Configure the following settings for each CA Gateway instance.
- CA Gateway Instance Name
- CA Gateway URL
- CA IDs served by this CA Gateway
- RA Certificate Profile IDs
- Enable TLS
- CAGW Keystore File
- CAGW Keystore Password
- CAGW Keystore Alias
- CAGW Keystore Type
- Trust Store Type
- TLS Protocol
- TLS Cipher Suites
- Keystore Provider
- Truststore Provider
- Also trust the built-in system certificates
- HTTP Connection Pool Size
- HTTP Keep-Alive (seconds)
- HTTP Retry Count
- HTTP Retry Interval (seconds)
- Bypass Global Proxy for CAGW/PKIaaS Traffic
CA Gateway Instance Name
A unique name to identify the CA Gateway instance.
CA Gateway URL
The URL of the CA Gateway instance. This URL:
- Must not contain the API version – for example, it must not contain "/api/v1".
- Must not end with a trailing slash "/".
For example:
https://cagw.example.com/cagwMandatory: Yes.
CA IDs served by this CA Gateway
The identifiers of the Certificate Authorities integrated with this CA Gateway instance.
You can configure this parameter only when the CA Gateway instance is integrated with more than one Certificate Authority.
Mandatory: When the CA Gateway instance is integrated with more than one Certificate Authority.
RA Certificate Profile IDs
The identifiers of the Registration Authority profiles to sign and encrypt SCEP PKI messages.
Choose a key name | New value |
|---|---|
A Certificate Authority identifier defined in CA Gateway. | A profile identifier defined in the CA Gateway instance |
Mandatory: When more than one SCEP profile is defined in the CA Gateway instance.
Enable TLS
Yes to enable TLS security in connections with the CA Gateway instance; No, otherwise.
Mandatory: No. This option defaults to Yes.
CAGW Keystore File
A CA Gateway keystore file. This file must be a PKCS #12 file containing a private key and client certificate for Certificate Enrollment Gateway.
Specifically, to authenticate in the built-in CA Gateway service of the Certificate Authority solution, you must:
- Create and download credentials as explained in Creating CA Gateway API credentials
- Paste the PKCS #12 password in the CAGW Keystore Password field of the Certificate Enrollment Gateway configuration.
Mandatory: When Enable TLS is set to Yes.
CAGW Keystore Password
The password of the CAGW Keystore File.
Mandatory: When Enable TLS is set to Yes.
CAGW Keystore Alias
The alias of the private key entry (PrivateKeyEntry) in the CA Gateway Keystore. Run the following command to list all alias names in the <file> keystore.
keytool -v -list -keystore <file>Mandatory: When Enable TLS is set to Yes and the CAGW Keystore File contains more than one private key.
CAGW Keystore Type
The type of the CA Gateway Keystore file.
- PKCS12
- JKS
- JCEKS
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to PKCS12.
Trust Store Type
The format of the file containing the CA certificate chain for the CA Gateway client credential.
Trust Store Type | Description | Additional settings |
|---|---|---|
Reuse keystore file | Re-use the CAGW Keystore File. | None |
PKCS12 | Import a PKCS#12 truststore | CAGW Truststore File |
CAGW Truststore Password | ||
JKS | Import a JKS truststore | CAGW Truststore File |
CAGW Truststore Password | ||
JCEKS | Import a JCEKS truststore | CAGW Truststore File |
CAGW Truststore Password | ||
PEM | Import a PEM-formatted certificate file | CA Certificates File (PEM) |
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to Re-use the CAGW Keystore File.
TLS Protocol
The TLS protocol version that the Certificate Enrollment Gateway offers to the CA Gateway instance,
- System default
- TLSv1.2
- TLSv1.3
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to System default.
TLS Cipher Suites
The TLS cipher suites allowed for connections to the CA Gateway instance. Leave empty to use the Java runtime defaults (recommended).
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to the Java runtime defaults
Keystore Provider
The Java security provider used to load the CAGW Keystore Type. Leave this empty to use the default provider.
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to the default provider.
Truststore Provider
The Java security provider used to load the CAGW Truststore File.
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to the default provider.
Also trust the built-in system certificates
Yes, to include the built-in system certificate authorities when validating the CA Gateway server certificate. No, to trust only the certificates supplied by the CAGW Truststore File.
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to No.
HTTP Connection Pool Size
The maximum number of connections to the CA Gateway instance.
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to 10.
HTTP Keep-Alive (seconds)
The number of seconds to keep a connection to the CA Gateway instance alive before timing out.
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to 120.
HTTP Retry Count
The number of times a failed connection to the CA Gateway instance will be retried before dropping the connection.
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to 4.
HTTP Retry Interval (seconds)
The number of seconds to wait after a failed connection attempt to the CA Gateway instance before retrying the connection.
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to 0.
Bypass Global Proxy for CAGW/PKIaaS Traffic
Yes, to bypass the cluster Global Proxy and use a proxy server to connect to the CA Gateway instance. No, otherwise.
See below for the additional settings when selecting Yes.
Setting | Description | Default |
|---|---|---|
Proxy Host | The host name of the per-instance HTTP proxy used to reach the CA Gateway. Leave empty to connect directly without a per-instance proxy. | Empty |
Proxy Port | The port used by the per-instance HTTP proxy. | 80 |
Proxy Username | The optional user name for a proxy that requires Basic authentication. | Empty |
Proxy Password | The password for the proxy user name. | Empty |
Connect to Proxy over HTTPS | Yes, to connect to the proxy over HTTPS; No, to connect over HTTP. | No |
Mandatory. No. This option appears only when Enable TLS is set to Yes and defaults to No.