EverTrust Stream CA

Prerequisites

  • A certificate template should be created in Stream for Horizon to enroll certificates upon.

  • A dedicated Horizon account should be created in Stream and should have all lifecycle permissions on the desired CA. The credentials of this account should be either login and password or a PKCS#12 authentication certificate.

Create the PKI connector

1. Log in to Horizon Administration Interface.

2. Access PKI from the drawer or card: PKI  PKI Connectors.

3. Click on Add icon.

4. Select the correct PKI type.

5. Click on the next button

General tab

6. Fill in the common mandatory fields:

  • Connector Name* (string input):
    Choose a meaningful connector name allowing to identify the mapping between the PKI and the Certificate Profile. It must be unique and must not contain spaces.

  • Proxy (string select):
    If the PKI is not directly reachable from Horizon, you can set up an HTTP/HTTPS proxy to properly forward the traffic.

  • PKI Queue (string select):
    The PKI Queue used to manage the PKI Requests (enrollment, revocation).

  • Timeout (finite duration):
    Represents a predefined interval of time without a PKI response, when the time has passed "Horizon" will cease trying to establish the communication. Must be a valid finite duration.

7. Click on the next button

8. Fill all mandatory fields:

  • Endpoint* (string input):
    Fill in the Stream endpoint url.

  • Template* (sting input):
    Fill in the Stream certificate template to enroll upon.

  • CA (string input):
    Fill in the Stream CA enrolling certificate (internal name).

9. Click on the next button.

Authentication tab

  • Authentication PKCS#12* (import p12):
    Import the PKCS#12 file containing the authentication certificate used to connect to the PKI.

  • PKCS#12 Password* (string input):
    Password used to secure the aforementioned PKCS#12.

  • Login* (string input):
    Enter the login for the dedicated Horizon account on Stream.

  • Password* (string input):
    Enter the aforementioned account’s password .

10. Click on the save button.

You can edit Edit PKI, duplicate Duplicate PKI or delete Delete PKI the Evertrust Stream PKI connector.