Publish a certificate through a cURL destination

Prev Next

The cURL destination sends a certificate to any endpoint reachable over HTTP. An execution template, not the product, describes the request (address, method, body, and authentication). A new destination contract needs a template edit, not a product release.

Requirements

  • A certificate.
  • A device registered as the publication target.
  • A credential with an execution profile configured. Without one, publishing fails with "The credential does not have an execution profile for this operation." This is a requirement of the Executions module, not specific to Certificate Manager.
  • Optional: an OAuth2 identity provider, if the destination requires token authentication.

Steps

Step 1: Create an execution template for certificate publication

  1. On Segura® Platform, in the navigation bar, hover over the Products menu and select Executions.
  2. In the side menu, select Templates control > Templates.
  3. Click Add.
  4. In the Name * field, enter a name for the template.
  5. In the Executor * field, select cURL.
  6. In the Execution type * field, select Certificate publication.
  7. In Content, write the request: address, method, headers, and body.
    • Wrap the request's JSON body in single quotes, because tags are substituted before the line is split into arguments.
    • If a value containing a space, such as a certificate's common name, is not quoted, it breaks the argument count. The publish then fails with a message about the number of parameters, which does not point to the real cause.
    • To authenticate with OAuth2 before publishing, add the identity provider's address and scope to the template. The client ID and client secret come from the publishing profile's credential: ID from the username, secret from the password. There is no separate line to fetch the token: the request line performs both calls, first the identity provider, then the destination.
  8. Click View TAGs to open the tag legend.
  9. Save the template.

Step 2: Create a CURL publishing profile

  1. On Segura® Platform, in the navigation bar, hover over the Products menu and select Certificate Manager.
  2. In the side menu, select Publishing > Publishing profiles.
  3. In the Add dropdown menu, select CURL.
  4. In the Settings tab, enter the profile name and, optionally, the credential used for execution. See Publishing profiles for the fields shared by every destination type.
  5. In the CURL tab, enter the following fields:
    1. In Execution template, select the execution template created in Step 1. This list only shows templates whose execution type is Certificate publication.
    2. Optional: in Additional information, enter a value to fill the [#CERT_ADD_INFO#] tag. This field accepts letters, numbers, dot, hyphen, and underscore only.
  6. Click Continue.
  7. In the Devices tab, select the target device.
  8. In the Review tab, review the information entered, and click Save.

Step 3: Publish a certificate

Publish through the CURL profile the same way as any other destination. See Publish a certificate. The system builds the request from the template, replacing each tag with the matching certificate material, and sends it to the address the template declares.

TLS verification

The appliance verifies the connection to the destination and, if configured, to the OAuth2 identity provider, before sending anything. If either side's certificate is not trusted by the appliance, the publish fails before sending any material. To resolve this, in order of preference:

  1. Trust the certificate authority on the appliance.
  2. Point the template to the trusted authority bundle.
  3. Add set-tls-verify off as the first line of the template, before the request line. Placing it after the request line is rejected.

The first two options keep verification active and are preferable to disabling it.

The private key never appears in the execution log. It is replaced with asterisks. If the template requests certificate material that is not stored (for example, a private key that was never imported), the publish fails instead of sending an empty field.