This topic explains the concept of a keystore, which stores device certificates, private keys, aliases, and issuer information for systems such as Cisco IoT FND or TPS proxy.
The keystore is a secure storage repository that holds device certificates, private keys, aliases, and issuer information for specific systems such as Cisco IoT FND or TPS proxy.
-
Stores device certificates and private keys.
-
Contains aliases and issuer information.
-
Used by systems like Cisco IoT FND and TPS proxy.
The following table lists the certificate types used by Cisco IoT FND and the keystore location of the certificates.
| Cisco IoT FND Certificate Type |
Keystore Location |
|---|---|
| Device Certificate |
|
| Web Certificate |
|
| CSMP Certificate |
HSM or SSM |
The keystore must contain the following information for Cisco IoT FND to function:
-
Cisco SUDI or the device manufacturing certificate.
-
The root CA certificate of the issuing root CA or sub-CA server.
-
The certificate that is generated for the Cisco IoT FND server or TPS server for TPS (private key for the system).
For example, the keystore for Cisco IoT FND may contain a device certificate stored in cgms_keystore , a web certificate in jbossas.keystore , and a CSMP certificate in HSM or SSM.