Certificate Provisioning

Certificate Provisioning is a process in which a certificate is injected into a remote endpoint. Currently, Akeyless supports provisioning certificates to a Linux or a Windows and F5 endpoints utilizing Targets.

📘

F5 Certificate Type

For F5 target, the certificate type is Traffic by default.

Any stored certificate can be provisioned through the Gateway, whereupon successful provisioning, future renewals of the certificate will be provisioned automatically.

Setting up certificate provisioning requires Target permissions on the Gateway.

ℹ️

Provisioning Permissions on Target:

To prevent partial files, the Gateway first saves new items (certificates, keys, and so on) in a temporary folder on your server, then atomically renames them into the final paths you specify. Ensure the temporary folder is writable by the user defined in the Target.

Provisioning a Certificate Using the Akeyless CLI

Run the following CLI command to provision a certificate:

akeyless assoc-target-item \
--name <Certificate name> \
--target-name <Target Name> \
--gateway-url 'https://<Your-Akeyless-GW-URL>:8000' \
--certificate-path <Where to save the certificate> \
--post-provision-command <"echo Akeyless"> \
--f5-certificate-type[=traffic] <Certificate Type> \
--certificate-format[=pem] <Certificate Format>

Where:

  • name: The Certificate item name.

  • target-name The Target item name, to provision the certificate.

  • gateway-url: Akeyless Gateway URL (port 8000).

  • certificate-path: A path on the Target to save the certificate PEM file can be used as well with chain-path and private-key-path flags to save those on different locations.

  • certificate-format: Optional, the file format to provision the certificate in. Supported values are pem (default) and pfx.

  • post-provision-command: Optional, a custom command to run on the remote target after successful provisioning, for example, restarting a service.

For F5 BIG-IP, SSL profiles can be bound using the --bind-ssl-profiles flag. The partition segment of this flag can now include a subfolder path within the administrative partition (for example, client-ssl:Common/my-subfolder:my-profile), in addition to a top-level partition such as Common.

You can find the complete list of additional parameters for this command, including --bind-ssl-profiles, in the CLI Reference - Encryption Keys section.

Provisioning a Certificate Using the Akeyless Console

  1. Log in to the Akeyless Console, and go to Items, find the certificate you wish to provision.
  2. Click on the Certificate item, click on the Provisioning tab, and then Attach.
  3. Enter the following parameters:
  • Target Name - Choose an existing Target from the drop-down list to select the existing SSH/ Windows Target.

  • Gateway - Choose an existing Gateway from the drop-down list to select the relevant Gateway.

  • Certificate Remote Path - The path where the certificate will be provisioned to in the remote machine.

  • Certificate Format - Choose the file format the certificate will be provisioned in: PEM (default) or PFX.

  • Private Key Remote Path - A path on the target to store the private key.

  • Certificate Chain Path - A path on the target to store the full chain.

  • Post Provision Command - A custom command of your choice that will be executed on the remote machine as part of the provisioning process.

  • Bind to SSL Profile(s) - If set, the certificate will be bound to an existing SSL profile (relevant only for F5).

    • Profile Type - Select Client SSL or Server SSL.
    • Partition - The partition where the profile exists. By default, the partition is taken from the Certificate Remote Path.
    • Profile Name - The name of the SSL profile.

Did this page help you?
Footer Section