How-To: Issue a Server Certificate in Keytos Shield

Learn how to create a custom server certificate in seconds with Keytos Shield, the leading cloud PKI and RADIUS solution for Microsoft and Entra ID customers.

What Is a Server Certificate in Keytos Shield?

A server certificate is issued by Shield’s certificate authority (CA), with custom subject, names, lifetime and usages that you determine. This is most useful for anything that needs to trust Shield in your network: servers, appliances, domain controllers, or devices that don’t fit the built-in RadSec flow.

What Fields Can Be Configured for Server Certificates in Keytos Shield?

In Keytos Shield you can create a server certificate tailored to your environment’s specific needs. To make this possible, you can customize the following:

Field Description Example
Subject name The primary name for the certificate. Used to identify the certificate. CN=mysite.internal
Subject Alternative Names The secondary names for the certificate. Can be used to identify the certificate See SANs DNS: radius.contoso.com
Validity Period How many days the certificate is valid. Defaults to the longest lifetime your CA allows, which is also the maximum. 365 days
Extended Key Usages (EKUs) What the certificate can be used for. Client Authentication and Server Authentication are selected by default, and only EKUs your CA can issue are shown. At least one is required with Generate locally. With Import CSR, they’re added to the EKUs the CSR already has. See EKUs. Server Authentication

What Extended Key Usages Can Be Configured for Server Certificates in Keytos Shield?

Keytos Shield supports the following EKUs for server certificates:

EKU OID Description
Client Authentication (default) 1.3.6.1.5.5.7.3.2 Allows the server to prove its identity when authenticating as a client (e.g. mutual TLS or RadSec).
Server Authentication (default) 1.3.6.1.5.5.7.3.1 Allows the server to prove its identity to clients that connect to it. Required for all TLS and RADIUS server certificates.
Code Signing Authentication 1.3.6.1.5.5.7.3.3 Allows the certificate to sign code.
Email Protection Authentication 1.3.6.1.5.5.7.3.4 Allows the certificate to sign and encrypt email (S/MIME). Use with an RFC822 Name Subject Alternative Name.
IP Sec End System Authentication 1.3.6.1.5.5.7.3.5 This EKU is for hosts that use IPsec directly. Only select this if your device’s documentation requires it.
IP Sec Tunnel Authentication 1.3.6.1.5.5.7.3.6 This EKU is for gateways that terminate IPsec tunnels. Only select this if your device’s documentation requires it.
IP Sec User Authentication 1.3.6.1.5.5.7.3.7 This EKU identifies a user in IPsec.
Smart Card Logon 1.3.6.1.4.1.311.20.2.2 Allows Windows sign-in to Active Directory with the certificate. Use with a UPN Subject Alternative Name.
KDC Authentication 1.3.6.1.5.2.3.5 Allows a domain controller to prove its identity to clients. Only select this for domain controller certificates.
Document Signing 1.3.6.1.4.1.311.10.3.12 Allows the certificate to sign documents.
Document Encryption 1.3.6.1.4.1.311.80.1 Allows the certificate to encrypt documents.

With Generate locally, the certificate gets only the EKUs you pick. With Import CSR, your picks are added to the EKUs the CSR already asks for.

Keytos Shield Private Key Options: Generate Locally or Import CSR highlighted

What Subject Alternative Names Can Be Configured for Server Certificates in Keytos Shield?

Keytos Shield supports the following types of Subject Alternative Names (SANs) for server certificates:

SAN Description Example
DNS (recommended) Use this SAN for the hostname(s) clients use to reach the server. radius.contoso.com
User Principal Name (UPN) Use this SAN when the certificate will be used to authenticate as an Entra ID account (requires the Client Authentication EKU). radius-admin@contoso.com
URI Use this SAN if the software checking the cert expects a URI identity. urn:contoso:org:service
RFC822 Name (email) Use this SAN when the cert will also be used to sign or encrypt email for a mailbox, such as with S/MIME. alerts@contoso.com
IP Address Use this SAN when clients connect to the server by IP address instead of by hostname. This is similar to a DNS name, however if the server’s IP address changes the certificate must be reissued. 10.0.0.1

Step-by-Step Guide - How to Create and Issue Keytos Shield Server Certificates

Prerequisites for Creating Server Certificates in Keytos Shield

Before you begin creating server certificates in Keytos Shield, ensure that you have completed all the necessary prerequisites:

  1. The Keytos Entra ID applications are registered in your tenant.
  2. You have signed up for a Keytos Shield Plan.
  3. You are a Subscription Owner or Network Administrator.
  4. You have completed the Keytos Shield Network Security onboarding

How to Create a Server Certificate in Keytos Shield

  1. Navigate back to your Keytos Shield portal

  2. Using the left-hand menu expand Network Security and click Network profiles

    Keytos Shield Network Profiles page with Settings tab highlighted
  3. Scroll to the Create Certificate section and expand it.

    Keytos Shield Network Profiles page with Create Certificate section highlighted
  4. For What type of certificate do you want to create select Custom.

    Keytos Shield Network Profiles page with Server Certificate button highlighted
  5. Add the subject name in format CN=server1.contoso.com, OU=Custom Contoso Certificate, DC=contoso.

    Keytos Shield create a new server certificate with Subject Name highlighted
  6. The Domain Controller GUID and Domain Controller SID are only necessary for domain controller certificates. If you are trying to create a domain controller certificate, please follow our dedicated guide here.

  7. Enter any Subject Alternative Names (SANs) that you would like to include in the certificate. This can include DNS names, IP addresses, or other identifiers depending on your needs.

    Keytos Shield create server certificate page for with add DNS names button highlighted
  8. Set the Validity Period of your certificate to determine how long you would like the certificate to be valid for.

  9. Expand the Advanced Settings section and ensure that you have the necessary EKUs enabled for your needs. The defaults are Client Authentication and Server Authentication, which are necessary for a client to prove its identity to a server, and for a server to prove its identity to a client.

  10. For Private key, select either Generate Locally or Import CSR, depending on your scenario.

    • If you select Generate Locally, Keytos Shield will generate the private key for the certificate in your browser and then issue the RadSec client certificate. The private key never leaves the browser and you can download both the certificate and the private key.
    • If you select Import CSR, you will need to provide a Certificate Signing Request (CSR) from your network device for Keytos Shield to issue the RadSec client certificate. Click How to Create a CSR for guidance on generating a CSR from your device.
  11. Click Create certificate.

  12. Once the certificate has been created, click Download Certificate and Download Private Key (if applicable). These should download as certificate.cer and certificate.key, respectively.

    Keytos Shield Network Profiles Page with download server client certificate and private key button highlighted