Certificate Provisioning
Certificate Provisioning is a process in which a certificate is injected into a remote endpoint. Currently, Akeyless supports provisioning certificates to a Linux or a Windows and F5 endpoints utilizing Targets.
Any stored certificate can be provisioned through the Gateway, whereupon successful provisioning, future renewals of the certificate will be provisioned automatically.
Setting up certificate provisioning requires Target permissions on the Gateway.
Provisioning Permissions on Target:To prevent partial files, the Gateway first saves new items (certificates, keys, and so on) in a temporary folder on your server, then atomically renames them into the final paths you specify. Ensure the temporary folder is writable by the user defined in the Target.
Provisioning a Certificate Using the Akeyless CLI
Run the following CLI command to provision a certificate:
akeyless assoc-target-item \
--name <Certificate name> \
--target-name <Target Name> \
--gateway-url 'https://<Your-Akeyless-GW-URL>:8000' \
--certificate-path <Where to save the certificate> \
--post-provision-command <"echo Akeyless"> \
--f5-certificate-type[=traffic] <Certificate Type> \
--certificate-format[=pem] <Certificate Format>Where:
-
name: The Certificate item name. -
target-nameThe Target item name, to provision the certificate. -
gateway-url: Akeyless Gateway URL (port8000). -
certificate-path: A path on the Target to save the certificate PEM file can be used as well withchain-pathandprivate-key-pathflags to save those on different locations. -
certificate-format: Optional, the file format to provision the certificate in. Supported values arepem(default) andpfx. -
post-provision-command: Optional, a custom command to run on the remote target after successful provisioning, for example, restarting a service.
For F5 BIG-IP, SSL profiles can be bound using the --bind-ssl-profiles flag. The partition segment of this flag can now include a subfolder path within the administrative partition (for example, client-ssl:Common/my-subfolder:my-profile), in addition to a top-level partition such as Common.
You can find the complete list of additional parameters for this command, including --bind-ssl-profiles, in the CLI Reference - Encryption Keys section.
Provisioning a Certificate Using the Akeyless Console
- Log in to the Akeyless Console, and go to Items, find the certificate you wish to provision.
- Click on the Certificate item, click on the Provisioning tab, and then Attach.
- Enter the following parameters:
-
Target Name - Choose an existing Target from the drop-down list to select the existing SSH/ Windows Target.
-
Gateway - Choose an existing Gateway from the drop-down list to select the relevant Gateway.
-
Certificate Remote Path - The path where the certificate will be provisioned to in the remote machine.
-
Certificate Format - Choose the file format the certificate will be provisioned in: PEM (default) or PFX.
-
Private Key Remote Path - A path on the target to store the private key.
-
Certificate Chain Path - A path on the target to store the full chain.
-
Post Provision Command - A custom command of your choice that will be executed on the remote machine as part of the provisioning process.
-
Bind to SSL Profile(s) - If set, the certificate will be bound to an existing SSL profile (relevant only for F5).
- Profile Type - Select Client SSL or Server SSL.
- Partition - The partition where the profile exists. By default, the partition is taken from the Certificate Remote Path.
- Profile Name - The name of the SSL profile.
Updated about 14 hours ago
