Oracle-Based Deployment Guide for Cisco IoT FND, Release 5.x.x and Later

PDF

Oracle-Based Deployment Guide for Cisco IoT FND, Release 5.x.x and Later

Keystore

Want to summarize with AI?

Log in

This topic explains the concept of a keystore, which stores device certificates, private keys, aliases, and issuer information for systems such as Cisco IoT FND or TPS proxy.


The keystore is a secure storage repository that holds device certificates, private keys, aliases, and issuer information for specific systems such as Cisco IoT FND or TPS proxy.

  • Stores device certificates and private keys.

  • Contains aliases and issuer information.

  • Used by systems like Cisco IoT FND and TPS proxy.

The following table lists the certificate types used by Cisco IoT FND and the keystore location of the certificates.

Table 1. Keystore Certificate Types and Locations

Cisco IoT FND Certificate Type

Keystore Location

Device Certificate

cgms_keystore

Web Certificate

jbossas.keystore

CSMP Certificate

HSM or SSM

The keystore must contain the following information for Cisco IoT FND to function:

  • Cisco SUDI or the device manufacturing certificate.

  • The root CA certificate of the issuing root CA or sub-CA server.

  • The certificate that is generated for the Cisco IoT FND server or TPS server for TPS (private key for the system).

For example, the keystore for Cisco IoT FND may contain a device certificate stored in cgms_keystore , a web certificate in jbossas.keystore , and a CSMP certificate in HSM or SSM.