Hi,
I’m currently figuring out if the Hub is a product we can use for our company to easily manage certificate requests and manage the certificates on our customers servers.
While testing I noticed that I could remove the “job” from the hub when I delete the “managed certificate job” from the “client” (CCM).
Am I missing something to disable this way of the API?
Also; when i delete an “instance” from the hub, a few seconds later it rejoins automatically.
So if you don’t have control over the end-customer server, I cant even get rid of the instance?
Must be a way right?
Yes the administrator of the machine can remove managed certificate configurations (“job” isn’t a term used in our system so I was initially confused what you meant), it’s their machine and they are the administrator if they can access the app (you have to be in the administrators group to use the app).
However we are considering the ability to limit or alert that - it hasn’t been requested by a customer before as normally administrators are trusted.
Regarding joining the hub, if you provide hub joining credentials to a server then it can join the hub and it will continue to join the hub unless you invalidate the joining credentials.
If you don’t control the instances connected to the hub I would suggest having a different joining key per organization (a security principal and API key, with the Hub Managed Instance role) for
We will look at making that easier as it’s obviously more complex than it should be currently. As a workaround to remove an instance for the hub, first remove the joining key from the instances stored credentials, then restart the instances Certify Management Agent service, then remove the instance in the hub.
My approach is seen from the MSP side of things, not a system administrator
Since the SSL certificates gains less lifetime, a product as this is becoming more and more viable.
Definitly an option to “lock” certificates that come from a hub instead of created locally is a welcome option!