Updated Date: 05/27/2026
Integrating CyberArk Certificate Management with BIG-IQ
The BIG-IQ Centralized Management system supports integration with CyberArk as an external certificate authority (CA) provider for certificate lifecycle management.
You can use CyberArk integration to:
- Configure CyberArk as an external CA provider
- Retrieve and manage API authentication keys
- Retrieve and use certificate templates from CyberArk
- Generate and submit certificate signing requests (CSRs)
- Import and synchronize certificates from CyberArk
BIG-IQ communicates with CyberArk using REST APIs to authenticate, retrieve templates, request certificates, and synchronize certificates, and keys.
Before integrating CyberArk with BIG-IQ, ensure that:
- You have network connectivity between BIG-IQ and the CyberArk endpoint.
- You have valid CyberArk credentials or API key access.
- You have the required permissions to access applications and templates in CyberArk.
- Your BIG-IQ system is licensed and operational.
-
On the BIG-IQ menu, go to Configuration > LOCAL TRAFFIC > Certificate Management > Third Party CA Management.
-
Click Add.
-
From the Provider list, select CyberArk.
-
Type a unique provider name.
-
Select an API endpoint.
The API endpoint list displays the available CyberArk regional endpoints.
-
Specify authentication details using one of these methods:
- Manually enter the API key.
- Retrieve the API key using a CyberArk username and password.
-
Optional: Modify the automatically generated login URL if required.
-
Click Get API Key to retrieve the API key automatically.
-
In the Key Passphrase field, type the passphrase associated with the key.
-
Click Test Connection to validate connectivity and authentication with the CyberArk external CA.
-
Click Save.
BIG-IQ saves the CyberArk CA provider configuration and establishes connectivity with external CA.
You can configure application templates associated with the CyberArk CA provider.
-
Go to Configuration > LOCAL TRAFFIC > Certificate Management > Third Party CA Management.
-
Select the configured CyberArk provider.
-
Click Edit Template.
-
From the Application ID list, select an application.
BIG-IQ retrieves the list of application IDs associated with the selected CyberArk provider.
-
Select a template and associated nickname.
-
Click Save.
BIG-IQ saves the selected CyberArk template configuration.
-
Go to Configuration > LOCAL TRAFFIC > Certificate Management > Certificates & Keys.
-
Click Create.
-
From the Issuer list, select the configured CyberArk issuer.
BIG-IQ automatically retrieves all templates associated with the selected issuer.
-
Select a template.
BIG-IQ retrieves the following template details:
- CSR upload support status
- Supported key types
- Supported key curves
-
Configure the certificate request settings.
-
Generate or upload the CSR as required.
-
Click Save.
BIG-IQ submits the CSR request to CyberArk and creates the certificate request.
You can import certificates directly from CyberArk into BIG-IQ.
- Go to Configuration > LOCAL TRAFFIC > Certificate Management > Certificates & Keys.
- Click Import.
- Select Import from CA Providers.
- Select the configured CyberArk provider.
- Click Import.
BIG-IQ retrieves and synchronizes certificates from CyberArk.