Est subsystem deplyment change #5169
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Following the other change to EST subsystem the deployment has been modified to work like other subsystem, in particular TPS.
The certificates for EST are obtained from the CA after security domain registration. The EST communicate with the CA using the subsystem certificate and it is associated to the "Certificate Manger Agents" role.
The CA administrator has the role for "Enterprise EST Administrators".
The est profile is associated to the new role and it is enabled but not visible by default.
Standalone 2-steps installation is supported as well as the previous installation with certificates provided in a p12.
Test have been updated for the new approach.