action (config sync)). This is error is related to the role of a user managing the automation request.

Error: "Cannot find the certificate request associated with this certificate file. A certificate request must be completed on the computer where it was created." when installing certificate using Microsoft IIS 7

When installing a certificate using Microsoft IIS 7 Manager, you may receive the following error message even though the certificate is installed:

DigiCert and Adobe Approved Trust List

The Adobe Approved Trust List (AATL) is used to distribute and maintain a list of trustworthy digital certificate issuers for Adobe Acrobat and Adobe Reader.

Installing SSL certificate Node.js

Log in to CertCentral and download the certificates from the order page by following these steps: 1. Log in to CertCentral

Domain Authentication Error | PKI Platform 8

Error: "This certificate profile type requires that domain names be authenticated and assigned to this account." Requires you to contact PKI Support.

Timestamp VBA Projects

Using a timestamping service usually takes more time than the default digital signing process.

How to sign code with a Code Signing Certificate for Microsoft Office and VBA

To sign code with a Code Signing Certificate for Microsoft Office and VBA, perform the following steps: 1. Open the document or template that contains the macros you want to sign

Safenet Hardware Token not detected in Adobe Reader on Mac OS

When attempting to create a Digital ID for digital signatures in Adobe Reader on Mac OS, Adobe Reader does not detect the inserted Safenet hardware token containing the certificate to be used.

MPKI 8.x Error "AutoEnrollmentDCOMSrv: cannot run: AEException: could not find any matching RA PSE; but we need one!"

If restarting Auto Enrollment service fails, this may happen if the service is unable to find the private key of the RA certificate that was generated on HSM.

View archived PKI Client logs in zlib format

How to install the necessary utilities to extract and view archived PKI Client logs files in zlib format for Windows, Mac OS and Linux.

Certificates may not be present after updating to a newer version of Windows 10

Administrators and end users are missing their certificates after a recent update on their local system.

Patch Management Update Process

Exadata DB patching is done quarterly on all nodes.

DC 1 Locally hosted install fails to start Ambassador

When performing a local install of DigiCert One, the Ambassador service fails to install correctly.

Access Denied Error during Discovery Sensor Installation on Windows

You might get an access denied error when installing a sensor on a Windows machine. This is not a sensor issue but rather a Windows permissions one.

Error: There was a problem with the digital certificate. The VBA Project could not be signed. The signature will be discarded

To resolve this issue, export the certificate from the original computer with Include all certificates in the certificate path option selected.

Discovery Sensor Not Picking Up Certificates Installed on Port 25

Discovery sensor does not pick up certificates installed on port 25.

Discovery Services during DigiCert Maintenance Window

During our maintenance window, any scheduled scans and their results will fail as data is being loaded and services go down.

Exceeded Maximum amount of Scans Error

This error occurs when the number of scans allowed in an account’s subscription has been exceeded.

Error: "Error 30ab - Valid or Pending ID exists" when Replacing a Managed PKI for SSL Administrator ID

When trying to replace Managed PKI Administrator ID, you may receive the following error message: Error 30ab - Valid or Pending ID exists

Sensor Stopped Responding During a Scan

Sensor stops responding mid scan. It is usually because the network connection to the sensor has been interrupted or the sensor needs to be updated to the latest version.

Partial Completion of Discovery Scan Issue

Sometimes a scan will be complete, but only partially due to insufficient time allocated to the scan.

An unexpected error occurred with the PKI Enterprise Gateway, Error A901

When users try to enroll and get an A901 error 

The option: "Yes, export the private key" is greyed out

The System and Administrator accounts do not have sufficient permissions or the Administrators group does not have ownership of the directory.

Error: "The certificate status could not be determined because the revocation check failed" after installing certificate into Exchange 2010

This issue occurs because Exchange Server 2010 uses Microsoft Windows HTTP Services (WinHTTP) to manage all HTTP and HTTPS traffic, and WinHTTP does not use the proxy settings that are configured for the Internet browser.

How to Enable Automatic Root Update on Microsoft Server 2008

To disable automatic root certificates update on Microsoft Windows 7 or Microsoft Server 2008, perform the steps outlined below.

How to enable ActiveX for Certificate creation with Internet Explorer 7, 8, 9 & 10

Please make the following changes to the security settings of the Microsoft Internet Explorer browser:

SSL Certificate Browser Errors

Troubleshoot KeyLocker and Click-to-Sign

Troubleshoot KeyLocker for jSign using the PKCS#11 Library

Troubleshoot KeyLocker for JarSigner using the Java Cryptography Extension (JCE) Library

Troubleshoot KeyLocker for JarSigner using the PKCS#11 Library

Troubleshoot KeyLocker for JarSigner using the DigiCert KSP

Troubleshoot KeyLocker for Microsoft SignTool

Enabling OCSP Stapling on Your Server

The OCSP protocol does not require the browser to spend time downloading and then searching a list for certificate information.

Repair | Intermediate SSL Certificate Errors

This page provides instructions on how to replace an Intermediate certificate and how to reissue and reinstall a SSL certificate when intermediate certificate error occurs.

OpenSSL Quick Reference Guide

OpenSSL is an open-source command line tool that is commonly used to generate private keys, create CSRs, install your SSL/TLS certificate, and identify certificate information.

Supported domains for Private TLS/SSL certificates

Use Private TLS/SSL certificates to secure private and public domains and IP addresses.

Resolving PKI Client issues on macOS Monterey

This article details how to resolve issues experienced by using the DigiCert PKI Client to access the PKI Platform 8 administration portal called PKI Manager, using macOS Monterey machines running on either M1 or Intel-based chips.

Onion Domains

.Onion is a top-level Internet domain used by anonymous websites on the Tor network accessibly only from the Tor anonymity browser.

Enabling TLS 1.1 and TLS 1.2 on web browsers

To enable TLS 1.1 and/or TLS 1.2 protocols on web browsers, see the list below.

How to download SafeNet Authentication Client

Download SafeNet Authentication Client for Windows XP, Vista, and 7. Download SafeNet Authentication Client 9.0 for Windows 8 and up.

How to initialize or reset a SafeNet 5110FIPS USB Token Device password

To initialize or reset a SafeNet 5110FIPS USB Token Device password please follow the steps below:

What is a Distinguished Name (DN)?

The Distinguished Name is a set of values entered during enrollment and the creation of a Certificate Signing Request (CSR).