EverTrust Stream CA

Prerequisites

  • A certificate template should be created in Stream for Horizon to enroll certificates upon.

  • A dedicated Horizon account should be created in Stream and should have all lifecycle permissions on the desired CA. The credentials of this account should be either login and password or a PKCS#12 authentication certificate.

Create the PKI connector

1. Log in to Horizon Administration Interface.

2. Access PKI from the drawer or card: PKI > PKI Connectors.

3. Click on Add HTTP Proxy.

4. Select the correct PKI type.

5. Click on the next button

General tab

6. Fill in the common mandatory fields:

  • Connector Name* (string input):
    Choose a meaningful connector name allowing to identify the mapping between the PKI and the Certificate Profile. It must be unique and must not contain spaces.

  • Proxy (string select):
    If the PKI is not directly reachable from Horizon, you can set up an HTTP/HTTPS proxy to properly forward the traffic.

  • Queue PKI (string select):
    The PKI Queue used to manage the PKI Requests (enrollment, revocation).

  • Timeout (finite duration):
    Represents a predefined interval of time without a PKI response, when the time has passed "Horizon" will cease trying to establish the communication. Must be in valid finite duration.

7. Click on the next button

8. Fill all mandatory fields:

  • Endpoint* (string input):
    Fill in the Stream endpoint url.

  • Template* (sting input):
    Fill in the Stream certificate template to enroll upon.

  • CA (string input):
    Fill in the Stream CA enrolling certificate (internal name).

9. Click on the next button.

Authentication tab

  • Authentication PKCS#12* (import p12):
    Import the PKCS#12 file containing the authentication certificate used to connect to the PKI.

  • PKCS#12 Password* (string input):
    Password used to secure the aforementioned PKCS#12.

  • Login* (string input):
    Enter the login for the dedicated Horizon account on Stream.

  • Password* (string input):
    Enter the aforementioned account’s password .

10. Click on the save button.

You can edit Edit PKI, duplicate Duplicate PKI or delete Delete PKI the Evertrust Stream PKI connector.