# Create mTLS certificate for Production request
source: https://developer.mastercard.com/identity-insights-for-accounts/documentation/tutorials-and-guides/certificate-creation-tutorial/index.md

## Introduction {#introduction}

MTLS (Mutual Transport Layer Security) is a mutual authentication method for a secure connection between client and server. The Key Management Portal (KMP) is an application available in [Mastercard Connect](https://www.mastercardconnect.com/-/sign-in) as a self-service portal for Mastercard customers, which allows them to request and exchange keys and certificates with Mastercard. The portal provides guided workflows to create and manage requests for key and certificate exchange, as well as an inventory of all PKI for keys and certificates that have been exchanged between you and Mastercard using KMP.

### Prerequisites {#prerequisites}

To access KMP, your company must be registered with Mastercard. Once your company has been setup and given a company identifier (CID), you can sign up for Mastercard Connect.
To sign up, go to [Mastercard Connect](https://www.mastercardconnect.com/-/sign-in) then click **Sign up**. Please contact your Mastercard representative to get help with Mastercard Connect Signup.

## Registration and Access to the Key Management Portal (KMP) {#registration-and-access-to-the-key-management-portal-kmp}

* Sign in at [Mastercard Connect](https://www.mastercardconnect.com/-/sign-in)
* Click Store in the top menu.
* Search for "Key Management Portal card" to **Open** it. You can also select "Administration" under Business capabilities to narrow down the search results.

![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_store.png)

* On the Key Management Portal card, select **Request**.
* Select **Security Officer Level 1** access.
* Click **Request access**.
* A request for access to KMP was submitted to your Mastercard Connect Security Administrator. The designated Security Administrators within your company must approve your request.

## Launching the KMP Application {#launching-the-kmp-application}

* Sign in to [Mastercard Connect](https://www.mastercardconnect.com)
* Click **My Items**.
* Click on the Key Management Portal card to **Open** it.

## Complete the set up in KMP {#complete-the-set-up-in-kmp}

* Your company must have at least 2 active Security Officers on the Key Management Portal to be permitted to create new requests in KMP. If you see the following message when logging into KMP then your company needs to have at least 1 additional Security Officer registered on the Key Management Portal application in Mastercard Connect. To get registered, see Registration and Access to the Key Management Portal. ![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_setup_alert.png)
* **Furthermore,** a **Certificate Management Group email** must be added to your company profile.

## Adding your Certificate Management Group email {#adding-your-certificate-management-group-email}

* Your Certificate Management Group email is an alternative means of communication which the Mastercard Key Management Delivery team will use for crucial communication with your organization and in case there is no longer an active user on the Key Management Portal.
* Follow below steps to add a Certificate Management Group email:

### 1. Click My Company. {#1-click-my-company}

![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_connect.png)

### 2. Click on the pencil icon next to Certificate Management Group Email. {#2-click-on-the-pencil-icon-next-to-certificate-management-group-email}

![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_company_details.png)

### 3. Enter your Certificate Management Group email and click Save. {#3-enter-your-certificate-management-group-email-and-click-save}

![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_group_gmail.png)

## Generate CSR {#generate-csr}

A CSR is an encoded file that provides a standardized way to send a public key as well as some information that identifies your company and domain name. This method will keep your private key secure, at no time will Mastercard see it or be able to recover it.

* Generate a CSR as per the Mastercard Identity Insights application DN requirements.

### Common Name: CID {#common-name-cid}

### Organization: Customer Name {#organization-customer-name}

### Organization Unit: Client-PRD-MII {#organization-unit-client-prd-mii}

### Country: 2-digit ISO Country code {#country-2-digit-iso-country-code}

* This CSR is required to be uploaded on the Certificate Request Form.
* Once you upload your CSR file, Mastercard sets a default 364-day expiry period for the API Signing certificate.

#### Option 1 : {#option-1-}

* You want to generate a new private key and CSR Command to use to generate private key and CSR.
  * Open a terminal to run the openssl commands below to generate the CSR.

    * openssl req -out certreq.csr -keyout cakey.pem -new

##### In the above command: {#in-the-above-command}

**req** : The req command primarily creates and processes certificate requests in PKCS#10 format

**new** : This option generates a new certificate request. It will prompt the user for the relevant field values

**keyout filename** : This gives the filename to write the newly created private key to

**out filename** : This specifies the output filename to write to

```XML
openssl req -out certreq.csr -keyout cakey.pem -new
  ..+.....+...++++++++++++++++*..+..+.......+.....+...+...+....+...+......+..+..........++++++++++++++++++++++*..+....+.....+..+....+..++++++
  ..+.........+...+..+...+...+...+++++++++++++++++++++*.....++++++++++++++++++++++++*....+.......+......+..+.......+...........+....+..++++++
  Enter PEM pass phrase:
  Verifying - Enter PEM pass phrase:
  -----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
  There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
  Country Name (2 letter code) [AU]:us
  State or Province Name (full name) [Some-State]:
  Locality Name (eg, city) []:
  Organization Name (eg, company) [Internet Widgits Pty Ltd]:
  Organizational Unit Name (eg, section) []:
  Common Name (e.g. server FQDN or YOUR name) []:
  Email Address []:

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
```

* Command to use to see the created files
  * openssl ls -ltr
  * Ensure certreq.csr and cakey.pem is created

```XML
openssl ls -ltr

  07/12/2024  02:32 PM             1,862 cakey.pem
  07/12/2024  02:35 PM             1,110 certreq.csr
```

#### Option 2 : {#option-2-}

* You want to use existing private key to generate a new CSR Command to use existing private key and generate CSR
  * Open a terminal to run the openssl commands below to generate the CSR.

    * openssl req -out newcertreq.csr -key cakey.pem -new

##### In the above command: {#in-the-above-command-1}

**key filename** : This specifies the file to read the private key from.

```XML
openssl req -out newcertreq.csr -key cakey.pem -new
  Enter pass phrase for cakey.pem:
  You are about to be asked to enter information that will be incorporated
  into your certificate request.
  What you are about to enter is what is called a Distinguished Name or a DN.
  There are quite a few fields but you can leave some blank
  For some fields there will be a default value,
  If you enter '.', the field will be left blank.
  -----
  Country Name (2 letter code) [AU]:us
  State or Province Name (full name) [Some-State]:
  Locality Name (eg, city) []:
  Organization Name (eg, company) [Internet Widgits Pty Ltd]:
  Organizational Unit Name (eg, section) []:
  Common Name (e.g. server FQDN or YOUR name) []:
  Email Address []:

  Please enter the following 'extra' attributes
  to be sent with your certificate request
  A challenge password []:
  An optional company name []:
```

* Command to use to see the created files
  * openssl ls -ltr
  * Ensure newcertreq.csr is created.

```XML
openssl ls -lt

  07/12/2024  02:32 PM             1,862 cakey.pem
  07/12/2024  02:35 PM             1,110 certreq.csr
  07/12/2024  02:57 PM             1,110 newcertreq.csr
```

* **Commands to use to verify the generated csr and optionally the private key**

      - openssl req -text -in certreq.csr -noout

      - openssl rsa -in cakey.pem -check

```XML
openssl req -text -in certreq.csr -noout
  Certificate Request:
  Data:
  Version: 1 (0x0)
  Subject: C= , ST= , L= , O= , OU= , CN= , emailAddress= 
  Subject Public Key Info:
  Public Key Algorithm: rsaEncryption
  Public-Key: (2048 bit)
  Modulus:
  00:cc:0a:40:d2:b5:85:4f:48:ee:60:86:c3:6c:11:
  fe:30:4b:0e:82:44:46:84:4c:1c:a4:75:55:1b:50:
  e0:c4:8c:dd:ae:bd:17:a2:01:90:f5:ad:da:56:b8:
  ae:35:eb:23:ec:b1:35:d7:62:44:bc:9a:79:2e:5c:
  99:ab:a9:f0:e0:44:ea:d1:29:f4:78:a1:0a:c2:d8:
  7a:71:32:ee:73:a7:35:62:75:12:b8:88:0c:7e:42:
  bf:f7:0a:ee:26:49:ba:ce:4a:52:a5:cf:55:18:5f:
  3b:4c:15:0a:66:5a:45:75:4a:30:5f:31:b0:9e:22:
  4b:6f:59:cf:01:04:9d:8d:9a:ca:a8:37:18:86:78:
  4f:54:3c:96:74:95:ff:d4:a7:36:7d:47:37:a1:6c:
  38:19:36:2e:36:32:1c:27:61:2c:18:3f:91:c0:32:
  99:4a:f5:d7:68:fd:66:65:aa:5b:0d:94:20:f3:8f:
  37:54:f4:bb:62:4b:cc:9a:d3:dd:79:a9:c4:f8:a3:
  92:85:be:06:94:cc:02:f7:2b:02:8e:66:ad:7e:36:
  f3:d1:2b:df:01:7b:5c:ce:69:1c:d7:10:ac:0e:30:
  4e:65:ec:e4:11:a8:81:f8:97:15:db:73:0c:a5:a3:
  6f:8d:c1:35:7b:f0:9a:c4:b1:aa:ff:62:59:19:cb:
  f8:19
  Exponent: 65537 (0x10001)
  Attributes:
  unstructuredName         :
  challengePassword        :
  Requested Extensions:
  Signature Algorithm: sha256WithRSAEncryption
  Signature Value:
  22:f9:93:3d:e7:c0:2a:02:5c:01:2a:85:59:8e:85:6b:4c:72:
  51:0d:b3:a2:1f:ad:e5:aa:9c:6e:b4:85:ff:7b:03:b5:de:0c:
  f2:65:7b:89:23:2e:2c:f7:d9:26:47:5d:2c:2f:3f:85:82:f3:
  bb:88:70:c1:2e:68:8c:e4:b0:79:1d:88:bd:80:76:12:48:6d:
  c3:2b:0a:78:72:22:51:47:4f:d0:51:09:7a:ed:98:a9:b0:85:
  4b:83:88:56:0f:2c:15:d8:d6:e9:e6:9c:d0:a6:2e:e3:12:d8:
  01:c1:2d:c4:5d:ef:33:6a:ac:89:5a:32:29:b4:cd:86:6b:d1:
  9a:1d:dd:26:e4:0d:5c:8f:4a:0c:29:d0:48:1f:7d:b0:49:63:
  e1:d6:68:48:08:6d:b1:44:63:ea:1d:c7:11:d2:37:e6:11:5b:
  62:fc:50:30:ec:9b:6e:39:59:bf:f7:9f:96:87:c2:05:b6:b2:
  d2:5d:f7:f4:ad:94:c6:6a:3c:e4:64:e3:ec:a0:b8:40:f8:30:
  4c:f9:a1:bf:d4:ba:f8:64:7d:dc:bb:54:4d:eb:9b:26:0a:d8:
  68:b3:69:7d:6c:9c:f6:7a:20:46:04:03:06:f3:27:85:93:50:
  38:6b:8b:8d:d2:aa:8d:65:ae:d3:16:83:97:6b:1b:2d:4f:49:
```

```XML
openssl rsa -in cakey.pem -check
  Enter pass phrase for cakey.pem:
  RSA key ok
  writing RSA key
  -----BEGIN PRIVATE KEY-----
  MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDMCkDStYVPSO5g
  hsNsEf4wSw6CREaETBykdVUbUODEjN2uvReiAZD1rdpWuK416yPssTXXYkS8mnku
  XJmrqfDgROrRKfR4oQrC2HpxMu5zpzVidRK4iAx+Qr/3Cu4mSbrOSlKlz1UYXztM
  FQpmWkV1SjBfMbCeIktvWc8BBJ2NmsqoNxiGeE9UPJZ0lf/UpzZ9RzehbDgZNi42
  MhwnYSwYP5HAMplK9ddo/WZlqlsNlCDzjzdU9LtiS8ya0915qcT4o5KFvgaUzAL3
  KwKOZq1+NvPRK98Be1zOaRzXEKwOME5l7OQRqIH4lxXbcwylo2+NwTV78JrEsar/
  YlkZy/gZAgMBAAECggEAHQr+lB+LZLA0Yh/8lBbxkA02+Prf8LfmwdADt7oo7EFC
  0rsOsJw5dobzE7IA9iLMv8WvrMNLlm8EfcFnjERJyZp1tCUdK8h8gCSRNSizQVoV
  IrkYW5Td9mDo8zCmmmOXSALTRc+/xJLVnWxHSS9jQKE5RmuLwM6P3z8w1GvEQ2H6
  h/EfIPbeVhwtTm4/vp7pYJdroAjLc4WtbXHMTyfW8U2ngpoBgXCGRI5eX3MPndqZ
  Ok2LTRutebLQhvkHw/4p3BfjWTMF689y77uY3zKda8GE+E68FsD2+H87sdhTHYX1
  76MiQ6Z+UAw213ynxshRCbu+r/Cow2Qsl9UIAmig2wKBgQDtLsg0I4mvwMPf7WN5
  dsQ9cbgw4EJF7cX7L+A5YabI3eFfyR1ZlyMvUEG5GrH30J1W/4hYZNYdB6sl9Vbo
  oGk1t+5kNZjM+MHSOO/4JCKBGb6PdSo89ES5fZaIg40VSjKlND2DqXyzuZyZHshM
  /IY0fplp0FWx6PjIcqPKoU0dfwKBgQDcOlaI482yjac+maavc8EUv6FMHg9Trc07
  UqHOVCpvDUpfdVHB2fCo3OBsvRtLBbA3r5c+lepvD02Ix+LUy3pUp8ap3y5DnfNd
  bb1yJ4ofLqubl75jJy/B41WA742bTD4AaxRo7w8df+hIMTdwyrAYfl+PvnLkd0+P
  W1gMYTvmZwKBgQDICWGun55bTX+l14fDBIjjrYqEJk+evLfybuF0Y8iPtpqC95K6
  Yb66A706iao5cIeSvTdYHct7dmFBRVcEIW46cSMs/wsdLFwDmiPBq3AyY+0U/uMd
  v4JK0wHnptORdh+at6F97q8OwWeyuISEcaIamf93f88Wmn9gR1ee6UWprwKBgG61
  AOVFpxTYMre8Y9eVV/2HK51pCwlkuGPW8TIYi1BSHQ4JmvTZCyrIBiWDluHK1T/Z
  DC3RDQ2RYsecvAF+3FsMEEk6wTYKg9l2niJxj/SG8IuB55pOi6prDoOHaOcll5F8
  QsFRU4bf0rPf0d/odEeL15waAAWrmJoXMBbhFkyHAoGANVHhUNoWOaTpuACN59vS
  KLxLvZi0HH6zcsXf7gGu5oWQna6vTsWQGXVyCzuI9irOzdSaumHvp6UUCu9gcyQf
  qorc8i4QGM4s0dR68vyhkOlsGjMUipNMn+bk3hUuBYiUR1370alKa63T1zRZROc8
  ck5gDdmQS0S6mKh/BpNOLU0=
  -----END PRIVATE KEY-----
```

Note: To know more about the requirements your CSR must meet, refer to [Mastercard Requirements for CSRs](https://developer.mastercard.com/platform/documentation/security-and-authentication/csr-requirements/).

## Request certificate in KMP {#request-certificate-in-kmp}

* Navigate to Certificate Request Form to create the new certificate request.
* Select "Mastercard Identity Insights" as the Mastercard application name , "New Certificate" as request type and "Production" as the environment.

![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_certificate_request.png)

* Select "Next"
* Select Certificate Profile as "Client" and enter the Mastercard Project Contact Email id.
* Then it shows the DN requirements.

![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_certificate_request01.png)

## Download the certificate/CA Chain/File {#download-the-certificateca-chainfile}

* Login to KMP.
* On the Detail Screen, click **Actions** then **Download**.

![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_download.png)

* Ensure that the "Format PKCS #8" option is selected.

![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_download01.png)

* Select the preferred ordering of Root CA (unless you select the DER format in which case the Root Chain cannot be included).

![](https://static.developer.mastercard.com/content/identity-insights-for-accounts/uploads/kmp_download02.png)

* **Press Download**

The downloaded file will be saved in the default download folder of your browser.

## Following are the several outcomes that may be observed: {#following-are-the-several-outcomes-that-may-be-observed}

* The root chain is always included in the downloaded file containing the certificate and chaining:
  * The downloaded file is a .pem file
  * An extra CA Chain is delivered along with the certificate chaining inside a zip file
