Configure Certificate Root Trust for the Universal Orchestrator
Keyfactor recommends using HTTPS to secure the channel between each Keyfactor Universal Orchestrator and the Keyfactor Command server(s). This requires an SSL
certificate configured in IIS on the Keyfactor Command server(s). This certificate can either be a publicly-rooted certificate (e.g. from DigiCert, Entrust, etc.), or one issued from a private certificate authority
(CA
). If your Keyfactor Command server is using a publicly rooted certificate, the orchestrator
server may already trust the certificate root for this certificate. However, if you have opted to use an internally-generated certificate, your orchestrator server may not trust this certificate. In order to use HTTPS for communications between the orchestrator and the Keyfactor Command server with a certificate generated from a private CA, you may need to import the certificate chain for the certificate into either the local machine certificate store on the orchestrator server on Windows or the root certificate store on Linux.
