...
Transport Certificates
Drawio | ||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Cert Name | Description | Issuer | Private Key held by | CSR generated by | Certificate Generated by | Actions required by LFI | |
---|---|---|---|---|---|---|---|
C1 | Identifies the TPP to OFP | OFTF | TPP | TPP | TPP | None | |
S2 | Identifies non mtls OFP endpoints to TPP | Lets Encrypt | Ozone | NA | Ozone | None | |
S1 | Identifies mtls OFP endpoints to TPP | OFTF | Ozone | Ozone | LFI | Yes | |
C4 | Identifies OFP to LFI’s Ozone Connect endpoint | OFTF | Ozone | Ozone | LFI | Yes | |
S4 | Identifies LFI’s Ozone Connect endpoint to Ozone | OFTF | LFI | LFI | LFI | Yes | Ozone will provide scripts to the LFI to assist with CSR generation if requested |
S3 | Identifies | OFTF | Ozone | Ozone | LFI | Yes | |
C3 | Identifies LFI to the | OFTF | LFI | LFI | LFI | Yes | Ozone will provide scripts to the LFI to assist with CSR generation if requested The subject of the certificte should be provided to Ozone. Ozone will limit access to certifictes issued by OFTF AND having that specific subject |
Drawio | ||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
...