Integrate Identity Manager with Smart ID Certificate Manager
- Karolin Hemmingsson (Unlicensed)
- Ylva Andersson
- Ann Base (Deactivated)
- Josefin Klang (Deactivated)
This article is valid for Smart ID 20.11 and later.
This instruction describes how to connect to Smart ID Certificate Manager from Smart ID Identity Manager.
The following prerequisites apply:
- Smart ID Certificate Manager (CM) is already installed and ready to use: Bootstrap is done, System CA and Production CA Hierarchies are signed, token procedures are configured.
- Identity Manager needs a CM Officer certificate with permission to issue and manage the certificates.
- For CM 7.x: The current rootfile of the Nexus CM is available.
- For CM 8.x:
- The TLS certificate is available.
PRIME running on a TLS 1.3-enabled JRE (either Java 11 or Zulu 8 configured according to Configure Zulu 8 JRE for TLS 1.3.
The instructions in Configure Zulu 8 JRE for TLS 1.3 are only needed for Zulu 8.47 and lower.
Step-by-step instruction
To create a CM connection .zip file:
Download this file and store it in a new folder (that you will later create the .zip file from): nexus_cm.properties.
Open the .properties file for editing and enter your values:
Example for CM 8.x: nexus_cm.propertiessecurityOfficer=<CM IdM Officer name> p12path=CM_IdM_Officer.p12 rootfile=roots pinfile=pinEnc.cer
- Create a .zip file, with the following content:
- nexus_cm.properties
For CM 7.x:
rootfile
This is the CM client truststore, which is created or updated by CM clients such as Administrator's Workbench when you connect to a new CM instance for the first time and accept its server certificate. The rootfile can be found in the following path on the CM client machine:
Example: rootfile pathC:\Users\<USERNAME_GOES_HERE>\CertificateManager\certs\rootfile
- For CM 8.x:
Root CA certificate file
This is the root CA of the CM server TLS certificate. It can be obtained from the client trust store folder, which is created and maintained by CM clients, that is, Administrator's Workbench, when you connect to a CM instance for the first time. The root CA certificate file can be found in the following path:
Example: Root CA certificate file path%APPDATA%\Nexus\CertificateManager\certs\
- Place the root CA certificate file into the folder "roots" within the zip file.
- .p12 CM officer file
X509 PIN certificate
To add CM in Identity Manager Admin:
- Log in to Identity Manager Admin.
- Go to Home > Certificate Authorities (CA).
- Click New and enter a name for the CA.
- Click Save + Edit.
- In the General tab, add the following details:
- In Connection Type, select Certificate Manager.
- Set CA Host to the CM server hostname.
- Click Upload. Browse to the .zip file you have created, and upload it.
- In Signing password, enter the password to the .p12 officer file.
- Click Save.
Each PKI provides predefined certificate types. In CM, they are called Token Procedures.
To import the certificate types
- Go to the Details tab.
- Click to display the certificate types in CM.
- Click Apply to import the certificate types.
The imported certificate types are now listed in Certificate Types.
When you create a certificate template in Identity Manager Admin, then the imported certificate types are available to choose from.
To test the connection:
Click Testing, and then Test Connection.
The certificate types need to be downloaded, otherwise the test light of Revocation reasons will still be red.
When the test button shows two green lights, save your configuration, by clicking Save.
Additional information
Copyright 2024 Technology Nexus Secured Business Solutions AB. All rights reserved.
Contact Nexus | https://www.nexusgroup.com | Disclaimer | Terms & Conditions