Certificate Authority
Venafi Adaptable CA

Configure Venafi TPP to use the Futurex Adaptable CA driver

6min

This section outlines how to configure Venafi TPP before requesting certificates through the Futurex Adaptable CA driver by describing the following tasks:

  1. Manage credentials.
  2. Create a CA template.
  3. Create a certificate policy.

Manage credentials

Perform the following tasks to add the identity and TLS client certificate that you created on the KMES Series 3 as "credentials" in Venafi TPP:

  1. Define user credentials.
  2. Define TLS client certificate credentials.

The following sections show you how to perform these tasks.

Define user credentials

To define user credentials, perform the following steps:

1

Log in to Venafi TPP.

2

Select Policy Tree in the main menu.

3

In the main policy tree, select Add > Credential > Username Credential.

4

In the Username Credential window, add the username and password created for the Venafi identity on the KMES Series 3 earlier in the integration process, and add any other settings needed for the environment, such as a credential expiration date.

5

Select [ Save ] to save the credential.

6

Repeat steps 3-5 for each additional user needed.

Define TLS client certificate credentials

You can use TLS client certificates to mutually authenticate with the KMES Series 3, allowing only authorized operation and establishing an encrypted tunnel to prevent man-in-the-middle eavesdropping on traffic.

To define TLS client certificate credentials, perform the following steps:

1

Log in to the Venafi TPP.

2

Select Policy Tree in the main menu.

3

In the main policy tree, select Add > Credential > Certificate Credential.

4

In the Certificate Credential window, enter the credential name, choose the option to import a certificate, and select the binary-encoded PFX/PKCS #12 certificate that you exported from the KMES Series 3 earlier in this integration guide.

5

Specify the corresponding private key password and begin the import process.

6

After the certificate imports, select [ Save ] to complete the process.

Create a CA template

To create CA templates, perform the following steps:

1

Log in to Venafi Trust Protection Platform.

2

Select Policy Tree in the main menu.

3

In the main policy tree, select Add > CA Template > Adaptable.

4

In the Add New Adaptable window, define the following General and Connection fields:

Field

Required configuration



CA Name

The desired CA name.



Username Credential

The username credential you created in the Define user credentials section.



Certificate Credential

The certificate credential you created in the Define TLS client certificate credentials section.



Service Address

The KMES IP address or hostname and the Host API port number. This must use the following format:

ex://<IP Address/Hostname>:<Host API port>

For example, ex://216.177.186.25:2001.



Profile String

The container name and name of the issuing CA certificate on the KMES. This must use the following format:

<Container Name>;<Issuing CA>

For example, Venafi Adaptable CA;IssuingCA.



PowerShell Script

Futurex KMES CA.


5

If you need custom X.509 extensions, validity periods, or Futurex approval groups, define them in the Custom Fields section.

For these to be visible, you must have run the custom fields PowerShell script defined earlier in this guide, resulting in successful execution.

6

Select Validate to test the connection and authentication with the KMES Series 3. This can take 5-15 seconds to complete.

7

Select [ Save ] to complete the process.

Create a certificate policy

To create certificate policies, perform the following steps:

1

Log in to Venafi TPP.

2

Select Policy Tree in the main menu.

3

In the main policy tree, select Add > Policy.

4

In the Add New Policy window, define the policy name and other necessary settings, and select [ Save ].

5

Go to the Certificate tab of the new policy.

6

In the Other Information section, select the three dots next to the CA Template field and select the CA template you created previously.

7

Select [ Save ] to complete the process.