HP IAP Version 2.0 Administrator Guide (July 2008)
1. Complete the form at the b ot tom of the SSL Configuration view.
You can create only two types of CSR files: one for access to the PCC, a nd one for access to
the HTTP portal machines.
2. Click Generate CSR.
To install a certificate on the PCC portal, see
“Installing a third party certificate on the PCC portal” on page 38.
To install a certificate on each HTTP por tal, see
“Installing a third party certificate on the HTTP portals” on page 39.
NOTE:
If you enter incorrect information in the form and need to generate a n ew CSR, see
“Deleting a certificate signing request” o n page 38 for the procedure to follow.
Deleting a certificate signing request
After a certificate signing request (CSR) is generated for the PCC or HTTP portals, it cannot be
regenerated. If you have entered incorrect information in the certificate request, the file must be manually
deleted before you can create a new CSR in the SSL Configuration view.
To delete a CSR:
1. Log in to the PCC console.
2. Go to /opt/keys and delete the CSR with one of the following commands:
rm -f pccCert.pem (to remove the PCC cer tificate request)
rm -f httpCert.pem (to remove the HTTP certificate request)
3. Upon deleting pccCert.pem and/or httpCert.pem in directory /opt/keys,logofforclosethe
PCC UI. If you do not, refreshing the PCC UI will re-create these files, and the <SSL Configuration>
page will not allow new CSRs be created.
NOTE:
Important! Do not delete the private key files (pcckey.pem or httpkey.pem).
NOTE:
After deleting pccCert.pem or httpCert.pem in /opt/keys,besuretologofforclosethePCC
UI. If you don’t and refresh, the PCC UI will re-create these files. (The SSL Configuration page will
also not allow new CSRs be created.)
Installing and generating a certifi cate on the PCC portal
Follow these steps to generate and install a certificate for the IAP PCC portal.
38
Configuration