Root and intermediate certificate checklist

This checklist assumes that you are serving as you own CA (Certificate Authority). It summarizes the steps for setting up digital certificates using the Workbench User Key Store of a physically and electronically secure computer.

Use the check list to make sure you perform all necessary configuration tasks.

c Computer and device network disconnected from the company LAN and global Internet.

c Needed certificates identified: one root CA certificate, two or more intermediate certificates (optional) and one server certificate per controller. You need a code-signing certificate if you will be customizing the system by adding program objects. .

c Logical certificate naming convention established (a naming convention is not required, but it will help you differentiate among your certificates).

c CSR folder structure under the certManagement folder in the niagara_user_home created.

c Root CA certificate and any intermediate certificates created.

c CSR for each intermediate and code-signing certificate created.

c Any intermediate and code-signing certificates signed using the root CA certificate.

c Any signed intermediate certificates imported back into the Workbench User Key Store where they were originally created.

c Backup of the root CA certificate and the signed intermediate certificates created.

c Root CA certificate with only its public key exported in preparation to import it into the platform/station Trust Stores.