UPKI Server Certificate Issuance Service¶
Table of Contents
This is a service to issue a server certificate that can be used at
uec.ac.jp through the UPKI digital certificate issuing service of the National Institute of Informatics.The issued server certificate can be used for general applications that use TLS (SSL), such as HTTPS.
証明書の新規発行と更新の手続きは同じです． 更新時にもFQDNの存在やドメイン管理者の確認が義務付けられています． 申請書の提出をお願いいたします．
Submission of application form (user)
Fill out the UPKI SSL サーバ証明書申請書 in the 情報基盤センター申請書一覧 , and submit it to the Information Technology Center Office (4th floor, East Bldg. 3).Please remember to bring your identification card as we will verify your identity.
- For use in research and education:
Both the certificate manager and the application manager on the application form should be .full-time faculty members．
- For use in student circle activities, etc.:
The certificate manager’ on the application form can be a student. The `application manager should be a full-time faculty member (advisor or administrative staff) who is in a position to supervise the organization.
Confirmation and review of application details (Information Technology Center)
Based on the application form, the Information Technology Center will confirm the existence of the FQDN (server name) with the domain administrator of the FQDN.After confirming the existence of the certificate, the application will be reviewed and the result will be sent to the UEC account of the certificate manager and the applicant in charge by e-mail.
Create a CSR (Certificate Signing Request) (user)
管理責任者は 事前準備〜証明書の申請から取得まで に沿って 鍵長が2048bitsの鍵ペア を作成してください． 更新時も新しい鍵ペアを作成 してください．
作成した鍵ペアを使って CSR を作成してください． CSR を作成する際は 主体者 DN の入力が必要です．以下を入力してください．
What to enter
The University of Electro-Communications
New Issue: Attributes omitted, Update: Same as before
Server’s FQDN (host name)
Blank (Specify in the next step.)
The OU attribute should be omitted for new issues. When updating, add the attribute and set the value to the same as before.
To enter a blank field in OpenSSL, enter 「.」 (half-width period).
Creating a TSV (User)
Create a TSV file based on the CSR that you have just created, following the procedure described in 2.2.1.サーバ証明書 in the TSV作成ツール操作マニュアル.
Access the TSVツール and click 作成開始.
For the TSVファイルの種別, select 新規発行申請用TSV if you are issuing a new server certificate,or select 更新申請用TSV if you are renewing an issued server certificate, and click この内容で作成開始.
サーバ証明書の更新時に入力する 失効対象証明書シリアル番号 は， 10進数値 にしてください．16進数値となっているとエラーとなります．
Load the CSR file. In addition, please enter the missing information as follows to create the TSV.
The required fields are 利用管理者 Email and Webサーバソフトウェア名等.
Although 利用管理者氏名 and 利用管理者所属r are not required, they will be embedded in the body of the mail as the address of the mail sent from the application system, so please enter them as much as possible.
Please enter only one-byte characters for 利用管理者 Email.
利用管理者氏名, 利用管理者所属, Webサーバソフトウェア名等 can be entered in both single-byte and double-byte characters.
You will receive an email notification of the issue to the email address you entered in the 利用管理者 Email field. Please make sure to enter an e-mail address that can be received.
Enter the name of the HTTP server or other software that uses the server certificate in Webサーバソフトウェア名等.
(オプション) 同一計算機・同一 OS でホスト名が異なる複数のサーバで一つの証明書を利用する 場合, dNSName の項目を以下の例のように指定してください．
Please send the TSV file generated in the previous step to the Information Technology Center by e-mail. You will be informed of the mailing address by the e-mail in 2.
Application for issuance to the Certification Authority (Information Technology Center)
Based on the TSV file submitted by the user,the person in charge at the Information Technology Center applies to the certificate issuing organization (certification authority) for issuance of the certificate.If there is an error in the TSV file, we will ask the user to correct it as appropriate.
Download the server certificate and intermediate CA certificate. (User)
When the application is accepted by the CA and processing is completed, a notification will be sent to the
利用管理者 Emailentered in the TSV file in 4.The download links for サーバ証明書 and 中間CA証明書 are embedded in the body of the notice, so please save them.
The valid intermediate CA certificate differs depending on whether the server certificate is issued after 19:00 on March 26, 2018 or before 14:00 on March 26, 2018.Please check carefully before use.
Install the server certificate (User)
Please follow the サーバー証明書インストールマニュアル to install the server certificate and intermediate CA certificate on your server.After installation, check the expiration date of the server certificate using a browser.
証明書の更新時にも，新規申請同様にFQDNの存在やドメイン管理者の確認が義務付けられています． 証明書の新規発行・更新 に沿って，申請書の提出をお願いいたします．
After setting up the updated certificate on the server, you need to revoke the old certificate.Please contact the Information Technology Center after completing the replacement of the certificate. It is not necessary to create a TSV file.
When renewing or revoking a server certificate, the 失効対象証明書シリアル番号 should be a decimal value.If the value is a hexadecimal number, an error will occur.
The Information Technology Center does not provide support for key pair generation or installation of server certificates.Please refer to the web pages of the National Institute of Informatics (NII) and the texts available on the Internet and do the work by yourself.In particular, please be sure to check UPKI電子証明書発行サービス（国立情報学研究所）.
If you want to use an SSL server certificate on a virtual domain server,
The SSL server certificate issued this time
The private key (server private key) used to create the TSV file
Make sure to delete (cancel) the passphrase of the private key.
The validity period of the server certificate is determined by the UPKI digital certificate issuing service of the National Institute of Informatics.Please note that the Information Technology Center will not be able to adjust the deadline.
If you set a server name that could be used for phishing as the value of CN or SAN when creating a CSR,the issuance of the certificate will be delayed for legitimacy verification or, in some cases, disallowed.
The audit is conducted by a third-party certification authority.Please note that the Information Technology Center will not be able to provide reasons for delays or denials.
Although the CA does not disclose its criteria, it may delay or deny access to services that may be confused with widely used services such as Google, Microsoft, and Amazon.