This article describes the support for the Certificate Management Protocol (CMP) in Nexus Certificate Manager via Protocol Gateway.
Certificate Manager supports certificate enrollment over the Certificate Management Protocol (CMP), which is an Internet protocol used for obtaining X.509 digital certificates in a public key infrastructure (PKI). CMP is defined in RFC 4210.
The Protocol Gateway CMP service is compliant with the Certificate Enrollment Protocol (CMP) v2 as profiled by 3GPP for LTE, see 3GPP TS 33.310 version 9.5.0, and supports both initial enrollment requests and update requests for certificate renewal.
Request certificate via CMP and Protocol Gateway
The enrollment process is made up of the following major steps:
In the AWB client, select Cross menu and Import Certificate and open the file that contains the vendor CA certificate. See Import external CA certificate in Certificate Manager.cmpenroll
certificate format.
In the file cmpenroll.conf, set enroll.messagesigner.hmac.enabled
to true
. For information on settings in cmp.conf, see also CMP security configuration in Certificate Manager.