DigiCert MPKI CA

Prerequisites

The following are the prerequisites for configuring a Digicert MPKI CA account in AppViewX:

  • A Digicert MPKI Account with Administrator role Access.
  • An API Key configured in Digicert MPKI with required permissions to make API Requests from AppViewX.
  • The AppViewX server should either have internet access or have a proxy configured in AppViewX general settings. Check Proxy Setup for the steps to configure the proxy. https://adminguide.appviewx.com/proxy-4

Configuring DigiCert MPKI CA

To configure the DigiCert MPKI CA:

  1. Go to menu > KUBE+ > CLUSTER PKI > Certificate Authority.
  2. Click the +Add icon on the top right of the page.
  3. Select the DigiCert MPKI in the left side vendor list.
  4. Update the following details in the General Information section as described in the table.
    Table 1. General Information - Field and Description Table
    Name Description
    *CA Account name A unique name to identify the CA setting.

    No special characters other than ‘.’, ‘-’,’_’ are allowed. Names should not start with special characters.

    *Purpose/Usage

    Certificate Type for which CLM actions will be enabled.

    Example: Server, Client

    Proxy Required Enable this field if the CA communication needs to happen via Proxy. The proxy details configured in general settings will be used for communication.
    Data Center (AppViewX's CA agent) Select the data center through which the CA communication needs to happen.
    *: Mandatory fields
  5. Update the following details in the CA Configuration section as described in the table. These fields are necessary for invoking the DigiCert CA APIs for Certificate Management.
    Table 2. CA Configuration - Field and Description Table
    Name Validation
    *Base URL
    *Seat ID NA.
    *API Key
    Note:
    • *: Mandatory fields

    • Auto approval checkbox is optional and features work only for one-step certificate requests configured in the DigiCert Cert Central Account.

  6. Select Fetch Divisions and Certificate Types.
    The Division and Certificate types available in the DigiCert CA account will be fetched and listed for the specific API key user in the table as shown below.
  7. Click Save.
    Note: The pop-up message is displayed as <CA_name> Settings Added.

Validating DigiCert MPKI Connection

Once the DigiCert MPKI settings are added, the validation must be done to check whether the connection between AppViewX and DigiCert MPKI is configured properly.

  1. Go to menu > KUBE+ > CLUSTER PKI > Certificate Authority
  2. Select the DigiCert in the left side vendor list.
  3. Click Check to validate the CA setting that is created.
    The CA communication will be validated and the Connection Status will be shown as either Success or Failure.