Renew a certificate for the Log Server

You must renew the external certificate before it expires. If the certificate has expired or has been revoked a new certificate request must be generated.

Steps

  1. Do one of the following:
    • If the current certificate is still valid:
      1. Start the SMC Client.
      2. Select Dashboard > Servers / Devices Dashboard.
      3. Browse to Log Server.
      4. Right-click the Log Server, then select Properties.
      5. On the Certificate tab, do the following:
        1. Verify the information in the Certificate Definition Section.
        2. Click Generate Certificate Request.
    • If the current certificate has expired or has been revoked:
      Note: This needs to be done from the command line of the SMC Appliance.
      1. Start the SMC Client.
      2. Stop the Log Server.
        Enter the following command:
        sudo daemon-ctl stop sgLogServer
      3. Generate a new CSR for the Log Server.
        Enter the following command:
        sudo /usr/local/forcepoint/smc/bin/sgCertifyLogSrv.sh -reinit
      4. Enter the credentials for an administrator account with unrestricted permissions (superuser). When the certification has finished, a certificate request is created for the Log Server.
  2. In the SMC Client, export the certificate request.
    1. Select Dashboard > Servers / Devices Dashboard.
    2. Browse to Log Server.
    3. Right-click the Log Server, then select Properties.
    4. On the Certificate tab, click Export Certificate Request, browse to the location where you want to save the certificate request, then click Save.
      Save the certificate request in a location that is accessible from your local workstation.
    5. Click OK to close the Export Certificate dialog box.
    6. Click OK to close the Log Server Properties dialog box.
  3. Sign the certificate request using the external CA, then copy the signed certificate to a location that is accessible from your local workstation.
  4. In the SMC Client, import the signed certificate for the Log Server.
    1. Select Dashboard > Servers / Devices Dashboard.
    2. Browse to Log Server.
    3. Right-click the Log Server, then select Properties.
    4. On the Certificate tab, click Import Signed Certificate.
    5. Browse to the signed certificate file, then click OK.
    6. Click OK to close the Log Server Properties dialog box.
  5. On the command line of the SMC Appliance, transfer the signed certificate to the Log Server.
    1. Enter the sgCertifyLogSrv command:
      sudo /usr/local/forcepoint/smc/bin/sgCertifyLogSrv.sh
    2. Enter the credentials for an administrator account with unrestricted permissions (superuser).
  6. Start the Log Server.
    Enter the following command on SMC Appliance:
    sudo daemon-ctl restart sgLogServer

Example

Table 1. Log Server Properties dialog box - Certificate tab
Option Definition
Current Certificate Shows information about the current certificate of the server.

Click Export Certificate to export the current certificate. Click Renew Certificate to renew the certificate.

Check Revocation Checks against certificate revocation lists (CRLs or OCSP) whether the certificate of the new connection has been revoked. The certificate must be signed by a valid certificate authority.
Ignore Revocation Check Failures if There Are Connectivity Problems When selected, the server ignores all CRL check failures if the server cannot connect to CRL or OCSP server. This is done based on what is specified in the certificate.
Organization (O)

(Optional)

The name of your organization as it appears in the certificate.
Organization Unit (OU)

(Optional)

The name of your department or division as it appears in the certificate.
State/Province (ST)

(Optional)

The name of state or province as it appears in the certificate.
Locality (L)

(Optional)

The name of the city as it appears in the certificate.
Common Name (CN) A common name that includes the name of the Log Server element.
Public Key Algorithm

(Not editable)

The algorithm used for the public key.
Note: For Log Server certificates, only the ECDSA public key algorithm is supported.
Key Length The length of the key in bits.

Select 384.

Note: Key-size parameter of 521 bits is also acceptable if the configuration is not intended to be compatible with Commercial Solutions for Classified configuration.
Signature Algorithm

(Not editable)

Shows the signature algorithm according to the key length.
Subject Alternative Name (DNS) Name of the Log Server as a fully qualified domain name (FQDN).
Generate Certificate Request Shows the certificate request as text.
Export Certificate Exports the certificate request so that you can sign it using an external certificate authority.
Import Signed Certificate Imports a certificate that has been signed using an external certificate authority.

Next steps

Create Security Engine elements, then create certificates for the Security Engines.