Renew external certificate for the Log Server
You must renew the external certificates for the Log server manually before it expires.
Before you begin
- You must have the external Certificate Authority (CA) configured.Note: This is the certificate authority that is used to sign certificate requests.
- The Log Server must be running before generating the new Certificate Signing Request (CSR).
Steps
-
Select
Dashboard > Servers / Devices Dashboard.
- Browser to Log Server.
-
Generate the certificate request by using one of the following ways:
- From the context menu of the Log Server.
- Right-click the Log Server, then select Certificate > Renew Certificate.
- Click the Yes button, and then click the OK button. The certificate request is generated.
- From the Log Server properties dialog-box:Note: Use this option if the existing settings in the Certificate Definition section need to be updated.
- Right-click the Log Server, then select Properties.
- Click the Certificate tab.
- Click the Renew Certificate button.
- Configure the settings in the Certificate Definition section.
- Click the Generate Certificate Request button, and then click the Yes button.
- Click the OK button. The Certificate Request section is displayed.
- From the context menu of the Log Server.
-
Export the generated certificate request by using one of the following ways:
- From the Log Server properties dialog-box:
- Right-click the Log Server, then select Properties.
- Click the Certificate tab.
- In the Certificate Request section, click the Export Certificate Request button.
- Navigate to the desired location and click the Export button, and then click the OK button.
- From the context menu of the Log Server:
- Right-click the Log Server, then select Certificate > Export Certificate Request.
- Navigate to the desired location and click the Export button, and then click the OK button.
- From the Log Server properties dialog-box:
- Sign the exported certificate request by using the external Certificate Authority (CA).
-
Import the signed certificate by using one of the following ways:
- From the Log Servers properties dialog-box:
- Right-click the Log Server, then select Properties.
- Click the Certificate tab.
- In the Certificate Request section, click the Import Signed Certificate button.
- Select one of the following options:
- The From File option:
- Select the From File radio button, and then click the Browse button.
- Navigate the location where the signed certificate is saved.
- Select the signed certificate file, and then click the Import button.
- Click the OK button.
- The As Text option:
- Select the As Text radio button.
- Paste the certificate details.
- Click the OK button.
- The From File option:
- From the context menu of the Log Server:
- Right-click the Log, then select Certificate > Import Certificate.
- Select one of the following options:
- The From File option:
- Select the From File radio button, and then click the Browse button.
- Navigate to the location where the signed certificate is saved.
- Select the signed certificate file, and then click the Import button.
- Click the OK button.
- The As Text option:
- Select the As Text radio button.
- Paste the certificate details.
- Click the OK button.
- The From File option:
- From the Log Servers properties dialog-box:
- Stop the Log Server.
-
Execute the following script:
sgCertifyLogSrv
- Restart the Log Server.
- Verify the expiration date of the renewed certificate. For more details, refer to the Check the expiration date of the certificate topic.