Create a new Azure API Management machine¶
Creating a new machine is the initial step in enabling Certificate Manager - SaaS to connect directly to Azure API Management for certificate management. Once you have created machines, you can move on to provisioning certificates to those machines.
Before you begin¶
- Azure tenant ID, application (client) ID, and client secret from an Azure Active Directory service principal.
- Minimum required permissions on Azure: The service principal must have the API Management Service Contributor role (or equivalent read and write access) on the target Azure API Management instance.
- Azure subscription ID, resource group name, and API Management service name for the target instance.
- Credentials: Choose between user credentials or shared credentials.
- User credentials: Enter the Azure service principal credentials manually.
- Shared credentials: Optionally, you can use shared credentials from your credential provider (CyberArk is the only credential provider currently supported by Certificate Manager - SaaS). To use this option, first set up the connection to CyberArk.
Note
- No VSatellite is required. The connector operates against the Azure management plane over outbound HTTPS only.
- Azure Managed Identity is not yet supported as a connection option; a long-lived Azure AD application secret is required.
- Certificates sourced from Azure Key Vault are flagged during discovery. Provisioning installs uploaded (Custom) certificates and converts Key Vault-backed hostnames to Custom. The Key Vault reference is preserved for non-targeted domains.
Connection details¶
-
(Optional) From the Credential Type drop-down, select either Enter Credentials or Select Credentials. Only users with the enabled "CyberArk shared credential" capability will see this option.
Important
Your view of credentials may be limited due to your role. System Administrators and PKI Administrators should be able to select any credential, but users with the Resource Owner role are restricted to using the credentials associated with their teams.
Note
- Enter Credentials - Is used to enter your Azure service principal credentials manually.
- Select Credentials - Is used to select your shared credentials from CyberArk.
- If you choose Enter Credentials, proceed to the next step and enter your Azure credentials.
- If you choose Select Credentials, from the Credential drop-down, select your shared credentials.
-
Enter your Tenant ID. This is the unique identifier of the Azure Active Directory instance.
-
Enter your Client ID. This is the unique identifier of the Azure AD application (service principal) used for authentication.
-
Enter your Client Secret. This is the credential that authenticates and authorizes the client application when it interacts with Azure services.
Warning
Remember to store your username and password securely when creating a new machine. For security reasons, you will not be able to modify the fields under the "Access" tab without these credentials. This ensures that only authorized individuals can modify these fields.
-
Enter your Subscription ID. This is the Azure subscription that contains your API Management instance.
-
Enter your Resource Group name. This is the Azure resource group that contains your API Management service.
-
Enter your Service Name. This is the name of your Azure API Management instance.
-
Click Test Access, then click Continue. Note that Continue is only enabled if the Test Access is successful.
What's next?¶
Refer back to Create a new machine to finish setting up your new machine by configuring Discovery and Provisioning scheduling.
For existing machines:
- Now that you have one or more machines created, you can provision certificates to those machines.
- You can also discover certificates on machines to enable easy tracking of certificates deployed to your machines.