Review Service Accounts for the Gateway

The Keyfactor Windows EnrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). Gateway installs two services:

By default, these run as Network Service. To update the user running a gateway service, see Start the Gateway Services.

During configuration of the gateway, you will enter two service accounts from the managed identity provider (Active Directory or Keyfactor Identity Provider) in the gateway configuration to allow the gateway to communicate with the Keyfactor Gateway Receiver and the managed instance of Keyfactor Command. You need to have the credentials information (username and password for Basic authentication or OAuth configuration information for token authentication) ready for these service accounts before you begin your gateway installation. This information will be provided to you by your Keyfactor representative. You may be given just one service account to serve both roles.

The service account that holds the APIClosed An API is a set of functions to allow creation of applications. Keyfactor offers the Keyfactor API, which allows third-party software to integrate with the advanced certificate enrollment and management features of Keyfactor Command. role for the main functionality with the CA and communicates with the managed instance of Keyfactor Command needs to be granted permissions in Keyfactor Command (see Preparing Keyfactor Command for the Gateway).

The service account that holds the Web Proxy role for account synchronization and communicates with the Keyfactor Gateway Receiver does not need any permissions in Keyfactor Command.