Entrust Datacard

Entrust Certificate Services Support Knowledge Base

Last Modified: 2017-08-16 14:13:01.0

How do I replace Discovery self signed certificates with public SSL certificates?

Article Number: 70578

User-added image

! Before starting this procedure take a backup of your current Discovery configuration and certificate keystores.

Discovery Manager (Premises version only)
Locate your existing Discovery Manager certificate keystore.  The default path is:

C:\Program Files (x86)\Entrust\Discovery-Manager\data\tomcat.keystore

The default password for the Discovery Manager keystore is:
                changeit
The default certificate alias for the Discovery Manager keystore is:
                discovery manager ssl

You can create a new replacement Java keystore using our Java keystore command builder:
https://www.entrust.com/java-keytool-csr-generator/

Import the resulting certificate into the keystore:
http://www.entrust.net/knowledge-base/technote.cfm?tn=8426

If you overwrite the existing keystore and you use the same alias and the same password then you will not need to update the tomcat server.xml file. But if you do make changes to keystore file name or alias name or keystore password then you will have to update:
                C:\Program Files (x86)\Entrust\Discovery-Agent\tomcat\conf\server.xml
 
Discovery Agent
Locate your existing Discovery Agent certificate keystore.  The default path is:

C:\Program Files (x86)\Entrust\Discovery-Agent\data\tomcat.keystore
The default password for the Discovery Agent keystore is:
                changeit
The default certificate alias for the Discovery Agent keystore is:
                discovery agent ssl

You can create a new replacement Java keystore using our Java keystore command builder:
https://www.entrust.com/java-keytool-csr-generator/

Import the resulting certificate into the keystore:
http://www.entrust.net/knowledge-base/technote.cfm?tn=8426

If you overwrite the existing keystore and you use the same alias and the same password then you will not need to update the tomcat server.xml file. But if you do make changes to keystore file name or alias name or password then you will have to update:
                C:\Program Files (x86)\Entrust\Discovery-Agent\tomcat\conf\server.xml
 
If you are running Discovery Manager premise:

Starting in Discovery Agent version 2.4.3 there are 2 additional steps in the Discovery Agent:
In the following file:
C:\Program Files (x86)\Entrust\Discovery-Agent\data\agent-config.xml
  1. Under <AgentManagerLinkCurrentCert> paste a copy of your Discovery Manager premise certificate in PEM format
  2. Set the property <AgentManagerLinkState>Established</AgentManagerLinkState>
 
To apply the changes:
Restart Discovery Manager and Discovery Agent.

If you have any questions or concerns please contact the Entrust Certificate Services Support department for further assistance: 

Hours of Operation: 
Sunday 8:00 PM ET to Friday 8:00 PM ET 
North America (toll free): 1-866-267-9297 
Outside North America: 1-613-270-2680 (or see the list below) 
NOTE: Smart Phone users may use the 1-800 numbers shown in the table below.
Otherwise, it is very important that international callers dial the UITF format exactly as indicated. Do not dial an extra "1" before the "800" or your call will not be accepted as an UITF toll free call. 

CountryNumber
Australia0011 - 800-3687-7863
1-800-767-513
Austria00 - 800-3687-7863
Belgium00 - 800-3687-7863
Denmark00 - 800-3687-7863
Finland990 - 800-3687-7863 (Telecom Finland)
00 - 800-3687-7863 (Finnet)
France00 - 800-3687-7863
Germany00 - 800-3687-7863
Hong Kong001 - 800-3687-7863 (Voice)
002 - 800-3687-7863 (Fax)
Ireland00 - 800-3687-7863
Israel014 - 800-3687-7863
Italy00 - 800-3687-7863
Japan001 - 800-3687-7863 (KDD)
004 - 800-3687-7863 (ITJ)
0061 - 800-3687-7863 (IDC)
Korea001 - 800-3687-7863 (Korea Telecom)
002 - 800-3687-7863 (Dacom)
Malaysia00 - 800-3687-7863
Netherlands00 - 800-3687-7863
New Zealand00 - 800-3687-7863
0800-4413101
Norway00 - 800-3687-7863
Singapore001 - 800-3687-7863
Spain00 - 800-3687-7863
Sweden00 - 800-3687-7863 (Telia)
00 - 800-3687-7863 (Tele2)
Switzerland00 - 800-3687-7863
Taiwan00 - 800-3687-7863
United Kingdom00 - 800-3687-7863
0800 121 6078
+44 (0) 118 953 3088

 

Affected Products:

  • Entrust Authority Security Toolkit for the Java Platform 6.1 English Solaris
  • Entrust Authority Security Toolkit for the Java Platform 6.1 English Windows
  • Entrust Authority Security Toolkit for the Java Platform 7.0 English Solaris
  • Entrust Authority Security Toolkit for the Java Platform 7.0 English Windows
  • Entrust Authority Security Toolkit for the Java Platform 7.1 English Solaris
  • Entrust Authority Security Toolkit for the Java Platform 7.1 English Windows