Print

Uploading an MPP server identity certificate

About this task

Use this procedure to upload an identity certificate for the MPP server through the Experience Portal web admin interface without re-installing the Experience Portal software. The identity certificate for the MPP server is issued by an external Certificate Authority.

Before you begin

importantImportant:
  • The imported certificate file must be in the PKCS#12 format. This includes an identity certificate, CA public certificates, and the corresponding private key. This certificate file is encrypted and requires a password. The password is chosen during the creation of the PKCS#12 file by the designated CA.

  • If Extended Key Usage is specified in the X509.V3 certificate extension, specify Server Authentication, which is also called serverAuth, and Client Authentication, which is also called clientAuth, for the usage.

  • The certificate must have a valid Common Name that represents the EP server host name.

  • If the Subject Alternate Name is specified in the X509 V3 certificate extension, the certificate must contain valid DNS and IP Address entries that are associated with the EP server host name.

Procedure

  1. Log on to the EPM web interface.
  2. Click Security > Certificates.
  3. Click the MPP Identity Certificates tab.
  4. On the MPP Identity Certificates tab, click Upload.
  5. On the Upload Identity Certificate page, do the following:
    1. In the Server Name field, click the name of the MPP server.
    2. In the Security Certificate File field, click Choose File and choose the PKCS#12 formatted security file for the MPP server.
    3. In the Password field, enter the password of the chosen PKCS#12 formatted security file.
    4. Click Continue.
  6. On the Save Identity Certificate page, do the following:
    1. Review the warning that the MPP services will be automatically restarted to install the identity certificate if the MPP is in the Running state.
      noteNote:

      If the MPP is in the Stopped state before this procedure, it will remain in the Stopped state after the new identity certificate is installed. The MPP needs to be manually started through System Management > EPM Manager to apply the new identity certificate on the MPP.

    2. Review the identity certificate text that is displayed to ensure it is the correct certificate to install for the MPP server.
    3. Click Save to install the identity certificate on the MPP.

Next Steps

If you have completed the Pre-requisites for importing custom identity certificates , do the following to re-establish the link between the Primary EPM and the MPP:

  1. Log on to the EPM web interface by using an account with the Administration user role.

  2. On the EPM main menu, click System Configuration > MPP Servers.

  3. Click the name of the MPP server.

  4. On the Change MPP Server page, navigate to the MPP Certificate section, and select the Trust new certificate check box.

  5. Click Save.