OPTIONAL - CLI - Examination
Test
Open a browser and click RA Web, from the ribbon menu across the top of page from your CA instance.
Click Enroll >> Make New Request
In the Certificate Type drop-down list, select AdministratorEndEntityProfile
In the Key-pair generation selection, select By the CA
In the CN, Common name field, enter cli1
In the Username field, enter cli1
In the Enrollment code field, enter foo123
In the Confirm enrollment code field, enter foo123
Click Download PKCS#12
Save the file
For Keyfactor this is one of our most common support issues, it will simulate the expiry of your client certificate that you use to access EJBCA. In this test you will learn how to reissue the certificate without the EJBCA AdminWeb
TEST
You have now downloaded a P12 certificate. Lets assume 2 years has passed and this certificate has expired. Your goal is to set the end entity status back to NEW and set a new password using the CLI (ejbca.sh) without using the EJBCA Admin Web. Next go to the RA web and reissue the certificate.