Print

Uploading the EP Signing Certificate

About this task

Use this page to upload an external CA issued EP Signing Certificate if the external CA generated the CSR and private key. However, it is not recommended to make this a frequent operation.

When uploading a new EP Signing Certificate, the EP Signing Certificate must be issued by an external Certificate Authority. The uploaded EP Signing Certificate must have Basic Constraints with a CA value set to true.

Uploading a new EP Signing Certificate will force all Experience Portal servers to replace their current identity certificate with a new identity certificate signed by the new externally signed EP Signing Certificate. This will happen on the next restart of the Experience Portal servers’ services.

importantImportant:

After uploading a new EP Signing Certificate, restart the Experience Portal servers. On the EPM web interface, go to System Management > EPM Manager or MPP Manager, and restart the servers in the following order:

  1. MPP servers

  2. Auxiliary EPM servers

  3. Primary EPM servers

noteNote:

Do not upload the EP Signing Certificate multiple times without restarting all the Experience Portal servers. This will potentially cause loss of communications between the Experience Portal servers. In case this happens, do the following to regain communication between the servers:

  • Reconnect all MPP servers with the EPM server

  • Reconnect the primary and auxiliary EPM servers

  • Restart the Primary EPM.

For more information, see Reconnecting an existing MPP server with the EPM server and Reconnecting the primary and auxiliary EPM servers.

noteNote:

If you are importing an EP Signing Certificate signed by an external Certificate Authority, ensure the following:

  • The certificate must be formatted as a PKCS#12 file. A PKCS#12 file always includes a certificate and its corresponding key. The certificate is encrypted and requires a password. The PKCS#12 file must include all CA certificates.

  • The EP Signing certificate must include the standard extension Basic Constraints with the CA:true attribute. This allows the EP Signing Certificate to issue and sign identity certificates.

  • If the Extended Key Usage is specified in the X509.V3 certificate extension, specify Server Authentication (serverAuth), and Client Authentication (clientAuth) for the usage.

Procedure

  1. Log on to the EPM web interface.
  2. On the EPM navigation pane, click Security > Certificates.
  3. Click the EP Signing Certificate tab.
  4. Click the Certificate tab.
  5. Click Upload to upload a new EP Signing Certificate.
  6. On the Upload EP Signing Certificate page, click Choose File, and select the certificate file in the dialog box.
  7. In the Password field, enter the password for the PKCS#12 file
  8. Click Install.