Certificate Enrollment Gateway requires a client credential issued from Entrust CA Gateway. In Certificate Enrollment Gateway, the client credential is called the CA Gateway Keystore. Certificate Enrollment Gateway uses this client credential to access and authenticate to Entrust CA Gateway. The client credential must contain a private key and client certificate issued by a Managed CA in Entrust CA Gateway. The file may also include the CA certificate chain. The file must be in PKCS #12 (P12 or PFX), JKS, or JCEKS format.

In Certificate Enrollment Gateway, the client credential is called the CA Gateway Keystore. The CA Gateway Keystore can contain multiple private keys (multiple PrivateKeyEntry entries) and certificates. You can specify the alias of the private key to use for the client credential when you configure Certificate Enrollment Gateway.

To issue a client credential to Certificate Enrollment Gateway, you must configure Certificate Enrollment Gateway as a client in Entrust CA Gateway. In Entrust CA Gateway, you must assign the Certificate Enrollment Gateway client either the integrator or policy-override-tenant role.

See Configuring and deploying CA Gateway for configuring clients in Entrust CA Gateway,