Print

Uploading a Signed Certificate

About this task

Use this page to upload an external CA issued EP Signing Certificate if a CSR was generated on Experience Portal through the Certificate Signing Request tab and provided to the external CA. The uploaded certificate file must include the complete chain of certificates in PEM format. These include the public certificates of all external CA’s involved in the signing process (Intermediate and Root CA’s) and the EP Signing Certificate that was signed by the external CA. The external CA uses the certificate signing request generated from the EPM to generate the EP Signing Certificate.

Uploading a new EP Signing Certificate will force all Experience Portal servers to replace their current identity certificate with a new identity certificate signed by the new externally signed EP Signing Certificate. This will happen on the next restart of the Experience Portal servers’ services.

importantImportant:

After uploading a new EP Signing Certificate, restart the Experience Portal servers. On the EPM web interface, go to System Management > EPM Manager or MPP Manager, and restart the servers in the following order:

  1. MPP servers

  2. Auxiliary EPM servers

  3. Primary EPM servers

noteNote:

Do not upload the EP Signing Certificate multiple times without restarting all the Experience Portal servers. This will potentially cause loss of communications between the Experience Portal servers. In case this happens, do the following to regain communication between the servers:

  • Reconnect all MPP servers with the EPM server

  • Reconnect the primary and auxiliary EPM servers

  • Restart the Primary EPM.

For more information, see Reconnecting an existing MPP server with the EPM server and Reconnecting the primary and auxiliary EPM servers.

Procedure

  1. Log on to the EPM web interface.
  2. On the EPM navigation pane, click Security > Certificates.
  3. Click the EP Signing Certificate tab.
  4. Click the Certificate Signing Request tab.
  5. Click Upload to upload a new EP Signing Certificate.
  6. On the Upload Signed Certificate page, click Choose File, and select the certificate file in the dialog box.
  7. Click Continue.
  8. Click Save.