Aller au contenu principal
S'applique à :
DuoKey Cockpit v2Keyfactor / EJBCA enterprise CA engineMutual-TLS administrator authentication

Overview​

Keyfactor is registered as an issuer type in Cockpit's PKI module. The connector talks to Keyfactor's EJBCA REST API — the enterprise CA engine behind the Keyfactor platform — to enroll and revoke certificates against a specific certificate profile, end-entity profile and CA.

Keyfactor connector architecture
DuoKey CockpitPKI issuer connector — Keyfactor
mutual TLS — administrator client certificate
Keyfactor / EJBCA REST APIEnterprise CA engine, typically reachable on your own network
Configured CASigns under the certificate & end-entity profiles

Every call is authenticated by the administrator client certificate on the TLS connection itself — no separate credential is sent.

PropertyValue
Issuer typekeyfactor
BackendKeyfactor / EJBCA REST API
AuthenticationMutual TLS with an administrator client certificate
Issuance modelSynchronous — enrollment returns the certificate directly
Key custodyCaller/CSR-based — Keyfactor never returns a private key
Enterprise networks

The Keyfactor base URL commonly points at a host on your own network rather than the public internet. Cockpit's outbound connection policy explicitly allows private network ranges for this issuer while still refusing loopback, link-local and cloud metadata addresses.

Configuration​

Config fields​

FieldPurpose
base_urlBase URL of the Keyfactor / EJBCA instance (scheme, host and optional port).
certificate_profileEJBCA certificate profile applied to the enrollment.
end_entity_profileEJBCA end-entity profile applied to the enrollment.
ca_nameName of the CA (as configured in EJBCA) that signs the certificate.
username_patternOptional pattern for the EJBCA end-entity username; {cn} is substituted with the certificate's common name. Defaults to {cn}.
tls_skip_verifyOptional, non-production only. Accepts a Keyfactor server certificate that fails verification when no trust bundle is supplied.

Credentials​

FieldPurpose
client_cert_pemPEM-encoded administrator client certificate presented for mutual TLS.
client_key_pemPEM-encoded private key matching the client certificate.
tls_ca_pemOptional PEM trust bundle for validating the Keyfactor server certificate.
enrollment_passwordOptional end-entity enrollment password, required by some end-entity profile configurations in addition to the client-certificate identity.

All four fields are encrypted at rest and never echoed back by the platform.

Registering the issuer​

1

Provide the base URL and profiles

Enter the Keyfactor / EJBCA base URL, the certificate profile, end-entity profile and CA name to enroll against.

2

Upload the administrator client certificate

Provide the client certificate and private key pair used for mutual TLS, and optionally a trust bundle for the server certificate.

3

Set the username pattern (optional)

Adjust the end-entity username pattern if your EJBCA end-entity profile requires a naming convention other than the plain common name.

4

Test the connection

Run test-connection to confirm the mutual-TLS identity is accepted and the EJBCA API is reachable.

5

Issue through the issuer

Request certificates against the issuer; Cockpit submits the CSR and common name for enrollment.

Issuance flow​

Enrollment is synchronous: the CSR is submitted and the signed certificate comes back in the same response, with no polling or pending state.

Synchronous PKCS#10 enrollment
1. Build the requestCSR, certificate profile, end-entity profile and CA name; the end-entity username is derived from the common name
mutual TLS — administrator client certificate
2. Submit for enrollmentEJBCA authenticates the client certificate and signs immediately
3. Certificate issuedCertificate returned synchronously; the chain is included, or fetched from the CA if not
kept for later revocation
4. Revocation reference capturedIssuer distinguished name + serial number

A single authenticated request carries the CSR in and the signed certificate back out.

Supported operations​

OperationSupportedNotes
test-connectionYesConfirms the mutual-TLS identity is accepted and reports the EJBCA version.
issueYesSynchronous PKCS#10 enrollment against the configured profiles and CA.
renewYesNo native renewal flow — renew re-enrolls with the same request.
revokeYesRevokes by certificate serial and issuer distinguished name, with a standard revocation reason.