Renew a certificate for the Management Server

You must renew the external certificate before it expires.

Steps

  1. Log in to the console with the user account created during the installation.
  2. Stop the Management Server.
    Enter the following command to stop the Management Server:
    sudo daemon-ctl stop sgMgtServer
     
  3. Create a new certificate request.
    Enter the following command to create a new certificate request:
    sudo /usr/local/forcepoint/smc/bin/sgCertifyMgtSrv.sh -reinit mode=ext-pki-init key-size=384 dn="CN=MyMgmt,
    C=US,OU=MyCompany" dns="my-mgmt" csr-out=/tmp/mgmt.csr
    Note: Key-size parameter of 521 bits is also acceptable if the configuration is not intended to be compatible with Commercial Solutions for Classified configuration.
    Important:
    • Replace the 'dn' field value with an appropriate descriptive distinguished name for your environment.
    • Replace the 'dns' field value with a suitable and unique domain name that identifies the management server in your environment.
    • The CSfC compatible configuration can be disabled by generating a new Management Server certificate with a key size parameter of 521. The new configuration will then be compatible with CC instead.
  4. Export the generated CSR using scp.
    Enter the following command:
    scp /tmp/mgmt.csr <user>@<host>:<path>
     
  5. Sign the CSR externally and import the certificates using scp. Any intermediate certificates must be bundled into the same file with the signed leaf certificate.
    Enter the following command:
    scp <user>@<host>:<path>/mgmt.cert.pem /tmp/
    chmod a+r /tmp/mgmt.cert.pem
    scp <user>@<host>:<path>/ca.cert.pem /tmp/
    chmod a+r /tmp/ca.cert.pem
    sudo /usr/local/forcepoint/smc/bin/sgCertifyMgtSrv.sh mode=ext-pki-import crt-in=/
    tmp/mgmt.cert.pem ca-file=/tmp/ca.cert.pem
     
  6. Start the Management Server.
    Enter the following command:
    sudo daemon-ctl restart sgMgtServer

Next steps

Install the SMC Client, and then create a certificate for the Log Server.
Important:
  • Installing the SMC Client is optional. You can access SMC by using SMC Web Access or by installing the SMC Client to a separate host. By default, the SMC Web Access is enabled when the management server starts.
  • The SMC Client can be accessed using a web browser on https port 8085 on the SMC Appliance. For example, if the SMC Appliance is configured with the IP address 192.0.2.1, the SMC Client can be accessed using the URL https://192.0.2.1:8085/ in a web browser.