...
Gliffy Diagram | ||||||
---|---|---|---|---|---|---|
|
Simplified certificate enrollment flow
Gliffy Diagram | ||||||||
---|---|---|---|---|---|---|---|---|
|
Components description
CertService
...
Parameter name | Required | Syntax | Description | Validation rules |
---|---|---|---|---|
CA Name | Yes | String (1-128) | The CA name should include the name of the external CA server and the issuerDN, which is the distinguished name of the CA on the external CA server that will sign our certificate. |
|
URL | Yes | Schema + IPv4/FQDN + port + path | Url to CMPv2 server; includes mandatory parts: schema (http://) and IPv4/FQDN and optional parts: port and path (alias); e.g. http://127.0.0.1:8080/pkix or http://127.0.0.1/ejbca/publicweb/cmp/cmp NOTE: If FQDN is given ONAP must be able to resolve it |
|
Issuer DN | Yes | String (4-256) | Distinguished Name of the CA that will sign the certificate on the CMPv2 server side. When creating an end entity on the external CA server for client mode this IssuerDN will be passed through as the ca to sign for that user. |
|
CA Mode | Yes | Enum (CLIENT|RA) | Issuer mode (either Registration Authority (RA) or client mode) |
|
Authentication data::IAK | Yes | String (1-256) | Initial authentication key, used, together with RV, to authenticate request in CMPv2 server |
|
Authentication data::RV | Yes | String (1-256) | Reference value, used, together with IAK, to authenticate request in CMPv2 server |
|
Simplified certificate enrollment flow from CertService's perspective
...
...
CMPv2 client
CertService's client
...
Group | Parameter name | Required | Default | Syntax | Description | Origin |
---|---|---|---|---|---|---|
Timeout | No | 30s | Timeout for REST API calls | Application helm chart | ||
Path | Yes | Path where client will output generated keystore and truststore. Normally this path should be on a volume which is used to transfer keystore and truststore between CertService's client and main applicationend component | Application helm chart | |||
CA name | Yes | Name of CA which will enroll certificate. Must be same as configured on server side. Used in REST API calls | OOM global value | |||
CSR details | Common Name | Yes | Common name for which certificate from CMPv2 server should be issued | Application helm chart | ||
Organization | Yes | Organization for which certificate from CMPv2 server should be issued | OOM global value | |||
Organization Unit | No | Organization unit for which certificate from CMPv2 server should be issued | OOM global value | |||
Location | No | Location for which certificate from CMPv2 server should be issued | OOM global value | |||
State | Yes | State for which certificate from CMPv2 server should be issued | OOM global value | |||
Country | Yes | Country for which certificate from CMPv2 server should be issued | OOM global value | |||
SANs | No | Subject Alternative Names (SANs) for which certificate from CMPv2 server should be issued | Application helm chart |
...
Input Table for CMPV2 client:
...