EJBCA connector
You can use the EJBCA (Enterprise JavaBeans Certificate Authority) connector in DigiCert® Trust Lifecycle Manager to issue, enroll, and manage certificates from the EJBCA certificate authority (CA). You can also import existing certificates from EJBCA into your Trust Lifecycle Manager inventory for centralized management.
Before you begin
Before adding an EJBCA connector in Trust Lifecycle Manager, make sure the following prerequisites are satisfied:
If you plan to use the SCEP enrollment method when creating a Trust Lifecycle Manager certificate profile, you must ensure that the EJBCA RA profiles are configured as follows:
Add EJBCA connector
To add the EJBCA connector in Trust Lifecycle Manager:
From the Trust Lifecycle Manager menu, go to Integrations > Connectors.
Select the Add connector button.
In the Certificate authorities section, select EJBCA.
Complete the form as described in the following steps.
Configure the general connector properties in the top section of the form:
Name: Assign a friendly name to this connector.
Business unit: Select a business unit for this connector. Only users assigned to this business unit can manage the connector.
Managing sensor: Select one or more active DigiCert sensors to manage the integration.
Dica
Selecting multiple sensors adds fault-tolerance to the integration. If one sensor fails, Trust Lifecycle Manager will automatically fail over and use one of the other sensors.
Configure the EJBCA access details in the Link account section:
Base URL: Enter the base API URL path for accessing the EJBCA service.
Client certificate: Drag and drop or browse to select the client certificate (.p12, .pfx) to upload. The client certificate is used to establish a secure connection with the EJBCA service.
Passphrase: Enter the passphrase for the client certificate if password-protected.
Fill out the Import attributes section if you want to import existing certificates from EJBCA:
Import certificates from this connector: Select whether to import certificates or not. If importing, select options for which certificates to import.
To import all certificates into Trust Lifecycle Manager, select the All valid certificates option.
To import certificates that expired within a time frame, select the All expired certificates within 15, 30, 45, 90 days option.
To import certificates that are revoked but not yet expired, select the All revoked certificates that are not expired option.
Business unit: (Optional) Assign a business unit to import certificates. Only users assigned to this business unit can manage the imported certificates in Trust Lifecycle Manager.
Certificate assignment rules: (Optional) Select assignment rules for automatically assigning metadata to imported certificates.
Import frequency: Select scheduling options for ongoing import operations. Enter a value and select units (minutes, hours, or weeks) for how often to import certificates from EJBCA.
Select Add to create the EJBCA connector with the configured settings.
Issue certificates
EJBCA prerequisites
To issue EJBCA certificates from Trust Lifecycle Manager, ensure that your connected EJBCA service is configured as follows:
At least one certificate profile, end entity profile, and issuing CA are configured in EJBCA.
At least one prevalidated domain is available for certificate issuance in EJBCA. All certificate enrollment methods in Trust Lifecycle Manager require the domains to be prevalidated in EJBCA.
The issuing CA selected in Trust Lifecycle Manager certificate profile must also be included in both:
the selected EJBCA certificate profile, and
the selected EJBCA end entity profile.
Importante
The issuing CA configured in the EJBCA certificate profile and the EJBCA end entity profile must match the issuing CA selected in the Trust Lifecycle Manager certificate profile. If the issuing CA isn’t available in both EJBCA profiles, certificate enrollment fails.
Base templates
Use the following base templates to create certificate profiles in Trust Lifecycle Manager for issuing private server certificates from EJBCA.
Template name | Enrollment methods | Authentication methods |
|---|---|---|
|
|
|
|
| |
| — | |
|
| |
|
| |
|
|
|
|
| |
|
| |
|
|
Create profiles
Complete the profile creation wizard based on your unique business needs and how you plan to enroll and deploy the EJBCA certificates. Key profile settings for the EJBCA service include:
Connector: The EJBCA connector to use in Trust Lifecycle Manager.
End entity profile: The EJBCA end entity profile that defines the Subject DN and SAN fields.
Ccertificate profile: The EJBCA certificate profile that defines the certificate properties, such as signature algorithms, key type and size, validity period, extensions, and permissions (for example, validity override and Subject DN override).
Issuing CA: The certificate authority (CA) in EJBCA that validates requests and signs the certificates.
Enrollment method: Select one of the enrollment methods in the preceding table for how to enroll certificates from this profile in Trust Lifecycle Manager. To learn more, see Enrollment and authentication methods.
Importante
When using the SCEP enrollment method, select the DIGICERT_TLM_EJBCA_SCEP_RA_EEP end entity profile and DIGICERT_TLM_EJBCA_SCEP_RA_CP certificate profile that you created. See Important (SCEP enrollment method only).
Authentication method: Select an authentication method for validating enrollment requests. The available authentication methods depend on the enrollment method you selected. To learn more, see Enrollment and authentication methods.
Allow duplicate certificates: Select this check box to allow duplicate certificates with the same Subject DN to be issued.
Importante
If you’ve enabled Allow duplicate certificates in the Trust Lifecycle Manager certificate profile, disable Enforce unique DN for the selected CA in your EJBCA service.
What's next
Monitor and manage certificates from your Inventory page in Trust Lifecycle Manager.
Go to the Integrations > Connectors page to view, check status, or manage the EJBCA connector.
Select one of the View actions for a connector to load a pre-filtered inventory list of digital trust assets associated with it.