JKS certificate lifecycle

The following table outlines the stages of the certificate lifecycle for certificates located in Java keystores and the management level associated with each stage.

JKS certificate lifecycle

Stage

Friendly Name

Description

Enrollment

Provisioning

Stages 0-700 are performed by the JKS application driver only if remote key generation is enabled. If the private key and CSR are locally generated on the Trust Protection Foundation server, stages 0-700 are performed by the X509Certificate application driver.

NOTE  The private key and CSR are remotely generated on the certificate’s consumer application(s) if the Generate Key/CSR on Application option is enabled in the certificate object.

0

StartProcessing

No processing.

 

 

100

CheckStore

No processing.

 

 

200

CreateConfigureStore

Only applies to remote generation.

Trust Protection Foundation creates a backup of the keystore, if it exists.

If the configured keystore does not exist and the Create option is selected on the JKS application object, Trust Protection Foundation creates the certificate keystore.

For more information, see the Create setting in the Java Keystore Settings table.

 

Green check mark, indicates feature is supported

300

CreateKey

No processing.

DID YOU KNOW?  Stage 300 is used for key generation only when the API of a target device separates keypair and CSR generation. When they're combined, both key and CSR generation are always done at stage 400.

 

 

400

CreateCSR

Trust Protection Foundation creates the Certificate Signing Request (CSR).

If remote key generation is enabled, the Java keytool utility is used to generate the CSR. Otherwise, Trust Protection Foundation generates the CSR.

Green check mark, indicates feature is supported

Green check mark, indicates feature is supported

500

PostCSR

Trust Protection Foundation submits the CSR to the certificate authority (CA).

NOTE  If you post a manual CSR, this is the first stage of the certificate lifecycle.

Green check mark, indicates feature is supported

Green check mark, indicates feature is supported

600

ApproveRequest

Trust Protection Foundation approves the certificate renewal at the CA.

Green check mark, indicates feature is supported

Green check mark, indicates feature is supported

700

RetrieveCertificate

Trust Protection Foundation retrieves the certificate from the CA.

Green check mark, indicates feature is supported

Green check mark, indicates feature is supported

800

CheckKeyStore

 

If the certificate and private key are generated on the Trust Protection Foundation server, this is the stage when Trust Protection Foundation determines if the configured keystore exists.

If the keystore does not exist and the Create option is selected on the JKS application object, Trust Protection Foundation creates the certificate keystore.

If the keystore exists, Trust Protection Foundation creates a backup of the keystore on the same Directory.

For more information on the backup procedure, see About keystore backups.

 

Green check mark, indicates feature is supported

801

InstallCertificateChain

Trust Protection Foundation installs the root certificate chain.

NOTE  The Java Keytool will not allow a certificate to be installed if the appropriate root and intermediate root certificates are not already installed in the keystore.

NOTE  Root certificates can be discovered and brought under management, or they can be manually imported. For more information, see Managing root certificates.

 

Green check mark, indicates feature is supported

802

InstallCertificate

If remote key generation is enabled, Trust Protection Foundation uses the Java keytool utility to import the certificate reply obtained at stage 700.

Otherwise, Trust Protection Foundation imports both the private key (stage 300) and the certificate reply (stage 700) into the keystore.

For additional information, see About the benefits of central key generation.

 

Green check mark, indicates feature is supported

803

ReplaceLabel

If the Reuse Label option is selected on the JKS application object, Trust Protection Foundation re-installs the certificate with the correct label.

 

Green check mark, indicates feature is supported

900

CheckConfiguration

Reserved for future use.

 

 

1000

ConfigureApplication

Reserved for future use.

 

 

1100

RestartApplication

Reserved for future use.

 

 

1200

EndProcessing

Trust Protection Foundation completes the certificate processing and, if configured, runs a Validation check on the certificate and application.

 

Green check mark, indicates feature is supported

1400

Revocation

Trust Protection Foundation submits a revocation request to the CA.

NOTE  Certificate revocation is a certificate operation; it does not involve the application driver.

Green check mark, indicates feature is supported

Green check mark, indicates feature is supported