Approving or Denying a Pending Certificate Request

On the Pending tab of the certificates requests grid you can view the Details of a certificate request that required manager approval at the CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. level and choose to Approve or Deny it by clicking the action buttons at the top of the grid. You can also Approve or Deny the request from the Certificate Request Details dialog. The approve and deny operations can be done on multiple requests at once. To select multiple rows, click the checkbox for each row on which you would like to perform an operation, then select an operation from the top of the grid. The right-click menu only supports operations on one request at a time.

  • When you deny a request, you will be prompted to enter a comment regarding the denial. These comments can be delivered to the requester or other interested party using a denied request alert (see Denied Certificate Request Alerts). When a certificate is denied, its status will change to failed and it will move from the pending grid tab to the denied/failed grid tab. The denial comments will display in the Certificate Request Details dialogue.

  • When a request is approved on this page, the certificate will move to the Certificate Search grid (see Certificate Search and Collections) and can be viewed there. If you have configured issued certificate alerts (see Issued Certificate Request Alerts), the requester or other interested party will be notified immediately on approval.

Tip:  The following permissions (see Security Overview) are required to use this feature:

Alerts: Read
Certificate Requests: Manage

Certificate requests with a pending status have generally either been requested using certificate templates requiring manager approval at the CA level or from a CA configured to send all requests to pending automatically.

Figure 114: Certificate Template Requiring Manager Approval

Note:  Certificate requests that require approval at the CA level are supported only for Microsort CAs and select CA gateways. This feature is not supported for EJBCA CAs. Use workflow for configuring Keyfactor Command-level approvals for EJBCA CAs (see Workflow Definitions).