HP IAP Version 2.0 Administrator Guide (July 2008)

1. Complete the form at the b ot tom of the SSL Conguration view.
You can create only two types of CSR les: one for access to the PCC, a nd one for access to
the HTTP portal machines.
2. Click Generate CSR.
To install a certicate on the PCC portal, see
Installing a third party certicate on the PCC portal on page 38.
To install a certicate on each HTTP por tal, see
Installing a third party certicate on the HTTP portals on page 39.
NOTE:
If you enter incorrect information in the form and need to generate a n ew CSR, see
Deleting a certicate signing request o n page 38 for the procedure to follow.
Deleting a certicate signing request
After a certicate signing request (CSR) is generated for the PCC or HTTP portals, it cannot be
regenerated. If you have entered incorrect information in the certicate request, the le must be manually
deleted before you can create a new CSR in the SSL Conguration view.
To delete a CSR:
1. Log in to the PCC console.
2. Go to /opt/keys and delete the CSR with one of the following commands:
rm -f pccCert.pem (to remove the PCC cer ticate request)
rm -f httpCert.pem (to remove the HTTP certicate request)
3. Upon deleting pccCert.pem and/or httpCert.pem in directory /opt/keys,logofforclosethe
PCC UI. If you do not, refreshing the PCC UI will re-create these les, and the <SSL Conguration>
page will not allow new CSRs be created.
NOTE:
Important! Do not delete the private key les (pcckey.pem or httpkey.pem).
NOTE:
After deleting pccCert.pem or httpCert.pem in /opt/keys,besuretologofforclosethePCC
UI. If you don’t and refresh, the PCC UI will re-create these les. (The SSL Conguration page will
also not allow new CSRs be created.)
Installing and generating a certicate on the PCC portal
Follow these steps to generate and install a certicate for the IAP PCC portal.
38
Conguration