Preparing for the Keyfactor CA Policy Module
The preparation steps necessary for the Keyfactor CA
A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. Policy Module vary depending on the policy handler or handlers you intend to use.
The policy handlers have the following preparation requirements:
-
RFC 2818 Policy Handler
Before configuring the RFC 2818 Policy Handler, identify the Microsoft certificate templates that should automatically receive a DNS
The Domain Name System is a service that translates names into IP addresses. SAN
The subject alternative name (SAN) is an extension to the X.509 specification that allows you to specify additional values when enrolling for a digital certificate. A variety of SAN formats are supported, with DNS name being the most common. matching the certificate CN
A common name (CN) is the component of a distinguished name (DN) that represents the primary name of the object. The value varies depending on the type of object. For a user object, this would be the user's name (for example CN=John Smith). For SSL certificates, the CN is typically the fully qualified domain name (FQDN) of the host where the SSL certificate will reside (for example servername.keyexample.com or www.keyexample.com). when enrollment
Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). requests reach the CA. You will select these templates from a list during configuration. -
SAN Attribute Policy Handler
Before configuring the SAN Attribute Policy Handler, identify the Microsoft certificate templates that should allow CSR
A CSR or certificate signing request is a block of encoded text that is submitted to a CA when enrolling for a certificate. When you generate a CSR within Keyfactor Command, the matching private key for it is stored in Keyfactor Command in encrypted format and will be married with the certificate once returned from the CA. enrollment requests to submit SANs separately from the CSR, replacing any SANs in the original CSR. You will select these templates during configuration. -
Whitelist Policy Handler
Before configuring the SAN Attribute Policy Handler, identify the Microsoft certificate templates to gate and the machines allowed to enroll from them. Templates gated by this handler are available for enrollment only from machines in the allowed list. Because this handler is intended to force enrollments through the Keyfactor Command server, include your Keyfactor Command server in the allowed list. Enter templates by certificate template name (short name), so gather the exact template
A certificate template defines the policies and rules that a CA uses when a request for a certificate is received. names before configuration.
You will also need to have your Keyfactor product license available for upload into the policy module once installed to activate it.
Was this page helpful? Provide Feedback