CertEurope PKI
Prerequisites
-
A technical account should be created.
-
This technical account must have permissions to enroll and revoke SSL certificates on the desired domain(s).
Limitations
-
Only the following fields are managed:
commonName
andsubjectAltName DNS
. -
For multi-valued fields (SAN DNS), if more data items are provided than configured in CCS for the given "Offer Identifier", the exceeding items will be ignored.
-
All limitations induced by the use of the CCS REST Connector.
Create the PKI connector
1. Log in to Horizon Administration Interface.
2. Access PKI from the drawer or card: PKI > PKI Connectors.
3. Click on .
4. Select the correct PKI type.
5. Click on the next button
General tab
6. Fill in the common mandatory fields:
-
Connector Name* (string input):
Choose a meaningful connector name allowing to identify the mapping between the PKI and the Certificate Profile. It must be unique and must not contain spaces. -
Proxy (string select):
If the PKI is not directly reachable from Horizon, you can set up an HTTP/HTTPS proxy to properly forward the traffic. -
Queue PKI (string select):
The PKI Queue used to manage the PKI Requests (enrollment, revocation). -
Timeout (finite duration):
Represents a predefined interval of time without a PKI response, when the time has passed "Horizon" will cease trying to establish the communication. Must be in valid finite duration.
7. Click on the next button
Details tab
8. Fill in all mandatory fields:
-
Endpoint URL to the CSS partner API* (string input):
URL to access the CertEurope web service API. -
Technical account login* (string input):
Login of the technical account created in CCS, usually an email address. -
Technical account password* (string input):
Password of the technical account created in CCS. -
CCS offer identifier* (string input):
The identifier of the offer within CCS. -
Organization ID* (string input):
Customer organization ID. For French companies, it’s usually the "SIREN". -
Revocation reason (string select):
Select from the drop down the default revocation reason. -
Interval before retrying to retrieve certificate (finite duration):
The default value is set to 21 seconds.
9. Click on the next button.
Authentication tab
10. Fill in the PKI-authentication fields:
-
Authentication PKCS#12* (import):
PKCS#12 file containing the authentication certificate used to connect to the PKI. -
PKCS#12 Password* (string input): Enter the password used to secure the aforementioned PKCS#12.
11. Click on the save button.
You can edit , duplicate
or delete
the CertEurope PKI connector.