Cloud Gateway

Keyfactor Cloud Gateway is a Microsoft-compatible certificate authorityClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. (CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA.) gateway that enables certificate enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). and lifecycle management using cloud-hosted CAs managed by Keyfactor. This guide covers installation and configuration of the Keyfactor Cloud Gateway.

Note:  This documentation covers version 26.2 of the Keyfactor Cloud Gateway.

The Keyfactor Cloud Gateway supports management of digital certificates through a Microsoft CA hosted in a cloud-based environment managed by Keyfactor. The gateway behaves like an Enterprise CA in your local environment without the overhead of deploying and managing a full Microsoft Enterprise CA, enabling end-to-end certificate lifecycle management using standard Microsoft certificate enrollment tools.

The following certificate management functions are supported by the gateway, when used in conjunction with your managed instance of Keyfactor Command:

Note:  Certificate revocation is supported using your managed instance of Keyfactor Command but not through the gateway.

The gateway implementation includes synchronization of user accounts and groups from your local forestClosed An Active Directory forest (AD forest) is the top most logical container in an Active Directory configuration that contains domains, and objects such as users and computers. to the managed forest to ease management of access control for the supported certificate management functions. A highly available solution can be supported using Microsoft failover clustering and the clustering configuration in the gateway.

The Keyfactor Cloud Gateway functions by connecting to the Keyfactor Gateway Receiver in the managed forest. It uses TLSClosed TLS (Transport Layer Security) and its predecessor SSL (Secure Sockets Layer) are protocols for establishing authenticated and encrypted links between networked computers. version 1.2 for all APIClosed An API is a set of functions to allow creation of applications. Keyfactor offers the Keyfactor API, which allows third-party software to integrate with the advanced certificate enrollment and management features of Keyfactor Command. communications.