Certificate Requirements

The following table outlines the certificate requirements for various components within the ESA infrastructure:

S.No.CertificateCNSANCert TypeComments
1CAAs per industry standardsNACANA
2ESA Management – ServerFQDN of ESA where it is appliedHostname and FQDN of ESA where it is appliedServerEach ESA would have its own unique server certificate.
3ESA Management – ClientProtegrity ClientNAClientEach ESA would have its own unique client certificate.
4Consul Serverserver.<datacenter name>.<domain>127.0.0.1
Hostname and FQDN of ESA where it is applied
ServerEach ESA would have its own unique server certificate.
The domain and datacenter name must be equal to the value mentioned in the config.json file.
For example,
server.ptydatacenter.protegrity.
Skip this certificate, consul is uninstalled, and traditional TAC is being used.
5Audit Store – Serverinsights_clusterHostname and FQDN of all the ESAs in the Audit Store ClusterServerAll the ESAs in the Audit Store Cluster should share the same certificate.
6Audit Store – Clientes_security_adminNAClientAll the ESAs in the Audit Store Cluster should share the same certificate.
7Audit Store REST – ServerUse same certificate created in entry 5Use same certificate created in entry 5ServerAll the ESAs in the Audit Store Cluster should share the same certificate.
8Audit Store REST – Clientes_adminNAClientAll the ESAs in the Audit Store Cluster should share the same certificate.
9Audit Store PLUG – ClientplugNAClientAll the ESAs in the Audit Store Cluster should share the same certificate.
10Audit Store Analytics – Clientinsight_analyticsNAClientAll the ESAs in the Audit Store Cluster should share the same certificate.
11DSG Management-ServerFQDN of DSG where it is appliedHostname and FQDN of DSG where it is appliedServerEach DSG would have its own unique server certificate.
12DSG Admin Tunnel – Server CertificateFQDN of DSG where it is appliedHostname and FQDN of DSG where it is appliedServerEach DSG would have its own unique server certificate.
13DSG Tunnel – Client CertificateProtegrityClientNAClientCN value is configurable in gateway.json

The following table provides example as per the recommended deployment architecture mentioned in the section Model Architecture.

S.No.CertificateCNSANCert Type
1CAAs per industry standardsNACA
2ESA Management – ServerESA P1ESAP1.protegrity.comESA P1ESAP1.protegrity.com 
ESA S1ESAS1.protegrity.comESA S1ESAS1.protegrity.com
ESA S2ESAS2.protegrity.comESA S2ESAS2.protegrity.com
ESA S3ESAS3.protegrity.comESA S3ESAS3.protegrity.com
ESA S4ESAS4.protegrity.comESA S4ESAS4.protegrity.co
ESA S5ESAS5.protegrity.comESA S5ESAS5.protegrity.com
3ESA Management – ClientProtegrity ClientNAClient
4Consul ServerESA P1server.ptydatacenter. protegrityESA P1ESAP1.protegrity.comServer
ESA S1server.ptydatacenter. protegrityESA S1ESAS1.protegrity.com
ESA S2server.ptydatacenter. protegrityESA S2ESAS2.protegrity.com
ESA S3server.ptydatacenter. protegrityESA S3ESAS3.protegrity.com
ESA S4server.ptydatacenter. protegrityESA S4ESAS4.protegrity.com
ESA S5server.ptydatacenter. protegrityESA S5ESAS5.protegrity.com
5Audit Store – ServerAudit Store Cluster- Primary SiteESA P1insights_clusterESA P1ESAP1.protegrity.com
ESAS1.protegrity.com
ESAS2.protegrity.com
Server
ESA S1insights_clusterESA S1ESAP1.protegrity.com
ESAS1.protegrity.com
ESAS2.protegrity.com
ESA S2insights_clusterESA S2ESAP1.protegrity.com
ESAS1.protegrity.com
ESAS2.protegrity.com
Audit Store Cluster- DR SiteESA S3insights_clusterESA S3ESAS3.protegrity.com
ESAS4.protegrity.com
ESAS5.protegrity.com
ESA S4insights_clusterESA S4ESAS3.protegrity.com
ESAS4.protegrity.com
ESAS5.protegrity.com
ESA S5insights_clusterESA S5ESAS3.protegrity.com
ESAS4.protegrity.com
ESAS5.protegrity.com
6Audit Store – Clientes_security_adminNAClient
7Audit Store REST – ServerUse same certificate created in entry 5Use same certificate created in entry 5Server
8Audit Store REST – Clientes_adminNAClient
9Audit Store PLUG – ClientplugNAClient
10Audit Store Analytics – Clientinsight_analyticsNAClient
11DSG Management-ServerFQDN of DSG where it is appliedHostname and FQDN of DSG where it is appliedServer
12DSG Admin Tunnel – Server CertificateFQDN of DSG where it is appliedHostname and FQDN of DSG where it is appliedServer
13DSG Tunnel – Client CertificateProtegrityClientNAClient

Last modified : July 30, 2025