Certificate Manager generates the keys on the host. Specifically:

  • The key resides on the target host unless Issue a single shared certificate for all hosts is enabled in Step 4 - Certificate Details. When this option is enabled, Certificate Manager ignores this strategy and generates the key.
  • Certificate Manager fetches the CSR from the target host and issues the certificate. 
  • Certificate Manager deploys the key and the certificate.

See below for the supported settings.

Key Algorithm

Linux support

Windows support

Supported key sizes

RSA​

(tick) 

(tick)

20248, 3072, 4096

RSA-PSS

(tick) 

(error) 

20248, 3072, 4096

EC

(tick) 

(tick)  

P-256, P-384, P-521

Ed25519

(tick) 

(error) 

Ed448

(tick) 

(error)