Skip to main content

Provision trust bundle

Provision a trust bundle to apply a trust enforcement policy to trust stores on your servers. The trust bundle determines which CA certificates are included or excluded and how trust is enforced on the trust stores. You can provision the trust bundle to individual agents or an agent group and configure the trust store delivery settings for the selected agents.

To provision a trust bundle, perform the following steps:

Start by selecting the trust bundle you want to include in the provisioning request.

  1. In the Trust Lifecycle Manager menu, go to Inventory > Trust stores > Provision trust​

  2. Select Provision trust bundle.

  3. On the Provision trust bundle page, enter a Request name.

  4. In the Select trust bundle section, select the required trust bundle from the Trust bundle dropdown.

  5. If the required trust bundle is not available, select Create trust bundle to create one. After creating the trust bundle, return to the provisioning flow to continue.

  6. Select Next.

Select the agents or agent group to which you want to provision the trust bundle.

  1. On the Provision Trust bundle page, choose one of the following options:

    • Individual agents

      1. Select the checkbox for each agent to which you want to provision the trust bundle.

      2. (Optional) Use the filter options available in the column headers to locate the required agents.

    • Agent groups

      1. Select Agent groups.

      2. From the Select agent group dropdown, select the required agent group. The agents in the selected group and their operating systems are displayed.

  2. Select Next.

Configure the delivery options for the trust bundle on the selected agents.

  1. On the Provision Trust bundle page, configure the trust store settings using one of the following options:

    • Use default configuration: Select this option to apply the same trust store settings across all selected agents.

      1. Enable Use default configuration option.

      2. Select the operating system. The supported operating systems are Linux and Windows.

      3. In the Trust store path section, configure the following settings:

        • Format: Select the trust store format.

        • Trust store location: Enter the trust store location.

        • Trust store password (optional): Enter the trust store password, if required.

      4. Select Apply to all agents to apply the default configuration to the selected agents based on their operating system.

      Nota

      After applying the default configuration, you can modify trust store settings for individual agents.

    • Individual agent configuration: To configure trust store settings for an individual agent, locate and expand the agent, and then configure the following:

      • Trust store file path: Enter the trust store file path.

      • Trust store password (optional): Enter the trust store password, if required.

  2. Select Next.

Review the trust bundle configuration and delivery details before submitting the provisioning request.

  1. On the Provision trust bundle page, review the provisioning details, including:

    • Provisioning request name

    • Trust bundle

    • Agents and delivery options

  2. (Optional) Select Back to modify any previous step.

  3. Select Provision to submit the provisioning request.

What's next

  • After submitting the provisioning request, you are redirected to Inventory > Trust stores > Provisioning history​, where you can monitor the status of the trust bundle provisioning request. To learn more, see Provisioning history.

  • After provisioning is complete, you can view and manage the provisioned trust stores from Inventory > Trust stores > Endpoints. To learn more, see Manage endpoints for trust stores.