BookmarkSubscribeRSS Feed
MuraliKrishnan5
Calcite | Level 5
  • The Java Key story file (trustedcerts.jks.) does not have the current server certificate details updated.
  • The java Key store file (trustedcerts.jks.) just updated with current date of apply but NOT the server certificate which we have applied and we could see the previous year of apply in 2019 & 2021. Example as below:

Alias name: cn=xxxx,ou=xxxx,o=xxx,c=xxxx
Creation date: jul 5, 2023 (This part only updated)
Entry type: trustedCertEntry

Owner: xxxx, OU=xxxx, O=xxxx, C=xxx
Issuer: CN=xxx, OU=xxx, O=xxx, C=xxx
Valid from: Mon Oct 03 02:00:01 CEST 2016 until: Fri Oct 03 01:59:59 CEST 2036

We have Not applied the Root & Intermediate certificate as it is getting expired in 2036 so we didn’t apply it and please find the high level of steps which we have followed.

 

  1. Created the Key & CSR file.
  2. Stopped the SAS server and took the required back up.
  3. Remove existing certificates using Deployment Manager (xxxxx-mid1.xxxx.xxx.cer)
  4. From p7b file extracted the server certificate (xxxxx-mid1.xxxx.xxx.cer) alone and NOT the Root & Intermediate.( Location : /opt/sas/SASInstallFolder/SASSecurityCertificateFramework/1.1/cacerts/)
  5. Adding new certificates via the Deployment Manager . update in the above location.
  6. Verified and in the browser and also in the openssl x509 -in xxxx-mid1.xx.xx-noout -text. the Valid from changed to 2025.

 

Don't know why it is not updating in the trustedcerts.jks.

trustedcerts.pem - it as the details of root and intermediate. 

 

 

 

 

1 REPLY 1
gwootton
SAS Super FREQ
If the certificate isn't self-signed, you would not need to add the server certificate to the trust store (trustedcerts.pem/jks), only it's issuing certificates (the intermediate and root), as the server certificate is provided by the server.

The certificate and key for the server is stored in those individual files and referenced by the SAS Web Server configuration file. There are additional steps to provide the certificate and key to Environment Manager.

Update the Key and Certificate That Are Used by SAS Web Server
https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p0fwmiy0dasb5nn18fwx1x9mn2ub.htm

Update Certificates for SAS Environment Manager
https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1fpnnm9hxkhlzn1x5tkqs1caeg5.htm#p0noalwfbh...
--
Greg Wootton | Principal Systems Technical Support Engineer

suga badge.PNGThe SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment. 

Join SUGA 

Get Started with SAS Information Catalog in SAS Viya

SAS technical trainer Erin Winters shows you how to explore assets, create new data discovery agents, schedule data discovery agents, and much more.

Find more tutorials on the SAS Users YouTube channel.

Discussion stats
  • 1 reply
  • 212 views
  • 0 likes
  • 2 in conversation