3.6 3.5 3.4
3.6 3.5 3.4

Certificate Management: Bring Your Own Certificates (BYOC)

Manage bringing your own public CA or enterprise PKI certificates for On-Prem AgileSec production deployments.

Approaches

AgileSec provides generate_certs.sh for on-prem installations to generate and self-sign all required certificate material. Installer-generated certificates are recommended for proof of concepts and first-time installations. However, for production deployments users will often want to employ Bring Your Own Certificates (BYOC) approaches, replacing installer-generated certificates with public CA or enterprise PKI options.

Choose BYOC for internal client certificates when you need one or more of the following:

  • Policy or compliance requires all TLS/mTLS certificates to be issued by the enterprise PKI.

  • Centralized lifecycle management is required (standard issuance, rotation, and revocation).

  • You require stronger isolation (for example, per-service client certificates managed by PKI).

  • You need alignment with existing certificate management tooling and operational processes.

There are two approaches for BYOC certificate management:

BYOC Approach

Description

Recommended for

Approach 1: Replace external certificates only

Replace the external (user-facing) certificate with your enterprise PKI or public CA certificate, while keeping internal server/client certificates, admin client certificates, and SAML signing certificate generated by the installer.

Most production deployments.

Approach 2: Replace all certificate material

Replace the external certificate and replace internal server/client certificates, admin client certificates, and SAML signing certificate using your enterprise PKI / organization process.

Production only if required by policy (higher operational overhead).

Note: External TLS is typically terminated at the frontend HAProxy (or an external load balancer, if deployed in front of HAProxy), depending on your topology.

Secrets Manager Keystore: The Secrets Manager (SM) service uses a dedicated keystore to generate and protect platform key material. For Proof of Concepts, you may use the installer-generated alias values. For production, you must regenerate these aliases so they are unique to your environment and do not rely on defaults.

See BYOC: Update Secrets Manager Keystore.


BYOC Management Strategy

The goal is to ensure the platform has the correct .env configuration, the expected certificate directory layout exists, and any custom certificate material is placed using the exact filenames and parameters AgileSec expects.

  1. Prepare Environment

    1. Determine configuration details.

    2. Apply install configuration details to BYOC certificates (or vice versa).

    3. Create install configuration file .env as detailed in On-Prem Installation Guides.

    4. Run generate_certs.sh to create the baseline certificate structure for correct updates.

  2. Check requirements for each type of BYOC certificate.

  3. Replace the necessary generated certificates for your approach in place using the same filenames and directories as installer-generated material.

When using BYOC, ensure you can provide the client certificate, private key, and any intermediate CA chain using the same filenames and locations expected by AgileSec, so service configuration does not need to be modified.


BYOC Steps

See the following pages for prerequisites and instructions to manage BYOC certificates.