Configure the following settings for each CA Gateway instance.

CA Gateway Instance Name

A unique name to identify the CA Gateway instance.

CA Gateway URL

The URL of the CA Gateway instance. This URL:

  • Must not contain the API version – for example, it must not contain "/api/v1".
  • Must not end with a trailing slash "/".

For example:

https://cagw.example.com/cagw

Mandatory: Yes.

CA IDs served by this CA Gateway

The identifiers of the Certificate Authorities integrated with this CA Gateway instance.

You can configure this parameter only when the CA Gateway instance is integrated with more than one Certificate Authority.

Mandatory: When the CA Gateway instance is integrated with more than one Certificate Authority.

RA Certificate Profile IDs

The identifiers of the Registration Authority profiles to sign and encrypt SCEP PKI messages.

Choose a key name

New value

A Certificate Authority identifier defined in CA Gateway.

A profile identifier defined in the CA Gateway instance

Mandatory: When more than one SCEP profile is defined in the CA Gateway instance.

Enable TLS

Yes to enable TLS security in connections with the CA Gateway instance; No, otherwise.

Mandatory: No. This option defaults to Yes.

CAGW Keystore File

A CA Gateway keystore file. This file must be a PKCS #12 file containing a private key and client certificate for Certificate Enrollment Gateway.

Specifically, to authenticate in the built-in CA Gateway service of the Certificate Authority solution, you must:

  1. Create and download credentials as explained in Creating CA Gateway API credentials
  2. Paste the PKCS #12 password in the CAGW Keystore Password field of the Certificate Enrollment Gateway configuration.

Mandatory: When Enable TLS is set to Yes.

CAGW Keystore Password

The password of the CAGW Keystore File. 

Mandatory: When Enable TLS is set to Yes.

CAGW Keystore Alias

The alias of the private key entry (PrivateKeyEntry) in the CA Gateway Keystore. Run the following command to list all alias names in the <file> keystore.

keytool -v -list -keystore <file>

Mandatory: When Enable TLS is set to Yes and the CAGW Keystore File contains more than one private key.

CAGW Keystore Type

The type of the CA Gateway Keystore file.

  • PKCS12
  • JKS
  • JCEKS

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to PKCS12.

Trust Store Type

The format of the file containing the CA certificate chain for the CA Gateway client credential. 

Trust Store Type

Description

Additional settings

Reuse keystore file

Re-use the CAGW Keystore File. 

None

PKCS12


Import a PKCS#12 truststore


CAGW Truststore File 

CAGW Truststore Password

JKS


Import a JKS truststore


CAGW Truststore File

CAGW Truststore Password

JCEKS


Import a JCEKS truststore


CAGW Truststore File

CAGW Truststore Password

PEM

Import a PEM-formatted certificate file

CA Certificates File (PEM)

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to Re-use the CAGW Keystore File.

TLS Protocol

The TLS protocol version that the Certificate Enrollment Gateway offers to the CA Gateway instance,

  • System default
  • TLSv1.2
  • TLSv1.3

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to System default.

TLS Cipher Suites

The TLS cipher suites allowed for connections to the CA Gateway instance. Leave empty to use the Java runtime defaults (recommended). 

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to the Java runtime defaults

Keystore Provider

The Java security provider used to load the CAGW Keystore Type. Leave this empty to use the default provider.

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to the default provider.

Truststore Provider

The Java security provider used to load the CAGW Truststore File. 

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to the default provider.

Also trust the built-in system certificates

Yes, to include the built-in system certificate authorities when validating the CA Gateway server certificate. No, to trust only the certificates supplied by the CAGW Truststore File.

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to No.

HTTP Connection Pool Size

The maximum number of connections to the CA Gateway instance.

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to 10.

HTTP Keep-Alive (seconds)

The number of seconds to keep a connection to the CA Gateway instance alive before timing out.

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to 120.

HTTP Retry Count

The number of times a failed connection to the CA Gateway instance will be retried before dropping the connection.

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to 4.

HTTP Retry Interval (seconds)

The number of seconds to wait after a failed connection attempt to the CA Gateway instance before retrying the connection.

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to 0.

Bypass Global Proxy for CAGW/PKIaaS Traffic

Yes, to bypass the cluster Global Proxy and use a proxy server to connect to the CA Gateway instance. No, otherwise.

See below for the additional settings when selecting Yes.

Setting

Description

Default

Proxy Host

The host name of the per-instance HTTP proxy used to reach the CA Gateway. Leave empty to connect directly without a per-instance proxy.

Empty

Proxy Port

The port used by the per-instance HTTP proxy.

80

Proxy Username

The optional user name for a proxy that requires Basic authentication.

Empty

Proxy Password

The password for the proxy user name.

Empty

Connect to Proxy over HTTPS

Yes, to connect to the proxy over HTTPS; No, to connect over HTTP.

No

Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to No.