Purchase and enable a compliant CA

Updated at:

To set up a certificate authority (CA) within your enterprise that meets security compliance requirements, such as passing a cryptographic application security assessment, you can use the compliant CA feature. This topic describes how to purchase and enable a compliant CA.

Background information

A compliant CA hosts the compliant root CA with a third-party CA provider, enabling you to set up an enterprise CA under the supervision of a third-party CA provider.

A compliant CA consists of a root CA and a subordinate CA (intermediate CA). The subordinate CA is under the root CA. Each compliant root CA contains only one subordinate CA. Only the subordinate CA can issue private certificates.

Step 1: Purchase a compliant subordinate CA

When using a compliant CA for the first time, you must purchase a compliant subordinate CA. After the purchase, the system creates a root CA for you. After you enable the root CA, a subordinate CA is automatically created.

  1. Log in to the Certificate Management Service console.

  2. In the navigation pane on the left, choose Certificate Management > Private Certificate Management. On the Private Certificate Management page, select the region where the PCA service is located.

  3. On the Compliant CA tab, click Purchase Private Root CA.

  4. In the purchase panel, configure the following parameters.

    Parameter

    Description

    Commodity Module

    PCA Service is selected by default, which creates a CA service for your enterprise to maintain and manage certificates.

    PCA usage

    For Regulatory Compliance is selected by default, which is suitable for scenarios that require a cryptographic application security assessment or compliance with electronic certification service standards, such as direct bank-enterprise connections and electronic signatures.

    Commodity pecifications

    Create Child CA is selected by default.

    Certificate algorithm

    The encryption algorithm type used by the compliant CA to issue certificates. You can select RSA or SM (Chinese Cryptographic Algorithm).

    Subscription duration

    The service duration for the PCA service.

    Note
    • After the service expires, the compliant CA can no longer issue certificates, even if the certificate quota is not fully used.

    • The validity period of private certificates issued by the compliant CA cannot exceed the subscription duration of the PCA service. For example, if you purchase the compliant CA service for one month, the validity period of issued certificates cannot exceed 30 days.

  5. Read the Certificate Management Service Agreement, click Buy Now, and complete the payment.

    After the purchase, you can view the created compliant CA on the Private Certificate Management page in the Certificate Management Service console, under the Compliant CA tab. After the root CA is created, the Status of the compliant root CA is Disabled by default.

Step 2: Enable the compliant CA

Enabling the compliant root CA creates a compliant subordinate CA. After you confirm the enablement, your enterprise information is submitted to iTrusChina for qualification review. After the review is approved, the system automatically creates a subordinate CA under the compliant root CA.

  1. On the Compliant CA tab, find the target compliant root CA and click Enable in the Actions column.

  2. Enter the information for the compliant root CA.

    Parameter

    Description

    Registered Enterprise Name

    The registered name of the enterprise associated with this CA. The name can be in Chinese or English.

    Unified Social Credit Code

    The 18-digit Unified Social Credit Code of the enterprise associated with this CA. If the enterprise has not yet obtained a three-in-one business license , enter the business license registration number.

    Department Name

    The department name of the enterprise associated with this CA, such as the IT department.

    Landline Phone Number

    The landline number of the enterprise associated with this CA.

    Administrator Email Address

    The email address of the enterprise administrator.

    Administrator Name

    The name of the enterprise administrator.

    Administrator Mobile Phone Number

    The mobile number of the enterprise administrator.

    Administrator Identity Number

    The ID card number of the enterprise administrator.

    Application Form

    Upload the application form for the compliant root CA. Perform the following steps:

    1. Click Download Template to download the application form template.

    2. Print the application form.

    3. Fill in the printed application form. After verifying the information is correct, affix the official company seal in the designated area.

    4. Scan or take a photo of the completed and sealed application form, and save it as a JPG, GIF, or PNG file.

      Make sure the image is clear and legible.

    5. Click Upload File to upload the scanned form.

    Business License

    Click Upload File to upload a color scan or photo of the enterprise business license.

    The image must be in JPG, GIF, or PNG format and must be clear and legible. If you use a photocopy of the business license, you must affix the official company seal to the photocopy before scanning or taking a photo.

  3. Complete the configuration.

What to do next

After purchasing and enabling the compliant CA, you need to configure private certificates. For more information, see Manage private certificates.