Windows Enrollment Gateway

The CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. Gateways by Keyfactor allow organizations to request certificates from cloud-based certificate authorities using standard certificate request tools in the same way as one would request certificates against a local CA. This guide covers installation and configuration of the Keyfactor Windows EnrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). Gateway.

The Keyfactor Windows Enrollment Gateway supports management of digital certificates in an EJBCA CA hosted in a cloud-based environment managed by Keyfactor. The gateway runs and behaves in a similar manner to an Enterprise CA in your local environment without the overhead of needing to manage a full Enterprise CA implementation. This allows the gateway the ability to perform end-to-end certificate lifecycle within the enterprise.

The following certificate management functions are supported by the gateway, when used in conjunction with your managed instance of Keyfactor Command:

Note:  Certificate revocation is supported using your managed instance of Keyfactor Command but not through the gateway.

The gateway implementation includes synchronization of user accounts and groups from your local forestClosed An Active Directory forest (AD forest) is the top most logical container in an Active Directory configuration that contains domains, and objects such as users and computers. to the managed forest to ease management of access control for the supported certificate management functions. A highly available solution can be supported by implementing two or more instances of the Keyfactor Windows Enrollment Gateway, both directed to the same managed instance of Keyfactor Command and configured with the same set of templates. The Keyfactor Windows Enrollment Gateway does not support Microsoft failover clustering.

Note:  Account synchronization is not supported if OAuth is used as the authentication option to connect to the managed instance of Keyfactor Command.

The Keyfactor Windows Enrollment Gateway functions by connecting to the Keyfactor Gateway Receiver and managed instance of Keyfactor Command in the managed forest. It uses TLSClosed TLS (Transport Layer Security) and its predecessor SSL (Secure Sockets Layer) are protocols for establishing authenticated and encrypted links between networked computers. version 1.2 for all APIClosed An API is a set of functions to allow creation of applications. Keyfactor offers the Keyfactor API, which allows third-party software to integrate with the advanced certificate enrollment and management features of Keyfactor Command. communications.