SSL certificate installation - part 2

SSL certificate installation - part 2

Problem:  Need to create and add new wildcard SSL certificate to Unified Workspace server.


Prerequisite(s):
  • Completed part 1
  • Access to keystore password

Solution(s):  Below instructions will walk you through process of placing a new keystore on Unified Workspace servers.

Configuring new keystore file:
  1. Copy wildcard.jks file in stoneware\config directory
  2. Repeat for all Unified Workspace servers
  3. Go to webAdmin
  4. Go to Relay Admin
  5. Click on first relay object
  6. Enable SSL (if not already enabled)
  7. Change certificate source to wildcard.jks
  8. Click Save button
  9. Repeat steps 5-8 for each additional relay objects

Entering new keystore password*:
  1. Go to Server Administrator console for any dedicated relays (https://127.0.0.1:8090)
  2. Go to Services tab
  3. Right-click on relay service
  4. Click Properties
  5. Change Relay User password to keystore password 
    IMPORTANT - must be same password as used in part 1
  6. Click Save button
  7. Go Settings
  8. Shutdown service
  9. Repeat steps 1-8 for any additional relays
  10. Repeat steps 1-8 for any servers+relays
  11. Go to your directory server tools (AD/eDir/OpenLDAP/AD LDS)
  12. Find relayuser account (default location is stoneware OU)
  13. Reset the relayuser password to match the keystore password
    IMPORTANT - must be same password as used in part 1
  14. Configure relayuser account so password does not expire
  15. Start-up a server+relay
  16. Verify service has started up successfully
  17. Startup additional severs+relays
  18. Start-up additional dedicated relays
*If you have the current relayuser password documented, you can skip changing it in the directory and instead change keystore's and the keystore's keypair passwords to match what is already set in the directory.

Typically if you get any start-up error messages it's because the passwords have not been matched up correctly.  Highly recommended to copy-n-paste with a complicated password.


Reference(s):
SSL certificate installation - part 1



keywords: 
keystore, SSL, java