Skip to main content

PKI Certificate Parameters

You can customize the certificates that Combine's PKI generates, including key size, signing algorithm, private key encryption, and additional DNS names. You can also set the key size and signing algorithm from the TAP Dashboard, in the Certificate Settings section of Admin Settings > TAP Settings > Application Configuration.

NOTE: Changes to certificate parameters require a certificate rebuild to take effect. Contact your Combine Support Team for assistance with certificate rotation.

Configuration​

Set these Configuration Values in the Combine Configuration table (the combine-configuration DynamoDB table). See Edit Combine Configuration Values for instructions.

Certificate Key and Signing Options​

Configuration ValueDefaultDescription
combine.tap.certificates.key.size2048RSA key size in bits for generated certificates, for example 3072.
combine.tap.certificates.hash.algorithmSHA256withRSASigning algorithm used to generate certificates, for example SHA384withRSA.

Certificate Encryption​

Combine can encrypt the private key file (.key.pem) that it generates for a user or server certificate with the certificate password.

Configuration ValueDefaultDescription
combine.tap.certificates.user.key.encryptedfalseWhen true, encrypts the private key in user certificates.
combine.tap.certificates.server.key.encryptedfalseWhen true, encrypts the private key in server certificates.

Custom DNS Names​

You can add DNS Subject Alternative Names (SANs) to the TAP Server and Endpoint Server certificates to support custom DNS zones or external access. Each value is a space-separated list of DNS names.

Configuration ValueDefaultDescription
combine.tap.certificates.dns.tap.internal(empty)Additional DNS SANs added to the internal TAP Server certificate.
combine.tap.certificates.dns.tap.internal.directAccesstap.combine.ioDirect-access DNS names added to the internal TAP Server certificate.
combine.tap.certificates.dns.tap.external(empty)Additional DNS SANs added to the external TAP Server certificate.
combine.tap.certificates.dns.tap.external.directAccesstap.combine.io *.sequoiacombine.ioDirect-access DNS names added to the external TAP Server certificate.
combine.tap.certificates.dns.endpoints(empty)Additional DNS SANs added to the Endpoint Server certificate.
combine.tap.certificates.dns.endpoints.directAccessendpoints.combine.ioDirect-access DNS names added to the Endpoint Server certificate.