The following tutorial is meant to walk you through the process of generating your client authentication certificate and decrypting the SMPB batch file from DigiCert ONE IOT Manager.
Navigate to “Access” then “Users” on the left pain.
Select the account you are logged in with.
While viewing your User, scroll down to the “Client authentication certificates” section and select “Create client authentication certificate.” Configure your certificate and then select “Generate Certificate.” Please Note:The friendly name will be referenced by the system later. Make this easily identifiable. When the End Date has lapsed, the certificate will expire and a new one will need to be generated.
Copy your passcode that is displayed to a notepad for safe keeping and select "Download Certificate."
Configuring the PKI Client
Download the PKI Client and install it with local Admin permissions.
Search “PKI Client” from the Windows search.
After the Client launches and initializes, select “My Computer "and then “Import a certificate.”
Browse for your previously downloaded Client Auth certificate and then provide the password that was saved in Notepad.
You will be presented with a prompt asking if you want to protect your certificate with a PIN. It is advisable to do so as this will protect your certificate from unauthorized access.
Please Note: If this PIN is lost, a new certificate will need to be generated as resetting the PIN without the previous PIN is a destructive act on the PKI Client cert store.
Properly Formatted SMPB Batch Request
Requesting SMPB formatted batch
When requesting your batch select “Binary .CER (SMPB).”
Select “Use Authentication certificate from my profile” and locate your certificate from the drop down. It will be the same friendly name you provided when generating the certificate.
Decide on your Method to generate the certificates and then select “Start request.”
When the batch has been completed, download it by going to “Batch Jobs,” selecting your batch by name from the list and then selecting the blue download arrow.
Decrypting the SMPB batch
To decrypt the batch on a system with the Client Authentication certificate imported to the PKI Client, simply double click the downloaded SMPB file.
You will be presented with a window asking for a File location to save the decrypted zip file. Selecting "Continue" will present you with the PIN you set earlier when importing the Client Authentication certificate.
After successfully decrypting the file, you can now open the new zip file with Windows Explorer to view the contents.