Use this procedure if you selected acquire Entrust certificates in step 3 of Set up certificates for a community.
The following are the steps for importing a new Entrust certificate into Activator. Before you can use this procedure, you must consult with your organization’s Entrust administrator about the information required to connect with the Entrust/PKI server and import a new or updated certificate for your community.
Activator fulfills a client role in supporting the certificate management tasks of an Entrust server. The prerequisites for this client-server relationship are your Entrust server and a person who is designated as your organization’s Entrust administrator. Lacking these two requirements, your organization cannot use Entrust certificates in exchanging documents with your trading partners through Activator.
Activator enables an organization with an Entrust/PKI server to create Entrust X.509 certificates.
The following describes the certificate-generation process involving Activator and the Entrust server.
After Activator creates the key pair for signing documents, the application hands the public key to the Entrust server. The Entrust server creates the signing certificate and passes the certificate to Activator. The public key is within the certificate. Activator retains the private signing key. The private signing key is not disclosed to the Entrust server; the private key remains secure within Activator. This guarantees security integrity.
Meanwhile, the Entrust server creates the encryption key pair and creates an encryption certificate, which includes the public key. The Entrust server passes to Activator the encryption key pair and the encryption certificate.