<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAS server certificate - JKS file not getting updated with server details in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-server-certificate-JKS-file-not-getting-updated-with-server/m-p/883736#M26877</link>
    <description>&lt;UL&gt;&lt;LI&gt;The Java Key story file&lt;FONT color="#000000"&gt; (trustedcerts.jks.)&lt;/FONT&gt; does not have the current server certificate details updated.&lt;/LI&gt;&lt;LI&gt;The java Key store file &lt;FONT color="#000000"&gt;(trustedcerts.jks.)&lt;/FONT&gt; just updated with current date of apply but NOT the server certificate which we have applied and we could see the previous year of apply in 2019 &amp;amp; 2021. Example as below:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Alias name: cn=xxxx,ou=xxxx,o=xxx,c=xxxx&lt;BR /&gt;&lt;FONT color="#000000"&gt;Creation date: jul 5, 2023 (This part only updated)&lt;/FONT&gt;&lt;BR /&gt;Entry type: trustedCertEntry&lt;/P&gt;&lt;P&gt;Owner: xxxx, OU=xxxx, O=xxxx, C=xxx&lt;BR /&gt;Issuer: CN=xxx, OU=xxx, O=xxx, C=xxx&lt;BR /&gt;&lt;FONT color="#000000"&gt;Valid from: Mon Oct 03 02:00:01 CEST 2016 until: Fri Oct 03 01:59:59 CEST 2036&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We have &lt;STRONG&gt;Not applied the Root &amp;amp; Intermediate certificate as it is getting expired in 2036&lt;/STRONG&gt; so we didn’t apply it and please find the high level of steps which we have followed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Created the Key &amp;amp; CSR file.&lt;/LI&gt;&lt;LI&gt;Stopped the SAS server and took the required back up.&lt;/LI&gt;&lt;LI&gt;Remove existing certificates using Deployment Manager (xxxxx-mid1.xxxx.xxx.cer)&lt;/LI&gt;&lt;LI&gt;From p7b file extracted the server certificate (xxxxx-mid1.xxxx.xxx.cer) alone and &lt;STRONG&gt;NOT the Root &amp;amp; Intermediate&lt;/STRONG&gt;.( Location : /opt/sas/SASInstallFolder/&lt;STRONG&gt;SASSecurityCertificateFramework/1.1/cacerts&lt;/STRONG&gt;/)&lt;/LI&gt;&lt;LI&gt;Adding new certificates via the Deployment Manager . update in the above location.&lt;/LI&gt;&lt;LI&gt;Verified and in the browser and also in the openssl x509 -in xxxx-mid1.xx.xx-noout -text. the &lt;FONT color="#000000"&gt;&lt;STRONG&gt;Valid from changed to 2025.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Don't know why it is not updating in the&amp;nbsp;trustedcerts.jks.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;trustedcerts.pem - it as the details of root and intermediate.&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jul 2023 14:26:54 GMT</pubDate>
    <dc:creator>MuraliKrishnan5</dc:creator>
    <dc:date>2023-07-06T14:26:54Z</dc:date>
    <item>
      <title>SAS server certificate - JKS file not getting updated with server details</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-server-certificate-JKS-file-not-getting-updated-with-server/m-p/883736#M26877</link>
      <description>&lt;UL&gt;&lt;LI&gt;The Java Key story file&lt;FONT color="#000000"&gt; (trustedcerts.jks.)&lt;/FONT&gt; does not have the current server certificate details updated.&lt;/LI&gt;&lt;LI&gt;The java Key store file &lt;FONT color="#000000"&gt;(trustedcerts.jks.)&lt;/FONT&gt; just updated with current date of apply but NOT the server certificate which we have applied and we could see the previous year of apply in 2019 &amp;amp; 2021. Example as below:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Alias name: cn=xxxx,ou=xxxx,o=xxx,c=xxxx&lt;BR /&gt;&lt;FONT color="#000000"&gt;Creation date: jul 5, 2023 (This part only updated)&lt;/FONT&gt;&lt;BR /&gt;Entry type: trustedCertEntry&lt;/P&gt;&lt;P&gt;Owner: xxxx, OU=xxxx, O=xxxx, C=xxx&lt;BR /&gt;Issuer: CN=xxx, OU=xxx, O=xxx, C=xxx&lt;BR /&gt;&lt;FONT color="#000000"&gt;Valid from: Mon Oct 03 02:00:01 CEST 2016 until: Fri Oct 03 01:59:59 CEST 2036&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We have &lt;STRONG&gt;Not applied the Root &amp;amp; Intermediate certificate as it is getting expired in 2036&lt;/STRONG&gt; so we didn’t apply it and please find the high level of steps which we have followed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Created the Key &amp;amp; CSR file.&lt;/LI&gt;&lt;LI&gt;Stopped the SAS server and took the required back up.&lt;/LI&gt;&lt;LI&gt;Remove existing certificates using Deployment Manager (xxxxx-mid1.xxxx.xxx.cer)&lt;/LI&gt;&lt;LI&gt;From p7b file extracted the server certificate (xxxxx-mid1.xxxx.xxx.cer) alone and &lt;STRONG&gt;NOT the Root &amp;amp; Intermediate&lt;/STRONG&gt;.( Location : /opt/sas/SASInstallFolder/&lt;STRONG&gt;SASSecurityCertificateFramework/1.1/cacerts&lt;/STRONG&gt;/)&lt;/LI&gt;&lt;LI&gt;Adding new certificates via the Deployment Manager . update in the above location.&lt;/LI&gt;&lt;LI&gt;Verified and in the browser and also in the openssl x509 -in xxxx-mid1.xx.xx-noout -text. the &lt;FONT color="#000000"&gt;&lt;STRONG&gt;Valid from changed to 2025.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Don't know why it is not updating in the&amp;nbsp;trustedcerts.jks.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;trustedcerts.pem - it as the details of root and intermediate.&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 14:26:54 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-server-certificate-JKS-file-not-getting-updated-with-server/m-p/883736#M26877</guid>
      <dc:creator>MuraliKrishnan5</dc:creator>
      <dc:date>2023-07-06T14:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: SAS server certificate - JKS file not getting updated with server details</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-server-certificate-JKS-file-not-getting-updated-with-server/m-p/883740#M26878</link>
      <description>If the certificate isn't self-signed, you would not need to add the server certificate to the trust store (trustedcerts.pem/jks), only it's issuing certificates (the intermediate and root), as the server certificate is provided by the server.  &lt;BR /&gt;&lt;BR /&gt;The certificate and key for the server is stored in those individual files and referenced by the SAS Web Server configuration file. There are additional steps to provide the certificate and key to Environment Manager.&lt;BR /&gt;&lt;BR /&gt;Update the Key and Certificate That Are Used by SAS Web Server&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p0fwmiy0dasb5nn18fwx1x9mn2ub.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p0fwmiy0dasb5nn18fwx1x9mn2ub.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Update Certificates for SAS Environment Manager&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1fpnnm9hxkhlzn1x5tkqs1caeg5.htm#p0noalwfbhga1sn1grrrq6tls37m" target="_blank"&gt;https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1fpnnm9hxkhlzn1x5tkqs1caeg5.htm#p0noalwfbhga1sn1grrrq6tls37m&lt;/A&gt;</description>
      <pubDate>Thu, 06 Jul 2023 14:40:05 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-server-certificate-JKS-file-not-getting-updated-with-server/m-p/883740#M26878</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2023-07-06T14:40:05Z</dc:date>
    </item>
  </channel>
</rss>

