Certificate Enrollment Object certificate parameters in certificate requests

When sending a certificate request to a CA server, you can specify additional information that is placed into the certificate and is viewable by recipients. All information should follow the standard LDAP X.500 format.

Cloud-Delivered Firewall Management Center navigation path

Objects > PKI > Certificate Enrollment. Click Add Certificate Enrollment to open the Add Certificate Enrollment dialog box, and select the Certificate Parameters tab.

Fields

Field

Description

Include FQDN

Whether to include the device’s fully qualified domain name (FQDN) in the certificate request. You can select from these options:

  • Use Device Hostname as FQDN

  • Don't use FQDN in certificate

  • Custom FQDN—Select this and then specify it in the Custom FQDN field that displays.

Include Device's IP Address

Specify the interface whose IP address you want to include in the certificate request.

Common Name (CN)

Specify the X.500 common name to include in the certificate.

Note

When enrolling a self-signed certificate you must specify the Common Name (CN) in the certificate parameters.

Organization Unit (OU)

Specify the name of the organization unit (for example, a department name) to include in the certificate.

Organization (O)

Specify the organization or company name to include in the certificate.

Locality (L)

Specify the state or province to include in the certificate.

State (ST)

The state or province to include in the certificate.

County Code (C)

The country to include in the certificate. These codes conform to ISO 3166 country abbreviations, for example "US" for the United States of America.

Email (E)

Specify the email address to include in the certificate.

Include Device's Serial Number

Specify whether to include the device's serial number in the certificate. The CA uses the serial number to authenticate certificates or to later associate a certificate with a particular device. If you are unsure, include the serial number, because it is useful for debugging purposes.