Keyfactor
Enterprise CA issuance through Keyfactor's EJBCA engine, authenticated with an administrator client certificate.
Overview
Keyfactor is registered as an issuer type in Cockpit's PKI module. The connector talks to Keyfactor's EJBCA REST API — the enterprise CA engine behind the Keyfactor platform — to enroll and revoke certificates against a specific certificate profile, end-entity profile and CA.
Every call is authenticated by the administrator client certificate on the TLS connection itself — no separate credential is sent.
| Property | Value |
|---|---|
| Issuer type | keyfactor |
| Backend | Keyfactor / EJBCA REST API |
| Authentication | Mutual TLS with an administrator client certificate |
| Issuance model | Synchronous — enrollment returns the certificate directly |
| Key custody | Caller/CSR-based — Keyfactor never returns a private key |
The Keyfactor base URL commonly points at a host on your own network rather than the public internet. Cockpit's outbound connection policy explicitly allows private network ranges for this issuer while still refusing loopback, link-local and cloud metadata addresses.
Configuration
Config fields
| Field | Purpose |
|---|---|
base_url | Base URL of the Keyfactor / EJBCA instance (scheme, host and optional port). |
certificate_profile | EJBCA certificate profile applied to the enrollment. |
end_entity_profile | EJBCA end-entity profile applied to the enrollment. |
ca_name | Name of the CA (as configured in EJBCA) that signs the certificate. |
username_pattern | Optional pattern for the EJBCA end-entity username; {cn} is substituted with the certificate's common name. Defaults to {cn}. |
tls_skip_verify | Optional, non-production only. Accepts a Keyfactor server certificate that fails verification when no trust bundle is supplied. |
Credentials
| Field | Purpose |
|---|---|
client_cert_pem | PEM-encoded administrator client certificate presented for mutual TLS. |
client_key_pem | PEM-encoded private key matching the client certificate. |
tls_ca_pem | Optional PEM trust bundle for validating the Keyfactor server certificate. |
enrollment_password | Optional end-entity enrollment password, required by some end-entity profile configurations in addition to the client-certificate identity. |
All four fields are encrypted at rest and never echoed back by the platform.
Registering the issuer
Provide the base URL and profiles
Enter the Keyfactor / EJBCA base URL, the certificate profile, end-entity profile and CA name to enroll against.
Upload the administrator client certificate
Provide the client certificate and private key pair used for mutual TLS, and optionally a trust bundle for the server certificate.
Set the username pattern (optional)
Adjust the end-entity username pattern if your EJBCA end-entity profile requires a naming convention other than the plain common name.
Test the connection
Run test-connection to confirm the mutual-TLS identity is accepted and the EJBCA API is reachable.
Issue through the issuer
Request certificates against the issuer; Cockpit submits the CSR and common name for enrollment.
Issuance flow
Enrollment is synchronous: the CSR is submitted and the signed certificate comes back in the same response, with no polling or pending state.
A single authenticated request carries the CSR in and the signed certificate back out.
Supported operations
| Operation | Supported | Notes |
|---|---|---|
| test-connection | Yes | Confirms the mutual-TLS identity is accepted and reports the EJBCA version. |
| issue | Yes | Synchronous PKCS#10 enrollment against the configured profiles and CA. |
| renew | Yes | No native renewal flow — renew re-enrolls with the same request. |
| revoke | Yes | Revokes by certificate serial and issuer distinguished name, with a standard revocation reason. |