Import certificates from a Zero Touch PKI CA¶
In Certificate Manager - SaaS, you can connect to Zero Touch PKI via API and import certificates from its certificate authorities (CAs). You import certificates based on their Zero Touch PKI certificate policy.
Prerequisites¶
- From your Zero Touch PKI administrator, an account with access to the certificates to import. For security, CyberArk recommends the Service Requestor role.
- From the account, an API ID and key.
- The URL of your Zero Touch PKI instance.
- An understanding of which certificate policies you'll import certificates from.
- In Certificate Manager - SaaS, administrative access via the Platform Administrator, PKI Administrator, or System Administrator roles.
To import certificates from Zero Touch PKI¶
- Sign in to Certificate Manager - SaaS.
- Click Integrations > Certificate Authorities.
- Click New > Zero Touch PKI.
- In Step 1 of 2:
- Enter a Name for the CA.
- Select the Zero Touch PKI URL of your instance.
- In API Key ID, enter the API ID from the account.
- In API Key, enter the API key from the account.
- Click Test Connection.
- Click Create.
- In Step 2 of 2:
- In Product Options, search for and select the certificate policies from which you're importing certificates.
- (Optional) In Import options, select Include revoked certificates or Include expired certificates.
- (Optional) Turn on Scheduled import and choose a schedule.
- Click Done.
After the import runs, your Certificate Manager - SaaS inventory contains the imported Zero Touch PKI certificates. You can also run the import manually in the Import tab.