See below for the new features in Certificate Enrollment Gateway for Cryptographic Security Platform 1.5.0.
- Support for multiple CA Gateway instances (CEG-3668)
- Authentication error messages always logged for some successful EST operations (CEG-3729, CEG-3287)
- Support for TLS-ALPN-01 validation for ACMEv2 enrollment (CEG-3647)
- Reduced permissions for security groups created by InstallEnrollmentService.ps1 (CEG-3617)
Support for multiple CA Gateway instances (CEG-3668)
Starting in this release, Certificate Enrollment Gateway now supports multiple CA Gateway instances. Certificate Enrollment Gateway supports up to 20 CA Gateway instances.
See CEG Deployment Type: CA Gateway for details on the new options.
Authentication error messages always logged for some successful EST operations (CEG-3729, CEG-3287)
Previously, EST operations that completed successfully could still produced error entries in the audit log. This issue could occur during a request for the certificate request attributes of a profile that did not define any such attributes, and during the first exchange of an operation authenticated with a username and password. This issue could occur because anything that interrupted the normal path of an EST request was recorded in the audit log as a failure, with no distinction between a real problem and an ordinary step of the protocol.
This issue is fixed in this release. Starting in this release:
- Some log messages for an EST operation that were recorded as an error despite being a normal part of the protocol are now logged as information. For example, if an EST client does not send any credentials in the first message (expected with some EST clients), this message is logged as information instead of an error before credentials are requested by the client.
- A failure entry also now identifies the tenant, Certification Authority (CA), and related profile. Previously only a success entry identified this information.
- A profile without certificate request attributes is now noted in the ordinary product log.
Support for TLS-ALPN-01 validation for ACMEv2 enrollment (CEG-3647)
Starting in this release, ACMEv2 enrollment supports TLS-ALPN-01 validation. To support this validation, the following new ACMEv2 settings have been introduced in this release:
- ACMEv2 TLS-ALPN-01 Port specifies the TCP connection port that the ACMEv2 service uses when performing TLS-ALPN-01 validation. RFC 8737 mandates port 443. Using a different port is intended for testing only.
- ACMEv2 TLS-ALPN-01 Connect Timeout specifies the number of milliseconds to wait when opening the TLS-ALPN-01 validation connection before timing out. The default value is 10000 (10 seconds). The minimum permitted value is 1000. Set to 0 to wait indefinitely (no connect timeout).
- ACMEv2 TLS-ALPN-01 Read Timeout specifies the number of milliseconds to wait during the TLS-ALPN-01 validation handshake before timing out. The default value is 10000 (10 seconds). The minimum permitted value is 3000. Set to 0 to wait indefinitely (no read timeout).
Reduced permissions for security groups created by InstallEnrollmentService.ps1 (CEG-3617)
For WSTEP enrollment, the InstallEnrollmentService.ps1 script allows you to create, edit, and remove enrollment services in Active Directory. This script can create and assign security groups to these enrollment services. Previously, the security groups created by the InstallEnrollmentService.ps1 script were given the Full Control permission to the enrollment services. Starting in this release, the security groups created by the InstallEnrollmentService.ps1 script are given only the Read permission to the enrollment services.