About the benefits of central key generation

A primary advantage of central key generation is that it eliminates the dependency on device-side utilities, such as Java Keytool. Typically, central generation is also faster because command line utilities are rarely optimized for performance.

In addition, central generation keeps a copy of the private key in Trust Protection Foundation to allow for key recovery, for provisioning the same certificate to multiple devices, and for security-related cases where you want to enable TLS traffic inspections.

When performing central generation, CyberArk's JKS driver places a temporary copy of the keystore from the managed system into memory so that Trust Protection Foundation can perform the key operations.

Whenever the JKS driver modifies the keystore—this happens at the installation step when the Generate Key/CSR on Application option is disabled (set to No)—it verifies that the keystore on the managed system has not changed. If the local keystore has not changed, the JKS driver overwrites the local copy with the updated copy of the keystore.

If the JKS driver detects that the local keystore on the managed system has been altered while it was modifying its copy of the keystore—for example, if someone manually added a key or certificate—then it returns an error stating that the “Keystore is in use by another process” and it halts processing on the application without uploading or replacing the keystore, while not overwriting the local copy. The JKS driver also logs the “Certificate Chain Install Failed” (event ID 400E000F) and “Certificate Install Failed” (event ID 400E000B) events to the Trust Protection Foundation log store.