Renew a certificate for the Security Engine
You must renew the external certificate before it expires.
Steps
-
In the SMC Client, edit the certificate settings for each Security Engine node.
-
Select
Engine
Configuration.
- Right-click an engine, then select Edit <element type>.
-
Open the certificate settings in one of the following ways:
- For single Security Engines, click Certificate Settings on the General tab of the Engine Editor.
- For Security Engine clusters, browse to General > Clustering, right-click the Certificate cell for a node, then select Edit Certificate.
-
Select
-
In the Certificate Settings dialog box, do the following:
- Verify the information in the Certificate Definition Section.
- Click Generate Certificate Request.
- Browse to the location to save the certificate request and name it as you want, then click Export.
- Click OK to close the Certificate dialog box.
- Sign the certificate request using the external CA, then copy the signed certificate to a location that is accessible from your local workstation.
-
In the SMC Client, import the signed certificate for the Security Engine.
-
Select
Engine
Configuration.
- Right-click an Security Engine node, then select Certificate > Import Signed Certificate.
- Browse to the signed certificate file, then click Import.
- Click OK to close the Import Certificate dialog box.
Note: Engine polls SMC for the certificate periodically. After Engine sees imported certificate from SMC, it fetches the certificate and then automatically reboots to activate the new certificate. -
Select