MetaPKI
Prerequisites
Endpoint issuing CA
Create the PKI connector
1. Log in to Horizon Administration Interface.
2. Access PKI from the drawer or card:
.3. Click on .
4. Select the correct PKI type.
5. Click on the next button
General tab
6. Fill in the common mandatory fields:
-
Connector Name* (string input):
Choose a meaningful connector name allowing to identify the mapping between the PKI and the Certificate Profile. It must be unique and must not contain spaces. -
Proxy (string select):
If the PKI is not directly reachable from Horizon, you can set up an HTTP/HTTPS proxy to properly forward the traffic. -
PKI Queue (string select):
The PKI Queue used to manage the PKI Requests (enrollment, revocation). -
Timeout (finite duration):
Represents a predefined interval of time without a PKI response, when the time has passed "Horizon" will cease trying to establish the communication. Must be a valid finite duration.
7. Click on the next button
Details tab
8. Fill in all mandatory fields:
-
Endpoint* (string input):
The MetaPKI Endpoint. -
Endpoint Issuing CA* (string select):
Select the CA that will be issuing the certificates for this connector (from the imported Horizon CAs) -
Profile* (string input):
Example: Applications_Auth_Client_Serveur_SSL. -
Profile Cle* (string input):
Example: Serveur_SSL -
Workflow* (string input):
Example: S_LOCAL_SOFT -
Form Porteur Name (string input)
-
Valid Days (finite duration)
Certificate lifetime in days (must be a valid finite duration).
9. Click on the next button.
Authentication tab
10. Fill in the PKI-authentication fields:
-
Authentication Credentials* (select):
SelectCertificate
credentials containing the authentication certificate used to connect to the PKI.
11. Click on the save button.
You can edit , duplicate
or delete
the MetaPKI PKI connector.