Previous Topic: Upload the Signed Server CertificateNext Topic: Reactivate SSL


Deactivate SSL

You can deactivate the SSL configuration if you no longer require SSL. For example, if back channel authentication is no longer required or you no longer want an SSL connection to the UI you can deactivate SSL.

Note: If you reconfigure a Windows system with SSL enabled, deactivate the SSL configuration before reconfiguring your system. Reactivate SSL after the reconfiguration is complete.

Follow these steps:

  1. Begin at the SSL Configuration dialog.
  2. Click Deactivate in the Embedded web server or Administrative UI section.

    A confirmation prompt is displayed asking if you want to disable SSL.

  3. Click Yes to complete the deactivation.
  4. For the Administrative UI only, delete the tomcat.keystore file manually. This file is located in the following directory:

    federation_install_dir/secure-proxy/SSL/keys

    Deactivating SSL for the Administrative UI does not delete the corresponding key store file. If you change the UI SSL certificate for any reason, the certificate is not updated, which results in CA SiteMinder® Federation Standalone using the wrong certificate. Deleting the Tomcat key store helps ensure that any updates you make to the SSL certificate are reflected.

  5. Restart the federation services according to your operating environment.

The SSL connection is no longer active and the SSL Configuration Status setting changes to Server cert signed by CA, SSL ready. The certificate and key files remain so you can re-enable SSL.