Previous Topic: Re-encrypt the Super User Password

Next Topic: Re-encrypt the Policy Store and Key Store Data

Re-encrypt the Proxy Engine Agent Shared Secret

To migrate, re-encrypt the shared secret for the proxy engine Web Agent.

To re-encrypt shared secrets

  1. Open a command prompt window.
  2. Navigate to the SmHost.conf file, located at federation-mgr_home\secure-proxy\proxy-engine\conf\defaultagent\SmHost.conf.
  3. Enter the following command, using the values in the SmHost.conf file for some of the settings.

    smreghost -i policy_server_ip_address,port,port,port -u admin_user_name -p admini_password -hn host_name -hc host_config_object -f host_config_file_path -o -cf MIGRATE

    Example

    smreghost -i localhost -u siteminder -p mypassword
    -hn lfed-localhost20090511024942 -hc fed-localhost20090511024942
    -f "C:\Program Files\CA\FederationManager\secure-proxy\proxy-engine
    \conf\defaultagent\SmHost.conf" -o –cf  MIGRATE
    

    After executing this command, the re-encryption of the shared secret is complete.

  4. Navigate to the SmHost.conf file, located at the following directory:
    federation-mgr_home\secure-proxy\proxy-engine\
    conf\defaultagent\SmHost.conf
    
  5. Open the SmHost.conf file and verify that the shared secret is present and has a FIPS-approved algorithm prefix, such as {AES}.

Re-encryption of the shared secret is complete.


Copyright © 2010 CA. All rights reserved. Email CA about this topic