IdExchange 1.9.1

Updating the Enrollment Agent

The credentialing system will use the Enrollment Agent (EA) to sign the request sent to the certificate authority. The CA validates this signature to ensure the certificate is valid and is authorized. The procedure below is for updating the EA credential. Please note that your process may be different based on internal security policies. 


Step Number

Description

Example

1

Log in as the CMS Service Account.

*It is important to login with the CMS service account so that the CMS can use the same account to locate the certificate during the issuance process.


2

Open the Certificate MMC Snap It, go to Current User, Personal Certificates

image2020-6-24_6-52-28.png

3

Locate the certificate with the containing

  • Intended Purposes: Certificate Request Agent

  • Certificate Template: Enrollment Agent

image2020-6-24_6-54-19.png

4

Right click on the certificate, select all tasks, request certificate with new key.

image2020-6-24_6-55-0.png

5

Click Next

image2020-6-24_6-55-28.png

6

Verify the Enrollment Agent policy is selected, press enroll

image2020-6-24_6-56-26.png

7

Press the finish button.

image2020-6-24_6-56-40.png

8

If a new certificate was generated, backup old (expired) and then delete the old (expired) certificate from the certificate store.