Configure a Certificate Root Trust for the Keyfactor Remote CA Gateway

The Keyfactor Remote CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. Gateway requires the use of HTTPS to secure the channel between each Keyfactor Remote CA Gateway ConnectorClosed The Keyfactor Gateway Connector is installed in the customer forest to provide a connection between the on-premise CA and the Azure-hosted, Keyfactor managed Hosted Configuration Portal to provide support for synchronization, enrollment and management of certificates through the Azure-hosted instance of Keyfactor Command for the on-premise CA. It is supported on both Windows and Linux. and the Keyfactor Remote CA Service server(s). This requires an SSLClosed TLS (Transport Layer Security) and its predecessor SSL (Secure Sockets Layer) are protocols for establishing authenticated and encrypted links between networked computers. certificate configured in IIS on the Keyfactor Remote CA Service server(s). This certificate can either be a publicly-rooted certificate (e.g. from DigiCert, Entrust, etc.), or one issued from a private certificate authorityClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. (CA). If your Keyfactor Remote CA Service server is using a publicly rooted certificate, the Keyfactor Remote CA Gateway Connector server may already trust the certificate root for this certificate. However, if you have opted to use an internally-generated certificate, your Keyfactor Remote CA Gateway Connector server may not trust this certificate. In order to use HTTPS for communications between the Keyfactor Remote CA Gateway Connector and the Keyfactor Remote CA Service server with a certificate generated from a private CA, you may need to import the certificate chain for the certificate into either the local machine certificate store on the Keyfactor Remote CA Gateway Connector server on Windows or the root certificate store on Linux.