Tuesday, March 6, 2012

Genrating New Certificate For CA Directory

This case is to be used when you have CA IDM Provisioning Directory Installed & You want to Genrate New certificate for Corporate DSA in Directory
1)Stop DSA’s on all servers
dxserver stop all
1)After ensuring that there is a good backup of all SSLD folders on all servers ,Run the command at the right to generate new certificates.

dxcertgen -d 3650 certs

2) Open the "trusted.pem" file and copy the last entry to the "impd_trusted.pem" file.

3)Copy the appropriate ".pem" files to all servers including the "trusted.pem" and "impd_trusted.pem"
4)Stop and start all DSA’s on all servers
dxserver stop all ; dxserver start all