Step 1 - Configuring ICAO PKD Upload Settings
The ICAO PKD Upload Settings are used to upload Document Signer (DS) certificates, Master Lists (containing CSCA certificates), and Certificate Revocation Lists (CRLs) to the ICAO Public Key Directory (PKD). Once uploaded, this information becomes available to ICAO member states and participating countries.
To configure ICAO PKD Upload Settings, navigate to the following screen in the ADSS Server console:

The configuration items are described below:
|
Items |
Description |
|
ICAO PKD Server Address |
Specifies the LDAP server address of the ICAO PKD to which data will be uploaded. |
|
List of ICAO PKD Server Address |
Allows multiple server addresses to be configured. Click Add to include one or more ICAO PKD server addresses. The configured addresses will be displayed in this field. |
|
Port |
Defines the LDAP server port number used for communication. |
|
Bind DN/User |
Specifies the distinguished name (DN) or user ID used for binding to the LDAP server. |
|
Password |
The password associated with the Bind DN/User for authentication. |
|
Use TLS Client Authentication |
When enabled, the NPKD Service communicates with the ICAO LDAP server using TLS client authentication. Select the TLS client certificate from the Key Manager. The certificate can be chosen from the available list using the drop-down menu that appears when this option is enabled. Note: The Issuer CA of the selected TLS client authentication certificate must be registered in the Trust Manager with the appropriate CA purpose to validate TLS client certificates. |
Ensure that all configuration settings are saved by clicking the Save button.
After completing the above configurations, the LDAP server base path must also be defined to enable data upload to the ICAO PKD. To configure the base path, click here.
See also
Step 1 - Configuring ICAO PKD Upload Settings
Step 2 - Configuring ICAO PKD Download Settings
Step 3 - Registering Business Application
Step 4 - Using the Service Manager