Renew a certificate for the Security Engine

You must renew the external certificate before it expires.

Steps

  1. In the SMC Client, edit the certificate settings for each Security Engine node.
    1. Select Engine Configuration.
    2. Right-click an engine, then select Edit <element type>.
    3. Open the certificate settings in one of the following ways:
      • For single Security Engines, click Certificate Settings on the General tab of the Engine Editor.
      • For Security Engine clusters, browse to General > Clustering, right-click the Certificate cell for a node, then select Edit Certificate.
  2. In the Certificate Settings dialog box, do the following:
    1. Verify the information in the Certificate Definition Section.
    2. Click Generate Certificate Request.
  3. Browse to the location to save the certificate request and name it as you want, then click Export.
  4. Click OK to close the Certificate dialog box.
  5. Sign the certificate request using the external CA, then copy the signed certificate to a location that is accessible from your local workstation.
  6. In the SMC Client, import the signed certificate for the Security Engine.
    1. Select Engine Configuration.
    2. Right-click an Security Engine node, then select Certificate > Import Signed Certificate.
    3. Browse to the signed certificate file, then click Import.
    4. Click OK to close the Import Certificate dialog box.
    Note: Engine polls SMC for the certificate periodically. After Engine sees imported certificate from SMC, it fetches the certificate and then automatically reboots to activate the new certificate.