EJBCA PKI
Prerequisites
-
A certificate profile should be created, e.g. reusing the default "SERVER" certificate profile.
-
An authentication certificate should be issued for Horizon, and it should be given certificate issuance and revocation permissions on the aforementioned certificate procedure.
Limitations
-
Only the following fields are managed: all Subject DN fields and
subjectAltNames DNS, IPaddress, RFC822Name, msUPN
andmsGUID
. -
For multi-valued fields (SAN DNS and
RFC822Name
), if more data items are provided than configured in EJBCA for the given End Entity profile, the exceeding items will be ignored. -
All limitations induced by the use of the EJBCA RA SOAP Connector.
Create the PKI connector
1. Log in to Horizon Administration Interface.
2. Access PKI from the drawer or card:
.3. Click on .
4. Select the correct PKI type.
5. Click on the next button
General tab
6. Fill in the common mandatory fields:
-
Connector Name* (string input):
Choose a meaningful connector name allowing to identify the mapping between the PKI and the Certificate Profile. It must be unique and must not contain spaces. -
Proxy (string select):
If the PKI is not directly reachable from Horizon, you can set up an HTTP/HTTPS proxy to properly forward the traffic. -
PKI Queue (string select):
The PKI Queue used to manage the PKI Requests (enrollment, revocation). -
Timeout (finite duration):
Represents a predefined interval of time without a PKI response, when the time has passed "Horizon" will cease trying to establish the communication. Must be a valid finite duration.
7. Click on the next button
Details tab
8. Fill in all mandatory fields:
-
EJBCA RA URL* (string input):
Enter SOAP endpoint URL of the EJBCA WebService. -
EJBCA Certificate Profile Name* (string input):
Enter EJBCA Certificate Profile to map for certificate issuance. -
EJBCA CA Name* (string input):
Enter CA to use for certificate issuance. -
EJBCA End Entity Profile* (string input):
Enter EJBCA End Entity profile.
9. Click on the next button.
Authentication tab
10. Fill in the PKI-authentication fields:
-
Authentication Credentials* (select):
SelectCertificate
credentials containing the authentication certificate used to connect to the PKI.
11. Click on the save button.
You can edit , duplicate
or delete
the EJBCA PKI connector.