Zum Hauptinhalt springen
Gilt für:
DuoKey Cockpit v2Nexus Smart ID Certificate ManagerBearer-token or mutual-TLS authentication

Overview​

Nexus Certificate Manager is registered as an issuer type in Cockpit's PKI module. The connector submits enrollment and revocation requests to a Nexus Smart ID CM deployment's REST issuance API, against a configured CA and certificate profile.

Nexus connector architecture
DuoKey CockpitPKI issuer connector — Nexus
bearer API token, or mutual TLS client certificate
Nexus Smart ID CMCertificate Manager REST issuance API
CA + certificate profile
Configured CASigns under the selected profile

A bearer token is attached per request; a client certificate instead authenticates the TLS connection itself.

PropertyValue
Issuer typenexus
BackendNexus Smart ID Certificate Manager REST issuance API
AuthenticationBearer API token (default), or mutual TLS with a client certificate
Issuance modelSynchronous — enrollment returns the certificate and chain directly
Key custodyCaller/CSR-based — Nexus never returns a private key
Enterprise appliances

The Nexus base URL commonly points at an appliance on your own network rather than the public internet. Cockpit's outbound connection policy explicitly allows private network ranges for this issuer while still refusing loopback, link-local and cloud metadata addresses.

Configuration​

Config fields​

FieldPurpose
base_urlBase URL of the Nexus Certificate Manager REST endpoint (scheme, host, optional port and context path).
ca_nameName of the Nexus CA (as configured in Certificate Manager) that signs the certificate.
profile_nameNexus certificate profile used for enrollment.
default_validity_daysCertificate validity applied when a request does not specify one (default 365).
tls_skip_verifyOptional, non-production only. Accepts a Nexus server certificate that fails verification.

Credentials​

Nexus supports two authentication modes; choose one when registering the issuer.

ModeFieldsPurpose
Bearer tokenapi_tokenA static API token presented as a bearer credential on every request.
Mutual TLSclient_cert_pem, client_key_pemA client certificate and matching private key presented over mutual TLS. Both fields are required together.

An optional tls_ca_pem trust bundle can be supplied under either mode to validate the Nexus server certificate. All credential fields are encrypted at rest and never echoed back by the platform.

Registering the issuer​

1

Provide the base URL, CA and profile

Enter the Nexus Certificate Manager base URL, the CA name and the certificate profile to enroll against.

2

Choose the authentication mode

Provide either a bearer API token, or a client certificate and private key pair for mutual TLS. Add a trust bundle if the Nexus server certificate needs one.

3

Test the connection

Run test-connection to confirm the endpoint is reachable under the chosen authentication mode.

4

Issue through the issuer

Request certificates against the issuer; Cockpit submits the CSR, SANs and validity for enrollment.

Issuance flow​

Enrollment is synchronous: the CSR is submitted and the signed certificate, with its chain, comes back in the same response.

Synchronous REST issuance via Smart ID CM
1. AuthenticateBearer token applied per request, or the client certificate identity carried on the TLS connection
2. Submit the CSRCSR, CA name, certificate profile and SANs
3. Signed synchronouslyCertificate and chain returned in the same response
4. Serial extractedKept as the revocation reference

No polling and no pending state — the response either carries the certificate or an error.

Supported operations​

OperationSupportedNotes
test-connectionYesProbes the status endpoint under the configured authentication mode.
issueYesSubmits the CSR against the configured CA and profile; the response carries the certificate and chain.
renewYesNo native renewal flow — renew re-submits a fresh enrollment request.
revokeYesRevokes by certificate serial, with a standard revocation reason and optional comment.
Verify against a sandbox before production use

The Nexus connector is built against the Nexus Certificate Manager published REST contract. It has not yet been validated against a live CM instance. Before relying on it for production issuance, verify the request and response shapes against a Nexus sandbox and validate a full issue/revoke cycle in a non-production issuer first.