<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Certificates: Replacing CloudCenter's default component X.509 certificates in Data Center and Cloud Knowledge Base</title>
    <link>https://community.cisco.com/t5/data-center-and-cloud-knowledge-base/certificates-replacing-cloudcenter-s-default-component-x-509/ta-p/3640861</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Since the v4.2 release of CloudCenter (CC), the CC platform has adopted Spring X.509 Authentication, which requires the various roles of the CC architecture to communicate via mutual SSL authentication methods. These certificates are component-based and are different than the client-based certificate described in this &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-72336"&gt;article&lt;/A&gt;. For a summarized explanation of the differences between the two types and instructions to obtain custom certificates to use for SSL authentication, refer to this &lt;A href="http://docs.cliqr.com/display/CCD46/Certificate+Authentication"&gt;article&lt;/A&gt;. During the communication between the CloudCenter Manager, the Orchestrator, the Guacamole server, etc., the CloudCenter appliances request a valid certificate from each other as part of the SSL handshake. Once the certificate is offered it will be verified to ensure that it has been signed by a trusted authority. Each CloudCenter deployment needs a unique CloudCenter ID (CCID). The CloudCenter support team uses a known private Certificate Authority (CA) to generate the default certificates, which contain the values for the CCID; it can also be used to generate custom certificates for your deployments upon request. There is an option to request Certificate Signing Request (CSR) files from the CloudCenter support team so that your private CA can generate custom certificates. These component certificates (*.crt) files are stored on each appliance in the /usr/local/tomcat/conf/ssl directory and are specifically named mgmtserver.crt (CCM), cco.crt (CCO), gateway.crt (Docker container), monitor.crt (Health Monitor), guac.crt (Guacamole), and esb.crt (ESB). The goal of this document is to demonstrate how custom certificates can be used in place of the default certificates employed by the CC platform.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE&lt;/SPAN&gt;: Assuming that you have a valid certificate signed by a trusted authority, either private or public, you can use one certificate and rename it appropriately to befit to the server role. So a custom.crt file can be renamed to mgmtserver.crt file and placed onto the CCM appliance.&amp;nbsp; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;Placing the certificates&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;On the CloudCenter Manager (CCM)&lt;BR /&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, &lt;EM&gt;ccm_keystore.jks&lt;/EM&gt;, &lt;EM&gt;ccm.crt&lt;/EM&gt;, and &lt;EM&gt;ccm.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/ccm&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, esb&lt;EM&gt;_keystore.jks&lt;/EM&gt;, esb&lt;EM&gt;.crt&lt;/EM&gt;, and esb&lt;EM&gt;.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/esb&lt;/EM&gt; directory (if ESB is enabled)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Place the &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, esb&lt;EM&gt;_keystore.jks&lt;/EM&gt;, esb&lt;EM&gt;.crt&lt;/EM&gt;, and esb&lt;EM&gt;.key&lt;/EM&gt; files into the &lt;EM&gt;/etc/rabbitmq/certs&lt;/EM&gt; directory (if ESB is enabled)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Ensure that the files are owned by the user named &lt;EM&gt;cliqruser&lt;/EM&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;chown -R /usr/local/osmosix/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Remove existing and add new symbolic links&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;cd /usr/local/tomcat/conf/ssl&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f .keystore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f .truststore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f gateway.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f gateway.key&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f ca.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco_keystore.jks .keystore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/ca_truststore.jks .truststore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco.crt gateway.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco.key gateway.key&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/ca_root.crt ca.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Optional steps to verify the certificates in the keystore (assuming the working directory of &lt;EM&gt;/usr/local/osmosix/ssl/ccm&lt;/EM&gt;)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;To view the certificate in detail&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;keytool -printcert -v -file ccm.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;To verify that the certificate is in the truststore (this requires a call to support as they will provide the passphrase for the store)&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12pt; font-style: italic; font-family: verdana,geneva; font-weight: bold;"&gt;keytool -list -v -keystore ccm_keystore.jks&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;To verify that the certificate is in the truststore (this requires a call to support as they will provide the passphrase for the store)&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12pt; font-style: italic; font-family: verdana,geneva; font-weight: bold;"&gt;keytool -list -v -keystore ca_truststore.jks&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;To import a certificate into the keystore&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="font-weight: bold; font-style: italic; color: #333333;"&gt;keytool -import -alias sandbox -keystore ccm_keystore.jks -file ccm.crt&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;SPAN style="font-weight: bold; font-style: italic; color: #333333;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="color: #333333; font-size: 12pt; font-family: verdana,geneva;"&gt;On the CloudCenter Orchestrator (CCO)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12pt; font-family: verdana,geneva;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, &lt;EM&gt;cco_keystore.jks&lt;/EM&gt;, &lt;EM&gt;cco.crt&lt;/EM&gt;, and &lt;EM&gt;cco.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/cco&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default gateway&lt;EM&gt;.crt&lt;/EM&gt;, and gateway&lt;EM&gt;.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/docker&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Ensure that the files are owned by the user named &lt;EM&gt;cliqruser&lt;/EM&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12pt; font-style: italic; font-family: verdana,geneva; font-weight: bold;"&gt;chown -R /usr/local/osmosix/ssl&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Remove existing and add new symbolic links&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;cd /usr/local/tomcat/conf/ssl&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f .keystore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f .truststore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f gateway.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f gateway.key&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f ca.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco_keystore.jks .keystore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/ca_truststore.jks .truststore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco.crt gateway.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco.key gateway.key&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/ca_root.crt ca.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;On the CloudCenter Guacamole appliance (Guac)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, &lt;EM&gt;gua_keystore.jks&lt;/EM&gt;, &lt;EM&gt;gua.crt&lt;/EM&gt;, and &lt;EM&gt;gua.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/gua&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Ensure that the files are owned by the user named &lt;EM&gt;cliqruser&lt;/EM&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;chown -R /usr/local/osmosix/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Remove existing and add new symbolic links&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;&lt;STRONG&gt;cd /usr/local/tomcatgua/conf/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f .keystore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f .truststore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f gateway.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f gateway.key&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f ca.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/gua_keystore.jks .keystore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/ca_truststore.jks .truststore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/gua.crt gateway.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/gua.key gateway.key&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/ca_root.crt ca.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;On the CloudCenter Health Monitor (Health Monitor)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, &lt;EM&gt;mon_keystore.jks&lt;/EM&gt;, &lt;EM&gt;mon&lt;/EM&gt;&lt;EM&gt;.crt&lt;/EM&gt;, and &lt;SPAN style="font-style: italic;"&gt;mon&lt;/SPAN&gt;&lt;EM&gt;.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/mon&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Ensure that the files are owned by the user named &lt;EM&gt;cliqruser&lt;/EM&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;chown -R /usr/local/osmosix/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Remove existing and add new symbolic links&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;&lt;STRONG&gt;cd /usr/local/tomcat/conf/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f .keystore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f .truststore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f monitor.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f monitor.key&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f ca.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/mon/mon_keystore.jks .keystore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/mon/ca_truststore.jks .truststore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/mon/mon.crt monitor.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/mon/mon.key monitor.key&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG style=": ; font-size: 12pt; font-family: verdana,geneva;"&gt;ln -s /usr/local/osmosix/ssl/mon/ca_root.crt ca.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Apr 2017 14:27:27 GMT</pubDate>
    <dc:creator>tuanngu4</dc:creator>
    <dc:date>2017-04-12T14:27:27Z</dc:date>
    <item>
      <title>Certificates: Replacing CloudCenter's default component X.509 certificates</title>
      <link>https://community.cisco.com/t5/data-center-and-cloud-knowledge-base/certificates-replacing-cloudcenter-s-default-component-x-509/ta-p/3640861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Since the v4.2 release of CloudCenter (CC), the CC platform has adopted Spring X.509 Authentication, which requires the various roles of the CC architecture to communicate via mutual SSL authentication methods. These certificates are component-based and are different than the client-based certificate described in this &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-72336"&gt;article&lt;/A&gt;. For a summarized explanation of the differences between the two types and instructions to obtain custom certificates to use for SSL authentication, refer to this &lt;A href="http://docs.cliqr.com/display/CCD46/Certificate+Authentication"&gt;article&lt;/A&gt;. During the communication between the CloudCenter Manager, the Orchestrator, the Guacamole server, etc., the CloudCenter appliances request a valid certificate from each other as part of the SSL handshake. Once the certificate is offered it will be verified to ensure that it has been signed by a trusted authority. Each CloudCenter deployment needs a unique CloudCenter ID (CCID). The CloudCenter support team uses a known private Certificate Authority (CA) to generate the default certificates, which contain the values for the CCID; it can also be used to generate custom certificates for your deployments upon request. There is an option to request Certificate Signing Request (CSR) files from the CloudCenter support team so that your private CA can generate custom certificates. These component certificates (*.crt) files are stored on each appliance in the /usr/local/tomcat/conf/ssl directory and are specifically named mgmtserver.crt (CCM), cco.crt (CCO), gateway.crt (Docker container), monitor.crt (Health Monitor), guac.crt (Guacamole), and esb.crt (ESB). The goal of this document is to demonstrate how custom certificates can be used in place of the default certificates employed by the CC platform.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE&lt;/SPAN&gt;: Assuming that you have a valid certificate signed by a trusted authority, either private or public, you can use one certificate and rename it appropriately to befit to the server role. So a custom.crt file can be renamed to mgmtserver.crt file and placed onto the CCM appliance.&amp;nbsp; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;Placing the certificates&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;On the CloudCenter Manager (CCM)&lt;BR /&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, &lt;EM&gt;ccm_keystore.jks&lt;/EM&gt;, &lt;EM&gt;ccm.crt&lt;/EM&gt;, and &lt;EM&gt;ccm.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/ccm&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, esb&lt;EM&gt;_keystore.jks&lt;/EM&gt;, esb&lt;EM&gt;.crt&lt;/EM&gt;, and esb&lt;EM&gt;.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/esb&lt;/EM&gt; directory (if ESB is enabled)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Place the &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, esb&lt;EM&gt;_keystore.jks&lt;/EM&gt;, esb&lt;EM&gt;.crt&lt;/EM&gt;, and esb&lt;EM&gt;.key&lt;/EM&gt; files into the &lt;EM&gt;/etc/rabbitmq/certs&lt;/EM&gt; directory (if ESB is enabled)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Ensure that the files are owned by the user named &lt;EM&gt;cliqruser&lt;/EM&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;chown -R /usr/local/osmosix/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Remove existing and add new symbolic links&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;cd /usr/local/tomcat/conf/ssl&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f .keystore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f .truststore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f gateway.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f gateway.key&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f ca.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco_keystore.jks .keystore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/ca_truststore.jks .truststore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco.crt gateway.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco.key gateway.key&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/ca_root.crt ca.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Optional steps to verify the certificates in the keystore (assuming the working directory of &lt;EM&gt;/usr/local/osmosix/ssl/ccm&lt;/EM&gt;)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;To view the certificate in detail&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;keytool -printcert -v -file ccm.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;To verify that the certificate is in the truststore (this requires a call to support as they will provide the passphrase for the store)&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12pt; font-style: italic; font-family: verdana,geneva; font-weight: bold;"&gt;keytool -list -v -keystore ccm_keystore.jks&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;To verify that the certificate is in the truststore (this requires a call to support as they will provide the passphrase for the store)&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12pt; font-style: italic; font-family: verdana,geneva; font-weight: bold;"&gt;keytool -list -v -keystore ca_truststore.jks&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;To import a certificate into the keystore&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="font-weight: bold; font-style: italic; color: #333333;"&gt;keytool -import -alias sandbox -keystore ccm_keystore.jks -file ccm.crt&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;SPAN style="font-weight: bold; font-style: italic; color: #333333;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="color: #333333; font-size: 12pt; font-family: verdana,geneva;"&gt;On the CloudCenter Orchestrator (CCO)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12pt; font-family: verdana,geneva;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, &lt;EM&gt;cco_keystore.jks&lt;/EM&gt;, &lt;EM&gt;cco.crt&lt;/EM&gt;, and &lt;EM&gt;cco.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/cco&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default gateway&lt;EM&gt;.crt&lt;/EM&gt;, and gateway&lt;EM&gt;.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/docker&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Ensure that the files are owned by the user named &lt;EM&gt;cliqruser&lt;/EM&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12pt; font-style: italic; font-family: verdana,geneva; font-weight: bold;"&gt;chown -R /usr/local/osmosix/ssl&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Remove existing and add new symbolic links&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;cd /usr/local/tomcat/conf/ssl&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f .keystore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f .truststore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f gateway.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f gateway.key&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;rm -f ca.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco_keystore.jks .keystore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/ca_truststore.jks .truststore&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco.crt gateway.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/cco.key gateway.key&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;ln -s /usr/local/osmosix/ssl/cco/ca_root.crt ca.crt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;On the CloudCenter Guacamole appliance (Guac)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, &lt;EM&gt;gua_keystore.jks&lt;/EM&gt;, &lt;EM&gt;gua.crt&lt;/EM&gt;, and &lt;EM&gt;gua.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/gua&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Ensure that the files are owned by the user named &lt;EM&gt;cliqruser&lt;/EM&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;chown -R /usr/local/osmosix/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Remove existing and add new symbolic links&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;&lt;STRONG&gt;cd /usr/local/tomcatgua/conf/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f .keystore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f .truststore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f gateway.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f gateway.key&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f ca.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/gua_keystore.jks .keystore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/ca_truststore.jks .truststore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/gua.crt gateway.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/gua.key gateway.key&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/gua/ca_root.crt ca.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;On the CloudCenter Health Monitor (Health Monitor)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Replace the default &lt;EM&gt;ca_root.crt&lt;/EM&gt;, &lt;EM&gt;ca_truststore.jks&lt;/EM&gt;, &lt;EM&gt;mon_keystore.jks&lt;/EM&gt;, &lt;EM&gt;mon&lt;/EM&gt;&lt;EM&gt;.crt&lt;/EM&gt;, and &lt;SPAN style="font-style: italic;"&gt;mon&lt;/SPAN&gt;&lt;EM&gt;.key&lt;/EM&gt; files in the &lt;EM&gt;/usr/local/osmosix/ssl/mon&lt;/EM&gt; directory&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Ensure that the files are owned by the user named &lt;EM&gt;cliqruser&lt;/EM&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;chown -R /usr/local/osmosix/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;Remove existing and add new symbolic links&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;&lt;STRONG&gt;cd /usr/local/tomcat/conf/ssl&lt;/STRONG&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f .keystore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f .truststore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f monitor.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f monitor.key&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;rm -f ca.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/mon/mon_keystore.jks .keystore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/mon/ca_truststore.jks .truststore&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/mon/mon.crt monitor.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;ln -s /usr/local/osmosix/ssl/mon/mon.key monitor.key&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: verdana,geneva; font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG style=": ; font-size: 12pt; font-family: verdana,geneva;"&gt;ln -s /usr/local/osmosix/ssl/mon/ca_root.crt ca.crt&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Apr 2017 14:27:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/data-center-and-cloud-knowledge-base/certificates-replacing-cloudcenter-s-default-component-x-509/ta-p/3640861</guid>
      <dc:creator>tuanngu4</dc:creator>
      <dc:date>2017-04-12T14:27:27Z</dc:date>
    </item>
  </channel>
</rss>

