Skip to content

Register with Hub

The Register with Hub dialog is the remote QIE's side of site enrollment. The site administrator uses it to import the .qcb bundle the Hub operator generated, and afterwards to start, stop, or remove the registration.

On the remote QIE, open System Administration -> System Configuration and click Register with Hub in the toolbar, beside Management API.

Register with Hub dialog on a QIE that is not yet registered: Current Registration shows Not registered, and Replace Registration With New Bundle shows the parsed contents of the Foo Hospital bundle, ready for Confirm Registration.

The dialog has two sections.

Current Registration

If the QIE is already registered with a Hub, the top section shows the current registration. While the dialog is open it checks the tunnel status every 3 seconds, and the status bar warns that importing a new bundle overwrites the registration.

Field Meaning
Tunnel Status Not registered when the QIE has no registration, STOPPED after Stop Tunnel, CONNECTING while the tunnel is started but not connected, and CONNECTED once it is up
Registered Hub The wss://...:port/tunnel URL the client dials
Site Display Name The display name the Hub assigned to this site
Site Identifier The site UUID (matches the cert subject CN)
Client Cert Serial Serial number of the active client cert
Trusted Hub CA Serial Serial number of the Hub internal CA this QIE trusts. This is the trust anchor. Any server cert the CA signs validates, so a routine Hub server-cert rotation does not change this value

Three buttons control the lifecycle:

Button Effect
Start Tunnel Sets enabled=true on the registration and starts the tunnel client (if it was stopped)
Stop Tunnel Sets enabled=false and tears down the tunnel without losing credentials. Use this to suspend connectivity for maintenance
Unregister After a confirmation, deletes the local registration row, client cert, and trusted Hub CA cert. The Hub-side site row stays. Revoke it from the Hub if you want to fully decommission

Replace Registration With New Bundle

This section walks through importing a .qcb file. Importing replaces any existing registration: the previous client cert and trusted Hub CA cert are deleted and the tunnel restarts with the new credentials.

  1. Select bundle file (.qcb) is a file-upload picker. Choosing a file triggers an immediate upload to the QIE server. The server parses the JWS and verifies the signature against the Hub internal CA cert embedded inside the bundle (the bundle is signed by the CA private key), then returns the parsed fields to the dialog.
  2. Review bundle contents shows all parsed fields read-only: Hub URL, Site Identifier, Subdomain, Display Name, Description, Hub CA Cert Serial, Bundle Expires.
  3. Click Confirm Registration. If the QIE is already registered, an Overwrite Existing Registration confirmation comes first.

Close dismisses the dialog and does nothing else. It does not unregister the site, stop the tunnel, or undo a registration that has already been confirmed. To undo a registration, use Unregister.

On Confirm:

  1. QIE generates a fresh RSA-4096 keypair locally.
  2. QIE builds a CSR and POSTs { bundleId, csrPem } as JSON to the bundle's hubRegisterUrl. The TLS connection is validated by chaining the Hub's server cert to the CA cert in the bundle. The system trust store is not consulted.
  3. Hub verifies the bundle (not consumed, not expired), signs the CSR with the internal CA forcing the CN to the bundle's intendedSiteIdentifier, creates the hub_site row, and marks the bundle consumed.
  4. Hub returns { signedCertPem, siteIdentifier, subdomainLabel }.
  5. QIE saves the cert + key into its SSL Certs / Keys store, the Hub CA cert into its SSL Certs / Keys store (as the tunnel trust anchor), and populates the hub_registration singleton.
  6. QIE starts its tunnel client. mTLS handshake on /tunnel succeeds because the QIE's cert is now signed by the Hub's internal CA, and the listener's trust manager finds the matching hub_site row by serial.

If everything succeeds, a Registered message shows the site identifier and subdomain, the Current Registration section fills in, and Tunnel Status changes from CONNECTING to CONNECTED once the tunnel is up. On the Hub side, the site appears in the Sites Dashboard with a green status icon.