Description
Security Certificates (also known as SSL, TLS or X.509 certificates) are used on leased equipment in the Platform Hosting environments within the data center and by external CDT customers. These certificates are a non-proprietary protocol for securing data communications across computer networks and provide data encryption while in transit for TCP/IP connections.
As an alternative, CDT also offers delegated administrator access to customers who prefer to generate and manage their own certificates. Customers utilizing this option are provided access to CDT’s certificate console and are granted permission to issue certificates under approved third-level domains or specific URLs within root domains.
CDT provides version(s) of certificates in accordance with current certificate industry standards. Certificates are offered on both dedicated and virtual server platform configurations. CDT is authorized to offer certificates only for the following domains:
- .ca.gov
- .california.gov
- .cahwnet.gov
- .state.ca.us
Included
- Contract management and licensing for certificate management software.
- Liaison between the customer and the certificate vendor for technical issues.
- Customers notifications of upcoming renewals in accordance with the contact information provided on the Security Certificate Submittal.
- Technology products must be within vendor supported versions to sustain availability and integrity.
Scheduling
CDT’s goal is to provide timely, comprehensive and economical technology services. Requests for new certificates will typically be available 3 to 5 business days after the Case/Request has been approved by all parties. Certificate renewals are processed a week prior to the current certificate expiration date. If a renewal is needed earlier, please note the requested delivery date on the Case/Request. Certificates expire on the final day of issuance at 1700 hours. Delays in the Case/Request process, or server availability to obtain the certificate, may impact the timeliness of the certificate delivery. A 25-calendar day window is provided immediately following delivery of a certificate for testing, revocation or changes.
Roles & Responsibilities
Task/Role | CDT | Customer |
---|---|---|
Submit ServiceNow request for all Certificate and Sectigo service needs. | X | |
Issuance of all certificates including new and renewals. | X | |
All certificate installations including new and renewed certificates. | X | |
All new Wildcard SSL certificates. Note: Security Assurance Group approval (via a ServiceNow request) is required prior to requesting a new certificate. | X | |
Create CSR files. | X | |
Debug issues with CSR files. | X | X |
Facilitate EV certificates with Sectigo and Customer. Note: Customer submits ServiceNow Request. | X | |
Co-ordinate with Customer regarding issuance of the certificate. Note: Customer submits ServiceNow Request. | X | |
Add certificate issuance sub-domains under subdomain.ca.gov domains for a department. Note: Customer submits ServiceNow Request. | X | |
Provide delegated administration to a requesting Customer/Department. Note: Customer submits ServiceNow Request. | X | |
Provide support for issues related to SSL/Certificate issuances. Note: Customer submits ServiceNow Request. | X | |
Work with Sectigo Support for issues related to SaaS based patches and other service-related escalations. Note: Customer submits ServiceNow Request. | X | |
Reporting and modifications of existing certificates and administrators. Note: Customer submits ServiceNow Request. | X | |
Provide ServiceNow ticket management related to Secure Certificate services. Note: Customer submits ServiceNow Request. | X | |
Manage contract and renewal of Sectigo contract. | X | |
Notify Certificate_Services@state.ca.gov of changes to the certificate contact(s). | X | |
Provide a distribution list or a minimum of three email addresses to CDT which will be used to receive the certificate alert notifications. | X |
Rates
Subscriptions to this service are available. The costs are included in the Statewide Innovation and State Web Portal fee.
Request Service
Service Request Name | Link |
---|---|
Add, Change or Delete Security Certificates and/or CSR Files Request to Add, Change, and Delete Security Certificates and CSR files, or ask a general question by submitting a Case/Request. A completed Security Certificate Submittal is required for new certificates and renewals prior to the start of work. Please submit one form per URL, except in the case of SAN certificates. All information must be included in, or attached to the Case/Request. Multiple submittal forms may be attached to a single Case/Request. Customers requesting to use the delegated administration option should submit the Delegated Administrator Security Certificate Submittal to initiate service setup. Cases/Requests for individual certificates are not necessary. | Order Security Certificate Services |
Service Level Objectives
Service option | Fulfillment timeframe SLO | Notes/dependencies |
---|---|---|
New Secure Certificates (Customer Install) | 95% within 5 Business Days | Dependencies/Assumptions (applies to all the requests for new SSL certificate)
|
New Secure Certificates (CDT Install) | 95% within 10 Business Days | Dependencies/Assumptions (applies to all the requests for new SSL certificates)
|
Secure Certificates Renewal (Customer Install) | 95% within 5 Business Days or within requested completion date if the renewal request is submitted 20 days prior to the expiration date | Dependencies/Assumptions (applies to all the requests for renewal of SSL certificates)
|
Secure Certificates Renewal (CDT Install) | 95% within 10 Business Days or within requested completion date if the renewal request is submitted 20 days prior to the expiration date | Dependencies/Assumptions (applies to all the requests for renewal of SSL certificates)
|
Questions/Inquiry (New Domain Name Enrollment, Password Reset, Delegated Admin, SSL Certificate Notification Suspension, Other) | 95% within 5-10 Business Days depending on request type | Dependencies/Assumptions
|
FAQs
1. Is there a document that outlines the process, technical questions, and roles and responsibilities?
Yes. To request a copy of the Guidelines or the Submittal Process document, please contact us by telephone at (916) 464-4311 or email at ServiceDesk@state.ca.gov. In addition, if you would like the document in an alternative format or request any other reasonable accommodation, we will work with you to make that information available.
2. Who applies the certificates?
Certificate application is included in the offering with an associated cost where CDT manages customer web servers, certificate procurement, installation, and administration.
Self-managed is a no-cost option which offers customers delegated administrator access. Customers utilizing this option are provided access to CDT’s certificate console and are granted permission to issue certificates under approved, third level domains or specific URLs within root domains.
3. Does my ID or password expire?
The ID does not expire. The password expires every 90 days.
4. Does CDT provide training for the delegated administrator portal?
Once enrollment is complete, each customer is emailed a PowerPoint presentation along with their login information. If additional training is required, a personal training session is scheduled.
5. How is training conducted (classroom, conference call or WebEx)?
Training is delivered remotely via conference call.
6. How long is the training session?
Approximately 30 minutes.