Integration with Entrust Certificate Authority14 minutes to read
Key Manager Plus seamlessly integrates with Entrust Certificate Authority, a prominent provider of SSL/TLS certificates and digital identity solutions. This integration harnesses the Entrust API, empowering users to effortlessly - request, acquire, import, renew, and reissue certificates directly from the Key Manager Plus web interface. Streamline the lifecycle management of certificates in your environment by leveraging a range of operations supported through this integration. Prerequisite: Add the following base URL and port as an exception in your firewall or proxy to ensure Key Manager Plus is able to connect to Entrust's CA Services. This document guides you through the steps to effectively handle the lifecycle of SSL/TLS certificates issued by Entrust CA, encompassing tasks such as importing existing orders, creating new certificate requests, and managing the certificates. Refer to the sections that follow to learn more about Entrust integration and certificate management with Key Manager Plus:
1. Entrust Certificate Authority Details in Key Manager PlusTo begin managing SSL certificates issued by Entrust from Key Manager Plus, you must add your Entrust account in Key Manager Plus via your unique API Key. If you do not have an Entrust account, contact the Entrust team to sign up and get your login credentials. Once you have your allocated Entrust account, follow the steps below to generate an API key to begin the integration process.
Now, log into the Key Manager Plus web interface, and add your Entrust credential with the unique username and API key by performing the below steps:
Once your Entrust account details are linked to Key Manager Plus, the system retrieves vital information such as domains, organizations, and products (certificate profiles) and organizes them under the individual tabs with corresponding details. These details are crucial as Entrust issues certificates based on them. For further manual synchronization, use the Sync option under each tab for Organizations, Domains, and Products. Alternatively, you can also sync Organizations, Domains, or Products for a particular credential directly from the Credentials tab. 2. Import Existing Entrust OrdersIf you have an active Entrust account, it is likely that you currently have ongoing certificate orders. Key Manager Plus offers the convenience of not only initiating new certificate orders but also importing and effectively managing all existing orders from the Entrust portal through its user-friendly interface. To import the existing certificate orders:
This process ensures that all the prevailing certificate orders linked to your Entrust account are seamlessly imported into Key Manager Plus for streamlined management. 3. Create a New Certificate OrderOnce you have successfully linked your Entrust account with Key Manager Plus, you can start creating new certificate orders directly from the Key Manager Plus interface. To place a new certificate order in Entrust from Key Manager Plus:
Note: If you find any mismatch in the Entrust-related details (Organization/Product/Domain) displayed here, please verify the details in the Entrust portal and then perform a manual sync under Entrust >> Manage in the Key Manager Plus interface to refresh the details. For assistance with any other discrepancies related to the Entrust account, please contact the Entrust customer support team. 4. Update Certificate StatusUtilize the Update Certificate Status option to validate certificates based on your specific needs. Approve, Decline, Suspend, or Resume certificate orders as necessary. Please note that administrative privileges from an Entrust credential are essential within Key Manager Plus to execute these actions. If an administrative privileged credential is not present in Key Manager Plus, the user possessing administrative privileges in Entrust can alternatively perform these actions directly through the Entrust portal. 5. Check Order StatusOnce a certificate order is successfully created, you can view it under the Integrations >> Public CA Integrations >> Entrust window, with its status displayed to the right. To track the certificate availability for an order, select the order and click Check Order Status from the top pane. Once a certificate is issued, it is fetched and added to the Key Manager Plus certificate repository. You will be able to view it under SSL >> Certificates. Note: Beware that the certificates issued are automatically added to Key Manager Plus only if you have the required license count. If not, you must renew your Key Manager Plus license before attempting to import any certificates. However, it does not delete the certificate request from Entrust - the certificate can still be viewed and managed from the Entrust portal. 6. Renew, Reissue, Revoke, and Delete CertificatesIf the private key associated with a certificate is compromised or lost, it is essential to renew, reissue, revoke, or delete the certificate accordingly to maintain security best practices. You can do directly perform these actions in Key Manager Plus using the Entrust integration with a valid privileged Entrust credential. 6.1 Manual Certificate RenewalPerform the following actions to manually renew an Entrust-issued SSL certificate through Key Manager Plus:
Ensure that the renewed certificate is deployed in the exact location where the previous certificate was in use. This step is crucial to maintain a secure and consistent connection. Follow the instructions specified here, to ensure a proper certificate deployment. 6.2 Automated Certificate RenewalBefore configuring the auto-renewal process for Entrust-issued SSL certificates, perform the following actions:
Follow these steps to configure the auto-renewal process for the desired Entrust-issued SSL certificates:
Note: Do not attempt to manually renew the orders that are configured with the Auto-Renewal process. Key Manager Plus will carry out the auto-renewal process based on the configured details for the selected SSL certificates. Click the Auto-Renewal Audit option for insights about the certificates renewed through the auto-renewal process. 6.3 Reissue CertificateReissuing a certificate in Key Manager Plus generates a new certificate with the same information, such as organization name, domain name, expiry date, etc, with a new key pair, thus preventing unauthorized access and misuse of the compromised key. To reissue a certificate,
Ensure that the reissued certificate is deployed in the exact location where the previous certificate was in use. This step is crucial for maintaining a secure and consistent connection. Follow the instructions carefully to ensure proper deployment. 6.4 Revoke CertificateTo revoke a certificate from Key Manager Plus, perform the following action:
6.5 Delete Certificate OrderTo delete the certificate order from Key Manager Plus, perform the following action:
Note: Please note that the Delete option only removes the certificate order from the Key Manager Plus interface, and you can no longer manage it from Key Manager Plus. However, it does not delete the certificate order from Entrust - the certificate can still be viewed and managed from the Entrust portal. ©2025, Zoho Corporation Pvt. Ltd. All Rights Reserved. |