Cookies are used to collect information about you. Nexus uses this information to give you a better experience of the website (functional) and to count the pages you visit (statistics).
Click OK to give Nexus your consent to use cookies. Read more about Nexus' cookie policy.
This article describes how to configure Certificate Manager for such a use-case.
Prerequisites
You need the following:
Identity Manager CA configuration name
Name of Certificate Manager recovery token procedure
Key type and size of the certificates issued by the external CA
Chain certificates of the external CA (most notably you need to know the issuer DN of every issuing CA certificate, i.e. the ones that issue the end-entity certificates)
Step-by-step instruction
Prepare Certificate Manager for key archival and recovery for external CA
In Certificate Manager's AWB, create token procedures for key archival using the storage profile PKCS12. Note that the attached key procedure must use a key procedure format matching the key type and size of the respective external CA policy templates. For example: kar.key.type = RSA keylength.value = 4096
You also need a certificate procedure attached as well as using a signature algorithm with matchingkey typeto the certificates issued by the external CA (e.g.xyz with RSAfor RSA keys).
In Certificate Manager's AWB, create an import CA with configured P10 import token procedure for import of external CA certs. This import CA must have a dummy self-signed keypair and have the same subject DN as the external issuing CA. For more information, see Create CA in Certificate Manager.
For Identity Manager, set the import procedure in the Certificate Manager connector config's nexus_cm.properties file, see this code example: