Print

Uploading an Auxiliary EPM server identity certificate

About this task

Use this procedure to upload an identity certificate for the Auxiliary EPM through the Experience Portal web admin interface without re-installing the Experience Portal software. The identity certificate for the Auxiliary EPM is issued by an external Certificate Authority.

Before you begin

importantImportant:
  • The imported certificate file must be in PKCS#12 format. This includes an identity certificate, CA public certificates and the corresponding private key. This certificate file is encrypted and requires a password. The password is chosen during the creation of the PKCS#12 file by the designated CA.

  • If Extended Key Usage is specified in the X509.V3 certificate extension, specify Server Authentication which is also called serverAuth, and Client Authentication which is also called clientAuth, for the usage.

  • The certificate must have a valid Common Name that represents the EP server host name.

  • If the Subject Alternate Name is specified in the X509 V3 certificate extension, the certificate must contain valid DNS and IP Address entries that are associated with the EP server host name.

Procedure

  1. Log on to the EPM web interface.
  2. Click Security > Certificates.
  3. Click the EPM Identity Certificates tab.
  4. On the EPM Identity Certificates tab, click Upload.
  5. On the Upload Identity Certificate page, do the following:
    1. In the Server Name field, click the name of the Auxiliary EPM server.
    2. In the Security Certificate File field, click Choose File and choose the PKCS#12 formatted security file for the Auxiliary EPM server.
    3. In the Password field, enter the password of the chosen PKCS#12 formatted security file.
    4. Click Continue.
  6. On the Save Identity Certificate page, do the following:
    1. Review the warning that the Auxiliary EPM services will be automatically restarted to install the identity certificate if the Auxiliary EPM is in the Running state.
      noteNote:

      If the Auxiliary EPM is in the Stopped state before this procedure, it will remain in the Stopped state after the new identity certificate is installed. The Auxiliary EPM needs to be manually started through System Management > EPM Manager to apply the new identity certificate on the Auxiliary EPM.

    2. Review the identity certificate text that is displayed to ensure it is the correct certificate to install for the Auxiliary EPM server.
    3. Click Save to install the identity certificate on the Auxiliary EPM.

Next Steps

If you have completed the Pre-requisites for importing custom identity certificates , do the following to re-establish the link between the Primary EPM and the Auxiliary EPM:

  1. Log on to the EPM web interface by using an account with the Administration user role.

  2. On the EPM main menu, click System Configuration > EPM Servers.

  3. Click the name of the Auxiliary EPM server.

  4. On the Change EPM Server page, navigate to the Auxiliary EPM Certificate section, and select the Trust new certificate check box if the check box is visible.

  5. Click Save.

  6. On the EPM main menu, click Real-Time Monitoring > System Monitor.

  7. If the Config of the MPP displays Restart needed, restart the MPP.