Skip to main content

System Status: 

InCommon Certificate Enrollment Guide

Learn how to request an InCommon Digital Certificate.

InCommon Service – Certificate Authority Change

The UC San Diego InCommon service has changed Certificate Authorities from Sectigo to CERTInext. Please update any bookmarks accordingly. 

 

UC San Diego is using the CERTInext platform a US-based certificate lifecycle management (CLM) and Public Key Infrastructure (PKI) platform, as our InCommon Service certificate authority.

Registration and login

Register

To register for access, email pki-certs@ucsd.edu with your name, UC San Diego email, and your work group. Allow 24 hours for a response. 

Follow the activation link in the onboarding email. Create a local account on the CERTInext console. This allows CERTInext to authenticate your access, and provide an alternate login if UC San Diego's SSO interface is down.

Login using SSO

Go to the CERTInext Institutional login page and choose the orange "Sign in with your institution" button. Follow the prompts to sign in with UC San Diego's Single Sign On (SSO) option.

Once you have logged in, you will see the user dashboard.

Choose your group. If your group is not in the list, select UCSD.

Screen shot of GUI top right field where Group needs to be chosen.

Note: If you have issues, email pki-certs@ucsd.edu. Include any error messages.

Create a new certificate

Step 1 - Choose Product & Validity

Click the black New Certificate button in the upper-left menu bar to create an enrollment request. Then follow the 7-step certification process.

User dashboard with arrow pointing at new certificate.

In the Certificate menu, start with Step 1, Product and Validity Group.


Choose the New Certificate button.



  1. Complete the enrollment screens and be sure to include your contact information so you can receive the download links by email.
    1. Group: If your group or department is not listed, select UCSD as the default. To request that your group be added to the platform, email pki-certs@ucsd.edu.
    2. CA Source: Choose emSign.
    3. Certificate Type: SSL/TLS Certificates
    4. Product:
      1. InCommon OV SSL certificate: Choose this if your webserver responds to one domain name. 
      2. InCommon OV SSL UCC certificate: For multi-domain version of the above. For example, if your webserver responds to more than one name. 
        • If you select the UCC certificate type, you can use the drop down to select the number of SANs up to 100. Above that number is not recommended by our provider to avoid DNS and validation strain.

    5. Complete the enrollment fields
  2. When complete, on the bottom right corner, choose the black Next button.

Step 2 - Certificate Signing Request

You will need your Certificate Signing Request (CSR), to paste into the appropriate field. Then choose the Next button.

Choose Certificate Signing Request

Step 3 - Organizational Information

You may need to add UC San Diego's organization information:

Organization: University of California, San Diego 
Address: 9500 Gilman Drive 
City/State/Zip: La Jolla, CA 92093

Step 3:Organizational information - list UCSD.

Step 4 - Organization Representative Information

The organizational Representative will be pre-filled. Fill in your contact information under Certificate Download Delegation. Your email ID is your UC San Diego email address.

Fields for Organizational Information Rep

Step 5 - Certificate Information

Check the content to make sure it is correct. The domain names should autopopulate from the certificate you previously added.

Step 5 - screenshot certificate information.

Step 6 - Additional Information

Fill in the required information (red *). Tags and remarks fields available if you want to add additional information.

Step 6 screen shot Optional additional information.

Step 7 - Summary and Payment

Review information and choose submit.

Step 7: Summary and payment screenshot

Options

Managing Certificates

Review certificates through the Certificate menu option.
  • Any enrollment requests you submit will remain in your queue for easy management. 
  • The dashboard displays important information such as upcoming expirations and certificate status. 
  • You can renew or revoke certificates from the **Orders** queue (accessible from the left-hand menu).

Revoke Certificate

To revoke a certificate, at the top right of the screen choose the three dot "hamburger menu" option. The option to track, revoke, and download a certificate will appear. 

Screen shot of screen requirements to revoke certificate

For more information, contact pki-certs@ucsd.edu.
For more information, contact pki-certs@ucsd.edu