Generating an HTTPS security certificate
When Active IQ Unified Manager is installed for the first time, a default HTTPS certificate is installed. You might generate a new HTTPS security certificate that replaces the existing certificate.
Before you begin
You must have the Application Administrator role.
About this task
There can be multiple reasons to regenerate the certificate such as if you want to have better values for Distinguished Name (DN) or if you want a higher key size, or longer expiry period or if the current certificate has expired.
If you do not have access to the Unified Manager web UI, you can regenerate the HTTPS certificate with the same values using the maintenance console. While regenerating certificates, you can define the key size and the validity duration of the key. If you use the Reset Server Certificate
option from the maintenance console, then a new HTTPS certificate is created which is valid for 397 days. This certificate will have an RSA key of size 2048 bits.
Steps
-
In the left navigation pane, click General > HTTPS Certificate.
-
Click Regenerate HTTPS Certificate.
The Regenerate HTTPS Certificate dialog box is displayed.
-
Select one of the following options depending on how you want to generate the certificate:
If you want to… | Do this… | ||
---|---|---|---|
Regenerate the certificate with the current values |
Click the Regenerate Using Current Certificate Attributes option. |
||
Generate the certificate using different values |
Click the Update the Current Certificate Attributes option. The Common Name and Alternative Names fields will use the values from the existing certificate if you do not enter new values. The “Common Name” should be set to the FQDN of the host. The other fields do not require values, but you can enter values, for example, for the EMAIL, COMPANY, DEPARTMENT, City, State, and Country if you want those values to be populated in the certificate. You can also select from the available KEY SIZE (The key algorithm is “RSA”.) and VALIDITY PERIOD.
|
-
Click Yes to regenerate the certificate.
-
Restart the Unified Manager server so that the new certificate takes effect.
After you finish
Verify the new certificate information by viewing the HTTPS certificate.