Perform the following tasks to create a CA for the SSH key pair:Documentation Index
Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
Use this file to discover all available pages before exploring further.
- Create a new X.509 certificate container.
- Generate a new key pair for the SSH client.
- Create an approval group for PKI signing
- Add an issuance policy to the SSH client certificate.
- Export the public key for the SSH client key pair.
Create a certificate container
Perform the following steps to create a new X.509 certificate container:Select [ Add CA ] at the bottom of the page or right-click anywhere in the window and select Add CA.
In the pop-up menu, specify the following information for the Certificate Container:
- Name: Select SSH Key Offloading.
- Host: Select None.
- Type: Select X.509.
- Owner group: In the drop-down menu, select the role automatically created for the SSH Key Offloading service you deployed.
Generate a key pair
Perform the following steps to generate a new key pair for the SSH client:Right-click the X.509 certificate container you created and select Add Certificate > New Certificate.
In the Subject DN tab of the certificate creation wizard, select the Classic Preset in the drop-down menu and specify
SSH as the Common Name for the certificate.Create an approval group
Perform the following steps to create an approval group for PKI signing:Select [ Add Approval Group ] at the bottom of the page or right-click anywhere in the window and select Add Approval Group.
In the first drop-down list, select the role automatically created for the SSH Key Offloading service you deployed, and select [ Add ].
Add an issuance policy
Perform the following steps to add an issuance policy to the SSH client certificate:Expand the SSH Key Offloading certificate container view by selecting the plus (+) icon next to it.
In the Basic Info tab, configure the following settings:
- Approvals: Select 0. The Zero approval policy requires Anonymous Signing security usage displays. Step sets this.
- Allowed hashes: Select SHA-512.
Export the public key
Perform the following steps to export the public key for the SSH client key pair:Expand the SSH Key Offloading certificate container view by selecting the plus (+) icon next to it.

