JKS certificate lifecycle
The following table outlines the stages of the certificate lifecycle for certificates located in Java keystores and the management level associated with each stage.
|
Stage |
Friendly Name |
Description |
Enrollment |
Provisioning |
|
Stages 0-700 are performed by the JKS application driver only if remote key generation is enabled. If the private key and CSR are locally generated on the Trust Protection Foundation server, stages 0-700 are performed by the X509Certificate application driver. NOTE The private key and CSR are remotely generated on the certificate’s consumer application(s) if the Generate Key/CSR on Application option is enabled in the certificate object. |
||||
|
0 |
StartProcessing |
No processing. |
|
|
|
100 |
CheckStore |
No processing. |
|
|
|
200 |
CreateConfigureStore |
Only applies to remote generation. Trust Protection Foundation creates a backup of the keystore, if it exists. If the configured keystore does not exist and the Create option is selected on the JKS application object, Trust Protection Foundation creates the certificate keystore. For more information, see the Create setting in the Java Keystore Settings table. |
|
|
|
300 |
CreateKey |
No processing.
DID YOU KNOW? Stage 300 is used for key generation only when the API of a target device separates keypair and CSR generation. When they're combined, both key and CSR generation are always done at stage 400. |
|
|
|
400 |
CreateCSR |
Trust Protection Foundation creates the Certificate Signing Request (CSR). If remote key generation is enabled, the Java keytool utility is used to generate the CSR. Otherwise, Trust Protection Foundation generates the CSR. |
|
|
|
500 |
PostCSR |
Trust Protection Foundation submits the CSR to the certificate authority (CA). NOTE If you post a manual CSR, this is the first stage of the certificate lifecycle. |
|
|
|
600 |
ApproveRequest |
Trust Protection Foundation approves the certificate renewal at the CA. |
|
|
|
700 |
RetrieveCertificate |
Trust Protection Foundation retrieves the certificate from the CA. |
|
|
|
800 |
CheckKeyStore
|
If the certificate and private key are generated on the Trust Protection Foundation server, this is the stage when Trust Protection Foundation determines if the configured keystore exists. If the keystore does not exist and the Create option is selected on the JKS application object, Trust Protection Foundation creates the certificate keystore. If the keystore exists, Trust Protection Foundation creates a backup of the keystore on the same Directory. For more information on the backup procedure, see About keystore backups. |
|
|
|
801 |
InstallCertificateChain |
Trust Protection Foundation installs the root certificate chain. NOTE The Java Keytool will not allow a certificate to be installed if the appropriate root and intermediate root certificates are not already installed in the keystore. NOTE Root certificates can be discovered and brought under management, or they can be manually imported. For more information, see Managing root certificates. |
|
|
|
802 |
InstallCertificate |
If remote key generation is enabled, Trust Protection Foundation uses the Java keytool utility to import the certificate reply obtained at stage 700. Otherwise, Trust Protection Foundation imports both the private key (stage 300) and the certificate reply (stage 700) into the keystore. For additional information, see About the benefits of central key generation. |
|
|
|
803 |
ReplaceLabel |
If the Reuse Label option is selected on the JKS application object, Trust Protection Foundation re-installs the certificate with the correct label. |
|
|
|
900 |
CheckConfiguration |
Reserved for future use. |
|
|
|
1000 |
ConfigureApplication |
Reserved for future use. |
|
|
|
1100 |
RestartApplication |
Reserved for future use. |
|
|
|
1200 |
EndProcessing |
Trust Protection Foundation completes the certificate processing and, if configured, runs a Validation check on the certificate and application. |
|
|
|
1400 |
Revocation |
Trust Protection Foundation submits a revocation request to the CA. NOTE Certificate revocation is a certificate operation; it does not involve the application driver. |
|
|