TimWillemstein2 (Customer) to rsaSFDCadmin (RSA): asked a question.

Certificate validation for Collectors & Connectors etc.
Hi All,

Since years the whole concept of what keystores to use for trusting different
certificates has been a bit convoluted to me. I'm hoping you are able to help
me out to finalize the different keystores we have to use for different
purposes. I hope this helps me and others understand exactly what to do when
they have to create a trust.

I'll start with my limited knowledge of what keystores are required for which
setup:

**Request Forms** , more specifically the dropdown-menu-with-webservices =>
Place the certificate in the _cacert_ keystore of the server where acm is
installed. _Reboot of ACM is required_

**AFX Connector** ( _local installation_ , ACM is installed on the same server
as the AFX server) => Place the certificate in the _cacert_ keystore of the
server where AFX is installed. _Reboot of ACM / AFX? is required_

**AFX Connector** ( _remote installation_ , ACM is installed on a different
server from the AFX server) => Place the certificate in the _cacert_ keystore
of the server where AFX is installed. _Reboot required of ACM / AFX ?_

**Collector **( _local installation_ , ACM is installed on the same server as
the agent) => For this one I'm not sure, I know you can put the certificate
itself in the collector settings. But I've been having a lot of trouble with
this when the host is a domain and not a specific domain controller. I'm
hoping someone has a good approach for this and maybe even point out which
keystore to utilize (instead of GUI approach for completion sake). _Reboot of
ACM is required_

**Collector** ( _remote installation_ , ACM is installed on a different server
from the agent) => Same as above. _Reboot of ACM / RemoteAgent is required?_

I might have missed any here, so feel free to point those out!

Additionally I've been seeing in the patch notes that in newer versions
certificate can be uploaded through the UI instead of keystores, does anyone
know for which of these options that applies. This would of course simplify
everything immensely, which would be great.

Thank you in advance!

  • You didn't mention which version you are using, and I don't remember in which

    version **SSL Certificates** was added as an option under the **Files**

    section.

     

    BorisLekumovich_0-1693550449442 

    Check the product help: Administration > Managing the User Interface > Manage

    SSL Certificate

    It has some information which can clarify some of the questions.

    If you are on a version which does not has the functionality mentioned above,

    attaching a pdf with the relevant section from the help.

    Expand Post
    Selected as Best
  • You didn't mention which version you are using, and I don't remember in which

    version **SSL Certificates** was added as an option under the **Files**

    section.

     

    BorisLekumovich_0-1693550449442 

    Check the product help: Administration > Managing the User Interface > Manage

    SSL Certificate

    It has some information which can clarify some of the questions.

    If you are on a version which does not has the functionality mentioned above,

    attaching a pdf with the relevant section from the help.

    Expand Post
    Selected as Best