---
title: "Sign the CSR for the Enterprise Certificate Authority"
canonical: "https://docs.aryaka.com/space/KNOW/1268776999/Sign%20the%20CSR%20for%20the%20Enterprise%20Certificate%20Authority"
format: markdown
---
Every Aryaka customer is assigned a  customer certificate authority  by default.  Aryaka Secrets Manager (ASM)  generates the private key for the customer and stores it securely. This private key is used to generate a  certificate signing request  (CSR). By default, the CSR is signed by an Aryaka intermediate certificate authority for ease of onboarding. If you prefer, the CSR can be signed by a customer-selected certificate authority known as the  enterprise CA .  While there are several ways to manage a private certificate authority and have it sign new intermediate certificate authorities, this document describes using  OpenSSL  to do so. OpenSSL is a free open-source cryptography toolkit that is commonly used to secure communications. To ensure your certificate authority can sign other CAs Your certificate authority’s  .conf  file must include a multi-value extension that is configured to allowed it to sign other CAs as shown in the following example: [ intermediate_ca_ext ]
keyUsage                = critical,keyCertSign,cRLSign
basicConstraints        = critical,CA:true
subjectKeyIdentifier    = hash
authorityKeyIdentifier  = keyid:always
authorityInfoAccess     = @issuer_info
crlDistributionPoints   = @crl_info Note that the  basicConstraints  value (line 3 in the example) does  not  include the  pathlen  parameter that determines the maximum number of CAs that can follow this one. If a CA includes a  pathlen:0  parameter, it  cannot  sign additional CAs.  To use OpenSSL to sign the CA Download the CSR: Log into MyAryaka. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Certificate Authority  in the Vault tile. The Certificate Authority page appears.   Click  Generate CSR  in the Use Enterprise CA pane. The Certificate Authority dialog appears with all fields populated with a default value: Edit one or more of the fields as appropriate, then click  Generate CSR . A certificate signing request is downloaded to your local computer’s default download directory as a .csr file. Sign the downloaded CSR using the  openssl  command: openssl ca -config <path to the conf file> -in <path to csr> -out <path to output crt file> -extensions <extension name> For example: openssl ca -config ca/aryaka-root-ca/aryaka-root-ca.conf -in ca/aryaka-intermediate-cust-123-ca/aryaka-intermediate-cust-123-ca.csr -out ca/aryaka-intermediate-cust-123-ca/aryaka-intermediate-cust-123-ca.crt -extensions [ intermediate_ca_ext ] Upload the signed  .crt  file to MyAryaka from the Certificate Authority page:   Click  Upload Signed CA  in the Use Enterprise CA pane. The Upload Signed Certificate dialog appears. Click  Browse  then select this  .crt  file. Click  Upload . Related topics Manage certificate authority     Dynamic certificate generation and SSL interception