Deployment
Push certificates straight to where they terminate TLS — with validation and rollback.
Overview
Rather than exporting a certificate and installing it by hand, DuoKey can deploy it directly to the device or service that terminates TLS. Every deployment runs as a job that validates the result and can be rolled back.
| Target | Connector notes |
|---|---|
| F5 BIG-IP | iControl REST — deploy cert+key or cert-only; discover, test and rollback |
| Fortinet FortiGate | Deploy and rollback |
| Azure App Service | Bind certificates to app services |
| Entra ID | App Proxy and App Registration |
| Microsoft IIS · Active Directory / LDAPS · Windows CAPI | Agent-orchestrated (PowerShell) — a scanner agent bound to the target runs the import/bind locally or over WinRM |
| Nginx · Java Keystore | SSH — Cockpit connects directly, places the cert/key (or imports into the keystore) and runs the reload/restart command |
| Apache HTTPD | Configure-only for now — target creation is supported, live deploy is not yet wired |
| ServiceNow CMDB | Inventory / expiry sync (not a TLS-termination target) |
Deploy-job lifecycle
| State | Meaning |
|---|---|
| pending | Job created, not yet started |
| running | Pushing the certificate to the target |
| validating | Confirming the target now serves the new certificate |
| succeeded / failed | Terminal outcome |
| rolled_back | Reverted after completion |
Rollback is the one transition allowed after a job completes, so a bad push can be reverted to the previous certificate. F5 and Fortinet have dedicated rollback endpoints; generic targets roll back through the deploy-jobs API.
Connector operations
All connectors share a uniform set of operations — discover / inventory / add / remove / re-enroll — so managing certificates across heterogeneous targets feels consistent. Reusable connection profiles store target credentials once and can be tested and re-bound.
F5 BIG-IP
Register the F5 target
Add the F5 target (management address + credentials) and run test to confirm connectivity.
Deploy
Deploy the certificate and key, or cert-only when the key is already present. The job validates the SSL profile binding.
Roll back if needed
If validation fails or the change misbehaves, roll the job back to the previous certificate.
Microsoft IIS, Active Directory / LDAPS & Windows CAPI (agent)
These three targets share the same execution model — a Keyfactor-style Universal Orchestrator pattern. An on-prem scanner agent registers with Cockpit and is bound to the target; instead of Cockpit reaching in directly, the agent pulls deploy jobs at its own heartbeat cadence and runs them locally (or over WinRM against a remote host).
Enroll and run the agent
On the Windows host (or the box that will WinRM into it), enroll once with a single-use installer token generated from Scanner Agents → Generate installer in the cockpit UI:
dke-scanner-agent enroll --server https://<cockpit-host> --token <enrollment-token>This writes the issued agent identity and API key to ~/.dke/agent.toml (mode 0600). Then start the persistent agent process, which connects to the cockpit, sends heartbeats, and polls for deploy jobs:
dke-scanner-agent agentNo separate flag is needed to enable deploy jobs — every enrolled agent reports the cert_deploy capability automatically, so it shows up in the wizard's agent picker as soon as it's enrolled and running. The process must keep running (as a Windows service, not an interactive session that ends when you log off) for jobs to be picked up; see Agent Mode for the full CLI reference, including --heartbeat-interval and --config.
Bind the target to the agent
In the deploy wizard, pick the enrolled agent for the target — or, for a remote host the agent doesn't run on directly, choose the WinRM transport instead and supply the remote host's username, password, port and TLS settings.
Register the target
Microsoft IIS: site name, binding host header and port, machine store (LocalMachine\My or WebHosting), SNI. Active Directory / LDAPS: the DC's dedicated NTDS\My store, domain controller FQDN, in-place LDAPS reload (no restart). Windows CAPI: the SSL binding IP/port and the application GUID netsh http add sslcert requires.
Deploy
Cockpit resolves the managed certificate, builds a PFX and enqueues an encrypted job. The agent pulls it, imports the certificate into the Windows certificate store and binds it — an IIS site binding, an LDAPS reload, or a netsh http add sslcert binding — then reports the outcome back, which updates the deploy job.
Importing into the machine certificate store and binding IIS or CAPI needs an elevated PowerShell context (the agent shells out to powershell.exe to run Import-Module WebAdministration, Import-PfxCertificate -CertStoreLocation Cert:\LocalMachine\My, and netsh http add sslcert). Install dke-scanner-agent agent as a Windows service running under LocalSystem or an administrative service account — an interactive, non-admin console session will fail these steps with an access-denied error, even though the agent itself starts and heartbeats successfully.
Nginx & Java Keystore (SSH)
Cockpit reaches these two targets directly over SSH — no agent required.
Register the target
SSH host, port and username, plus either a password or a private key (PEM, optionally passphrase-protected) — with an optional SHA-256 host-key fingerprint to pin. Nginx also takes the certificate and key file paths and a reload command. Java Keystore takes the keystore path, alias, keystore type (PKCS12 or legacy JKS), the keystore password and an optional restart command.
Test the connection
Confirms the SSH credentials work and reports what is already deployed — an openssl x509 read of the certificate file for Nginx, a presence check for the keystore file for Java Keystore.
Deploy
Nginx: Cockpit writes the certificate and private key to the configured paths over SSH, then runs the reload command. Java Keystore: Cockpit builds a PKCS#12 locally from the managed certificate, ships it to the host over SSH and imports it with keytool -importkeystore under the configured alias, then runs the optional restart command.
Leaving the host-key fingerprint empty trusts whatever key the host presents on first connect. Pin the SHA-256 fingerprint on the target for production use.
API reference
Managing deploy targets, running and rolling back deploy jobs, storing reusable connection profiles, and syncing inventory to ServiceNow CMDB are all available programmatically through the platform API.