Certificate Manager generates the keys on the host. Specifically:
- The key resides on the target host unless Issue a single shared certificate for all hosts is enabled in Step 4 - Certificate Details. When this option is enabled, Certificate Manager ignores this strategy and generates the key.
- Certificate Manager fetches the CSR from the target host and issues the certificate.
- Certificate Manager deploys the key and the certificate.
See below for the supported settings.
Key Algorithm | Linux support | Windows support | Supported key sizes |
|---|---|---|---|
RSA | |
| 20248, 3072, 4096 |
RSA-PSS |
|
| 20248, 3072, 4096 |
EC |
|
| P-256, P-384, P-521 |
Ed25519 |
|
| — |
Ed448 |
|
| — |