Certificate Requirements

The following table outlines the certificate requirements for various components within the ESA infrastructure:

S.No.CertificateCNSANCert TypeComments
1CAAs per industry standardsNACANA
2ESA Management – ServerFQDN of ESA where it is appliedHostname and FQDN of ESA where it is appliedServerEach ESA would have its own unique server certificate.
3ESA Management – ClientProtegrity ClientNAClientEach ESA would have its own unique client certificate.
4Consul Serverserver.<datacenter name>.<domain>127.0.0.1
Hostname and FQDN of ESA where it is applied
ServerEach ESA would have its own unique server certificate.
The domain and datacenter name must be equal to the value mentioned in the config.json file.
For example,
server.ptydatacenter.protegrity.
Skip this certificate, consul is uninstalled, and traditional TAC is being used.
5Audit Store – Serverinsights_clusterHostname and FQDN of all the ESAs in the Audit Store ClusterServerAll the ESAs in the Audit Store Cluster should share the same certificate.
6Audit Store – Clientes_security_adminNAClientAll the ESAs in the Audit Store Cluster should share the same certificate.
7Audit Store REST – ServerUse same certificate created in entry 5Use same certificate created in entry 5ServerAll the ESAs in the Audit Store Cluster should share the same certificate.
8Audit Store REST – Clientes_adminNAClientAll the ESAs in the Audit Store Cluster should share the same certificate.
9Audit Store PLUG – ClientplugNAClientAll the ESAs in the Audit Store Cluster should share the same certificate.
10Audit Store Analytics – Clientinsight_analyticsNAClientAll the ESAs in the Audit Store Cluster should share the same certificate.
11DSG Management-ServerFQDN of DSG where it is appliedHostname and FQDN of DSG where it is appliedServerEach DSG would have its own unique server certificate.
12DSG Admin Tunnel – Server CertificateFQDN of DSG where it is appliedHostname and FQDN of DSG where it is appliedServerEach DSG would have its own unique server certificate.
13DSG Tunnel – Client CertificateProtegrityClientNAClientCN value is configurable in gateway.json

Last modified : October 31, 2025