Previous Topic: Request an SSL Server Certificate

Next Topic: Deactivate SSL

Upload the Signed Server Certificate

After you complete a certificate request, the SSL Configuration Status field reads Server cert requested, not signed, indicating that the certificate request is waiting to be signed. Federation Manager accepts a base-64 encoded PEM certificate or a full PKCS #7 certificate/chain response.

After you receive the signed certificate from the CA, the certificate must be uploaded to the storage location.

Note: You can click Help for a description of fields, controls, and their respective requirements.

To upload the signed server certificate

  1. Begin at the same SSL Configuration where you started the request.
  2. Select the signed certificate response in the Signed Certificate Response field. Click Browse to locate the file.

    Note: Only one key and certificate pair is needed for the SSL features because SSL does not support more than one pair.

  3. Identify the CA that signed the SSL certificate from the pull-down menu in the CA Certificate field.

    If the CA certificate is not in the key store, import a copy of the CA certificate used to sign the SSL certificate request. Import the certificate by clicking Import and completing the import steps.

  4. Click Apply to upload the server certificate to Federation Manager.

    A confirmation message is displayed and the SSL Configuration changes to reflect that the certificate is now updated.

  5. Restart the Federation Manager services, according to your operating environment.

After the server certificate is uploaded to the system, Federation Manager updates the certificate and activates SSL. Assuming that the certificate upload was successful, the SSL Configuration Status reads SSL Active. The button in the configuration group box changes to Deactivate.

The UI also indicates whether the uploaded certificate is FIPS-approved or not.


Copyright © 2010 CA. All rights reserved. Email CA about this topic