Orchestrators

Keyfactor Command uses orchestrators (a.k.a. agents) to manage a wide variety of certificate store types. As of this writing, Keyfactor offers these orchestrators:

Note:  The Keyfactor Mac Auto-Enroll Agent was deprecated as of Keyfactor Command version 11. Any Mac Auto-EnrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). tools and configurations in the product should not be used.

Table 28: Orchestrator Capabilities

 

Universal

Android

Native

Bash

Amazon Web Services Add/Remove

1

 

 

 

Amazon Web Services Inventory

2

 

 

 

Certificate Auto-enrollment

 

 

 

 

Certificate ODKG (on-device key generation, formerly reenrollment)

   

Certificate Renewal

 

F5 (Web Server, SSL Profiles, CA Bundles) Add/Remove

3

 

 

 

F5 (Web Server & SSL Profiles, CA Bundles) Inventory

4

 

 

 
F5 (SSL Profiles & CA Bundles) Discovery 5      

File Transfer Protocol Add/Remove

 

 

 

File Transfer Protocol Inventory

 

 

 

IIS (Personal, Revoked, Trusted) Add/Remove

6

 

 

 

IIS (Personal, Revoked, Trusted) Inventory

7

 

 

 

Java Keystore Add/Remove

8

 

 

Java Keystore Create

9

 

 

Java Keystore Discovery

10

 

 

 

Java Keystore Inventory

11

 

 
Linux Logon Management      
Log Fetching    

NetScaler Add/Remove

12

 

 

 

NetScaler Inventory

13

 

 

 

PEM Add/Remove

14  

PEM Discovery

15

 

 

 

PEM Inventory

16  

Remote CA & Template Synchronization

 

 

 

SSL Discovery & Monitoring

 

 

 
SSH Key Discovery      
SSH Key Generation      
SSH Key Management      

The options available in the Orchestrator Management section of the Management Portal are:

  • Management

    View and configure orchestrators.

  • Jobs

    View active orchestrator jobs and review job errors.

  • Blueprints

    Snapshot the certificate stores and scheduled jobs of one machine and apply them to multiple other similar machines.