The CA-signed certificate chain for the Manager and the Sensor is considered valid if the following conditions are met:
- The CSR should not be modified after exporting from the Manager. This will cause the certificate validation in the Manager to fail.
- The certificate must be X.509v3 version.
- The CA-signed certificate chain should comply with the following requirements:
- Should be issued from a trusted Certificate Authority
- Should be in .pem format
- Must contain valid serial numbers and valid issuer domain name
- Must include minimum SHA256 with RSA 2048 bit encryption
- The number of intermediate CA-certificates in the certificate chain should be between 0 and 4.
- The certificate chain should be in correct order. The chain should begin with the identity certificate (also known as leaf certificate) followed by intermediate CA-certificate 1, intermediate CA-certificate 2, ... intermediate CA-certificate N and end with the root CA-certificate.
- The identity certificate must be signed by the intermediate CA. The intermediate certificate must be signed by the root CA.
- The Basic Constraint CA flag must be set to True in case of root and intermediate certificates. For identity certificate, the flag must be set to False.
- The certificate must comply with the following parameters:
- ExtendedKeyUsage: TLS WebServerAuthentication and TLS WebClientAuthentication
- KeyUSage: Must not be set to Critical.
- Ensure that the validity period for the certificate specifies a valid date range.
- OCSP requests and responses use
CertID.issuerNameHash and
CertID.issuerKeyHash parameters to validate the revocation status of CA certificates.
Currently, the Manager supports SHA-1 hashing algorithm for the two parameters which needs to be managed in OCSP server configuration.