Creating an Entrust CA Gateway connector¶
This topic explains how to set up an Entrust CA Gateway certificate authority (CA) connector in Certificate Manager - SaaS using the Venafi CA Connector Framework. The connector issues, revokes, and imports certificates through a single Entrust CA Gateway that fronts one or more back-end certificate authorities. There's no separate renewal operation: renewal is handled as a new issuance.
One connector covers every authority and profile the gateway fronts, so you don't need a separate connection for each CA behind it.
Before you begin¶
Note
To create or manage an Entrust CA Gateway certificate authority connector, you must have one of the following roles:
- System Administrator
- PKI Administrator
- Platform Administrator
- Resource Owner (for connectors owned by your team)
Before you set up the CA connector, you'll need:
- A deployed VSatellite that can resolve and reach the Entrust CA Gateway host. The gateway doesn't need to be reachable from the internet.
- Your Entrust CA Gateway connector must already be deployed to Certificate Manager - SaaS using the Dev Central API. It won't appear in the Certificate Authority Type list until it has been deployed.
As an Entrust CA Gateway administrator, prepare the following:
- An API user that Certificate Manager - SaaS acts as, authorized for the back-end authorities and profiles you want to manage, with rights to enroll, revoke, and read certificates.
- The client certificate and private key for that API user, in PEM or DER format, as two separate files. The connector authenticates to the gateway with mutual TLS (mTLS) on the TLS handshake, so there is no API token or password to manage.
- (Optional) The CA certificate that signed the gateway's server certificate, in PEM or DER format. You need this only if the gateway's server certificate is signed by a private or internal CA.
Note
This connector supports mutual TLS only. Gateways configured for HTTP Basic authentication aren't supported.
Create an Entrust CA Gateway CA connector in Certificate Manager - SaaS¶
Before you complete these steps, review Create a custom CA connector, including the prerequisites and notes.
-
Sign in to Certificate Manager - SaaS.
-
Click Integrations > Certificate Authorities.
- Click New > Add Certificate Authority connector.
-
Under Connection, add the following.
- Enter a Name for the CA connector to use as its display name.
- Select the VSatellite that can resolve the hostname to the IP address of your Entrust CA Gateway host.
-
Select Entrust CA Gateway as the Certificate Authority Type.
Note
Your custom CA won't appear in this list until you have deployed your custom CA connector using the Dev Central API.
-
Click Next.
-
Under Information, add the connection details for your gateway.
-
Enter the Server URL.
This is the base URL of the Entrust CA Gateway, including the
/cagwpath. For example,https://cagw.example.com/cagw.Important
The URL must begin with
https://. Certificate Manager - SaaS rejects anhttp://URL, because mutual TLS authentication only takes effect over HTTPS. -
Click Choose a file and upload the Client Certificate.
This is the client certificate of the API user, in PEM or DER format.
-
Click Choose a file and upload the Client Private Key.
This is the private key that matches the client certificate, in PEM or DER format.
Warning
Store the client certificate and private key securely. Certificate Manager - SaaS encrypts both, and you can't retrieve them after you save the CA connector.
-
(Optional) Click Choose a file and upload the Trust Anchor.
This is the CA certificate that validates the gateway's server certificate, in PEM or DER format. Upload it when the gateway's server certificate is signed by a private or internal CA. If you leave it empty, Certificate Manager - SaaS validates the server certificate against the public trust store.
-
Click Test Connection.
A successful test confirms that the VSatellite can reach the gateway over mTLS and that the API user is authorized to list certificate authorities. If the connection isn't successful, resolve all issues and ensure you have a successful connection before continuing.
-
Click Next.
-
-
Under Issuance, set the following options.
-
In Product Options, select the products you want to make available to request policies.
The gateway lists one product for each pairing of certificate authority and profile that your API user is authorized for. Each product is named
<CA name> / <profile name>. For more information, see Choosing a product. -
Click Next.
-
-
(Optional) Under Import, set the following options to configure certificate import.
-
In Import options, select Entrust CA Gateway.
This connector offers a single import option, which covers every certificate authority your API user is authorized for.
-
(Optional) Enter a Start Date.
This is the earliest certificate event to import, in RFC 3339 format. For example,
2024-01-01T00:00:00Z. If you leave it empty, the import starts from 1 January 2000. -
(Optional) Enter a Preferred Page Size.
This is the number of certificate events to retrieve per request. The maximum is 100, and higher values are capped at 100.
-
To import certificates that have already expired, turn on Include Expired Certificates. This option is off by default.
- To import certificates that have been revoked at the gateway, turn on Include Revoked Certificates. This option is off by default.
- To schedule certificate import, enable Scheduled import and choose a schedule.
-
-
Click Create. The new Entrust CA Gateway CA appears on the Certificate Authorities page.
Choosing a product¶
The gateway returns one product for each pairing of certificate authority and profile, named <CA name> / <profile name>. Select every pairing you want request policies to use.
Only profiles that accept a certificate signing request (CSR) are supported. If you select a profile that generates the key pair at the CA, the request policy fails validation, and requests against it are rejected. Choose a profile that accepts a CSR instead.
If a profile is removed at the gateway after you select it, requests that use it fail validation. Edit the CA connector, reselect your products, and update the affected request policies.
What to expect from Entrust CA Gateway¶
- One connector covers many authorities. Every authority and profile behind the gateway is offered as a product on the same connector, so you don't need to add a CA connector for each back-end authority.
- Issuance can be asynchronous. If the profile has an approval workflow, the certificate stays pending until the request is approved at the gateway. Certificate Manager - SaaS polls the gateway and records the certificate when it's issued.
- Renewal is a new issuance. Renewing a certificate submits a new request against the same authority and profile.
- Revocation depends on the back-end authority. Certificate Manager - SaaS reports the revocation as submitted as soon as the gateway accepts it. An authority that doesn't support revocation reports the revocation as failed, with a message that says revocation isn't supported by that certificate authority. Revoke those certificates in the authority's own tooling instead.
- An authority that can't be read is skipped. If the connector can't read one authority during an import, it skips that authority and imports the rest. Certificates from the skipped authority are missing until the next successful import.
- The client certificate doesn't renew itself. Track the expiration date of the API user's client certificate. When it expires, the connector can't reach the gateway until you upload a replacement.
What's next?¶
This CA is now ready to be added to one or more request policies. To do this, select this CA when creating request policies.