You may need X509 V2 attribute certificate ([RFC3281]) for signing public key certificate. The private key and certificate of the attribute authority which issues your attribute certificate can be found in the CryptographicMaterial. Thus you can issue your own your attribute certificate for yourself by some security toolkits.
However the Plugtests service can also issue your attribute certificate if you need. To get your attribute certificate, go the the menu Attribute Certificate Request on the left menubar and upload the X.509 certificate.
Here is the profile of the attribute certificate.
Attribute Certificate:
acinfo:
acHolder: YOUR-DN
acIssuer: CN=Attribute Authority,OU=Plugtests STF-351 2008-2009,O=ETSI,C=FR
serialNumber: UNIQUE-NUMBER-FOR-THE-AC
validity: 20090101000000Z - 20100101235959Z
attributes:
role: uri:etsi.pades.plugtests.201111.participants
extensions:
authorityKeyIdentifier:
noRevAvail:
signatureAlgorithm: SHA1
signature:
This figure shows PKI trust model and attribute certificate issuance for
this plugtest.