After you acquire a new certificate, upload it to the key store. If you requested more than one certificate, upload each one separately.
To upload a new certificate
The SSL Configuration dialog displays.
Note: You only need one key and certificate pair for the SSL features because SSL does not support more than one pair.
If the CA certificate is not in the key store, import a copy of the CA certificate used to sign the SSL certificate request.
A confirmation message is displayed and the SSL Configuration changes to reflect that the certificate is now updated.
The FIPS Approved status must read True, indicating the certificate is FIPS-compatible.
Use the Federation Manager stop and start shortcuts as follows:
a. Open a command window.
b. Run the following scripts:
federation_mgr_home/fedmanager.sh stop
federation_mgr_home/fedmanager.sh start
When you run the fedmanager.sh script, it sources the Federation Manager environment script, ca_federation_env.ksh.
Note: Do not stop and start the services as the root user. You must be a non-root user.
The server certificates for SSL configuration are now FIPS-compatible.
| Copyright © 2010 CA. All rights reserved. | Email CA about this topic |