Adding a Certificate Template

RUCKUS One allows you to add a reusable certificate template to simplify certificate management, standardize the certificate issuance process, and ensure consistent security practices.

Complete the following steps to add a certificate template:
  1. From the navigation bar, select Network Control > Service Catalog.
    The Service Catalog page is displayed.
  2. Find the Certificate Management tile and click Add.
    The Add Certificate Instance page is displayed.
  3. Select Device Certificate from the options under Template Instance Type and select Template from the options under Device Certificate Type, then click Next.
    The Add Certificate Template page is displayed.
    Adding a Certificate Template
  4. Complete the following settings on the Template Details page:
    • Certificate Template Name: Enter a name of up to 32 characters for the certificate template.
    • Common Name: Enter a common name. The common name is typically used to convey identity information within the certificate. Variables such as ${USERNAME} are dynamically replaced with the corresponding enrollment value during issuance.
      Note: The Common Name value is used to generate the certificate filename. When configuring the Common Name field in a certificate template, use only variables that resolve to valid filename characters. If the Common Name contains unsupported characters or uses variables that resolve to unsupported characters, certificate generation can fail and prevent workflow enrollment from completing successfully. Example: If the Common Name is configured as ${ROLLUP_DEVICE_NAME}@students.shepherd.com and the ${ROLLUP_DEVICE_NAME} variable resolves to a value such as 2C:7B:A0:C9:34:70, certificate generation can fail because the colon (:) is not a supported filename character.
      The Common Name value must comply with the following requirements:
      • Leading and trailing characters
        • Must not start with a space.
        • Must not end with a space or a period (.).
      • Forbidden characters
        • Must not contain a comma (,), greater-than sign (>), colon (:), double quotation mark ("), vertical bar (|), question mark (?), asterisk (*), backslash (\), or forward slash (/).
        • Must not contain control characters (ASCII 0 through 31) or DEL (ASCII 127).
      • Dots
        • Must not contain only dots (., .., ..., and so on).
        • Must not contain consecutive dots (..).
      • Reserved names
        • Must not be exactly CON, PRN, AUX, or NUL.
        • Must not be exactly COM1 through COM9.
        • Must not be exactly LPT1 through LPT9.
    • Identity Group: Select an identity group from the drop-down list.

      If an Identity Group is not yet defined, you can create a new one; click Add, complete the fields in the Create Identity Group sidebar, and click Apply. You can then select the newly created identity group from the Identity Group drop-down. Refer to Adding an Identity Group for more details.

    • (Optional) Adaptive Policy Set: Select an Adaptive Policy Set from the drop-down list.

      If an Adaptive Policy Set is not yet defined, you can create a new one; click Add, complete the fields in the Add Adaptive Policy Set sidebar, and click Add. You can then select the newly created policy set from the Adaptive Policy Set drop-down. Refer to Creating an Adaptive Policy for more details.

    • Default Access: Select Accept or Reject to define the default access behavior for devices that use this certificate template.
  5. Click Next.
    The Settings page is displayed.
    Configuring More Settings
  6. Complete the following on the Settings page:
    • Onboard Certificate Authority: Select a certificate authority from the drop-down list.

      If an Onboard Certificate Authority is not yet defined, you can create a new one; click Add, complete the fields in the Add Certificate Authority sidebar, and click Save. You can then select the newly created certificate authority from the Onboard Certificate Authority drop-down. Refer to Adding a Certificate Authority for more details.

    • (Optional) Enable Chromebook Enrollment: Toggle the switch on to enable this feature. By default, Chromebook enrollment is disabled.
      Complete the following to configure Chromebook Enrollment:
      • Enrollment Type: Select Device or User from the drop-down list.
      • Existing Certificates: Select one of the following actions from the drop-down list: Do not remove existing certificates, Remove certificates with same common name, Remove certificates with same issuing CA, Remove certificate with same CN or issuing CA, and Remove all certificates.
      • Google API Key: Enter the Google API key. You can configure and obtain the key from the Google Cloud Console: console.developers.google.com
      • Service Account JSON Private Key: Drag and drop the file into the upload area, or click Browse to select a file. You can replace the file by clicking the Change File button, which allows you to browse and upload a new file.
  7. (Optional) Click Show more settings to display the additional settings.
    Complete the following on the Settings page:
    • Validity Period: Specify the certificate validity period.
      Note: The following properties determine the lifespan of the issued certificates. RUCKUS recommends setting the start date to 1 month before issuance to avoid issues with end-user system clocks.
      • Start Date: Select one of the following options:
        • By Date: Select a date from the calendar.
        • Before: Enter a value and select Hours, Days, Weeks, Months, or Years from the drop-down list.
      • Expiration Date: Select one of the following options:
        • By Date: Select a date from the calendar.
        • After: Enter a value and select Hours, Days, Weeks, Months, or Years from the drop-down list.
    • Certificate Strength: Configure the certificate strength settings.
      • Key Length: Configure the key length by dragging the slider. Valid values are 2048, 3072, or 4096.
        Note: The key length does not apply to certificates generated through Chromebook Enrollment or from manually added certificate signing requests (CSRs).
      • Algorithm: Select SHA-256, SHA-384, or SHA-512 from the drop-down list.
    • Organization Info: Complete the following settings:
      • Organization Pattern: Enter the name of the organization.
      • Organization Unit Pattern: Enter the organizational unit or department name.
      • Locality Pattern: Enter the name of the locality.
      • State Pattern: Enter the name of the state.
      • Country Pattern: Enter the name of the country.
  8. Click Next.
    The Summary page is displayed.
  9. Review the Summary page, and click Add to add the certificate template.
    The certificate template is added and displayed on the Certificate Template page. Refer to Managing Certificate Templates for more information.