Skip to main content
IssuedcertificateDeploy jobvalidate · rollbackF5 BIG-IPiControl RESTFortinet FortiGatedeploy + rollbackAzure App Servicebind certificateEntra IDApp Proxy / RegistrationIIS · AD/LDAPS · CAPIagent-orchestrated (PowerShell)Nginx · Java KeystoreSSH — no agent neededApache HTTPDconfigure-only (planned)ServiceNow CMDBinventory / expiry sync
Push an issued certificate straight to where it terminates TLS — each deployment is validated and can be rolled back.
Applies to:
DuoKey Cockpit v2F5 · Fortinet · Azure · Entra · Windows agents · SSH targetsValidated deploy jobs with rollback

Overview​

Rather than exporting a certificate and installing it by hand, DuoKey can deploy it directly to the device or service that terminates TLS. Every deployment runs as a job that validates the result and can be rolled back.

TargetConnector notes
F5 BIG-IPiControl REST — deploy cert+key or cert-only; discover, test and rollback
Fortinet FortiGateDeploy and rollback
Azure App ServiceBind certificates to app services
Entra IDApp Proxy and App Registration
Microsoft IIS · Active Directory / LDAPS · Windows CAPIAgent-orchestrated (PowerShell) — a scanner agent bound to the target runs the import/bind locally or over WinRM
Nginx · Java KeystoreSSH — Cockpit connects directly, places the cert/key (or imports into the keystore) and runs the reload/restart command
Apache HTTPDConfigure-only for now — target creation is supported, live deploy is not yet wired
ServiceNow CMDBInventory / expiry sync (not a TLS-termination target)

Deploy-job lifecycle​

StateMeaning
pendingJob created, not yet started
runningPushing the certificate to the target
validatingConfirming the target now serves the new certificate
succeeded / failedTerminal outcome
rolled_backReverted after completion
Rollback is a first-class step

Rollback is the one transition allowed after a job completes, so a bad push can be reverted to the previous certificate. F5 and Fortinet have dedicated rollback endpoints; generic targets roll back through the deploy-jobs API.

Connector operations​

All connectors share a uniform set of operations — discover / inventory / add / remove / re-enroll — so managing certificates across heterogeneous targets feels consistent. Reusable connection profiles store target credentials once and can be tested and re-bound.

F5 BIG-IP​

1

Register the F5 target

Add the F5 target (management address + credentials) and run test to confirm connectivity.

2

Deploy

Deploy the certificate and key, or cert-only when the key is already present. The job validates the SSL profile binding.

3

Roll back if needed

If validation fails or the change misbehaves, roll the job back to the previous certificate.

Microsoft IIS, Active Directory / LDAPS & Windows CAPI (agent)​

These three targets share the same execution model — a Keyfactor-style Universal Orchestrator pattern. An on-prem scanner agent registers with Cockpit and is bound to the target; instead of Cockpit reaching in directly, the agent pulls deploy jobs at its own heartbeat cadence and runs them locally (or over WinRM against a remote host).

1

Enroll and run the agent

On the Windows host (or the box that will WinRM into it), enroll once with a single-use installer token generated from Scanner Agents → Generate installer in the cockpit UI:

EnrollBASH
dke-scanner-agent enroll --server https://<cockpit-host> --token <enrollment-token>

This writes the issued agent identity and API key to ~/.dke/agent.toml (mode 0600). Then start the persistent agent process, which connects to the cockpit, sends heartbeats, and polls for deploy jobs:

RunBASH
dke-scanner-agent agent

No separate flag is needed to enable deploy jobs — every enrolled agent reports the cert_deploy capability automatically, so it shows up in the wizard's agent picker as soon as it's enrolled and running. The process must keep running (as a Windows service, not an interactive session that ends when you log off) for jobs to be picked up; see Agent Mode for the full CLI reference, including --heartbeat-interval and --config.

2

Bind the target to the agent

In the deploy wizard, pick the enrolled agent for the target — or, for a remote host the agent doesn't run on directly, choose the WinRM transport instead and supply the remote host's username, password, port and TLS settings.

3

Register the target

Microsoft IIS: site name, binding host header and port, machine store (LocalMachine\My or WebHosting), SNI. Active Directory / LDAPS: the DC's dedicated NTDS\My store, domain controller FQDN, in-place LDAPS reload (no restart). Windows CAPI: the SSL binding IP/port and the application GUID netsh http add sslcert requires.

4

Deploy

Cockpit resolves the managed certificate, builds a PFX and enqueues an encrypted job. The agent pulls it, imports the certificate into the Windows certificate store and binds it — an IIS site binding, an LDAPS reload, or a netsh http add sslcert binding — then reports the outcome back, which updates the deploy job.

Run the agent elevated

Importing into the machine certificate store and binding IIS or CAPI needs an elevated PowerShell context (the agent shells out to powershell.exe to run Import-Module WebAdministration, Import-PfxCertificate -CertStoreLocation Cert:\LocalMachine\My, and netsh http add sslcert). Install dke-scanner-agent agent as a Windows service running under LocalSystem or an administrative service account — an interactive, non-admin console session will fail these steps with an access-denied error, even though the agent itself starts and heartbeats successfully.

Nginx & Java Keystore (SSH)​

Cockpit reaches these two targets directly over SSH — no agent required.

1

Register the target

SSH host, port and username, plus either a password or a private key (PEM, optionally passphrase-protected) — with an optional SHA-256 host-key fingerprint to pin. Nginx also takes the certificate and key file paths and a reload command. Java Keystore takes the keystore path, alias, keystore type (PKCS12 or legacy JKS), the keystore password and an optional restart command.

2

Test the connection

Confirms the SSH credentials work and reports what is already deployed — an openssl x509 read of the certificate file for Nginx, a presence check for the keystore file for Java Keystore.

3

Deploy

Nginx: Cockpit writes the certificate and private key to the configured paths over SSH, then runs the reload command. Java Keystore: Cockpit builds a PKCS#12 locally from the managed certificate, ships it to the host over SSH and imports it with keytool -importkeystore under the configured alias, then runs the optional restart command.

Pin the host key

Leaving the host-key fingerprint empty trusts whatever key the host presents on first connect. Pin the SHA-256 fingerprint on the target for production use.

API reference​

Managing deploy targets, running and rolling back deploy jobs, storing reusable connection profiles, and syncing inventory to ServiceNow CMDB are all available programmatically through the platform API.

API reference
Detailed API endpoints are documented separately in the Developer Docs → PKI API.
DuoKey PKImanaged + discovered certssyncServiceNowconnectorconfigure · probe-aclupsertCMDBcertificate CIsexpiryIncidentsexpiry tickets
Certificates are synced to the ServiceNow CMDB as configuration items, and upcoming expiries raise incidents automatically.