07-28-2021 07:19 AM
Hi All,
Could anyone please help me re-generating the WSM self-signed certificate on CVP call server.
After an upgrade I found out that the Name of the server is incorrect in one of the previous certificates so I need to correct that.
Please suggest how can I perform this or is it possible to edit server name in pre existing WSM certificate.
Many Thanks
Shreyash Dadheech
07-28-2021 10:25 AM - edited 08-12-2021 11:26 AM
Hi,
Yes, we can delete and recreate. please use the below link and commands. before the start for CVP Standalone & UCCE setup please update CVP Call/VXML/Reporting servers Host name to FQDN in OAMP page and save and deploy.
=======================================================================================================
Open a command window as Administrator to run the commands. To view certificate list cmd
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -list
=======================================================================================================
Step 1. To delete the CVP OAMP, CVP CALL VXML & Reporting servers old self-signed certificates run these commands ||
=======================================================================================================
===========================
CVP OAMP (UCCE deployment)||
===========================
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -delete -alias wsm_certificate
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -delete -alias oamp_certificate
==========================
CVP CALL & VXML Server ||
==========================
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -delete -alias wsm_certificate
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -delete -alias vxml_certificate
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -delete -alias callserver_certificate
=======================
CVP Reporting servers ||
=======================
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -delete -alias wsm_certificate
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -delete -alias callserver_certificate
=================================================================================
(ii) Generate the new self-signed certificates with the FQDN of the CVP servers ||
=================================================================================
===========================
CVP OAMP (UCCE deployment)||
===========================
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -genkeypair -alias wsm_certificate -keysize 2048 -keyalg RSA -validity 1895
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -genkeypair -alias oamp_certificate -keysize 2048 -keyalg RSA -validity 1895
Reboot the CVP OAMP server.
==========================
CVP CALL & VXML Server ||
==========================
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -genkeypair -alias wsm_certificate -keysize 2048 -keyalg RSA -validity 1895
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -genkeypair -alias vxml_certificate -keysize 2048 -keyalg RSA -validity 1895
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -genkeypair -alias callserver_certificate -keysize 2048 -keyalg RSA -validity 1895
Reboot the CVP call server.
=======================
CVP Reporting servers ||
=======================
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -genkeypair -alias wsm_certificate -keysize 2048 -keyalg RSA -validity 1895
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -genkeypair -alias callserver_certificate -keysize 2048 -keyalg RSA -validity 1895
Reboot the Reporting servers.
=============================================================
(iii) Export wsm_Certificate from CVP and Reporting servers ||
=============================================================
Command to export the self-signed certificates:
Step 1. Export WSM certificate from CVP Server, Reporting and OAMP server.
===========================================================================
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -export -alias wsm_certificate -file %CVP_HOME%\conf\security\wsm_HCVP01.crt
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -export -alias wsm_certificate -file %CVP_HOME%\conf\security\wsm_HCVP02.crt
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -export -alias wsm_certificate -file %CVP_HOME%\conf\security\wsm_HCVPREP.crt
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -export -alias wsm_certificate -file %CVP_HOME%\conf\security\wsm_HCVPOPS.crt
C:\Cisco\CVP\conf\security\wsm.crt from each server and rename it as wsmX.crt depending on the server type.
Step 2. Import WSM certificates from CVP Server and Reporting server into OAMP server.
======================================================================================
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -import -alias HCVP01.lab.local_wsm -file c:\cisco\cvp\conf\security\wsm_HCVP01.crt
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -import -alias HCVP02.lab.local_wsm -file c:\cisco\cvp\conf\security\wsm_HCVP02.crt
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -import -alias HCVPREP.lab.local_wsm -file c:\cisco\cvp\conf\security\wsm_HCVPREP.crt
Reboot the servers
Step 3. Import CVP OAMP server WSM certificate into CVP Server and Reporting servers.
=====================================================================================
%CVP_HOME%\jre\bin\keytool.exe -storetype JCEKS -keystore %CVP_HOME%\conf\security\.keystore -import -alias HCVPOPS.lab.local_wsm -file c:\cisco\cvp\conf\security\wsm_HCVPOPS.crt
Reboot the servers
Ram.S
08-12-2021 09:13 AM
Hi Ram,
Thanks for the response.
Shreyash
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide