<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replace the self signed certificate with a signed certificate in Insight Remote Support</title>
    <link>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/7183433#M6353</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2114570"&gt;@Dave15&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for posting!&amp;nbsp;&lt;SPAN&gt;Since you have posted in an old topic and there is no response yet, I would recommend you to create a new topic using the create "New Discussion" button, so the experts can check and assist you further.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Feb 2023 07:58:01 GMT</pubDate>
    <dc:creator>Sunitha_Mod</dc:creator>
    <dc:date>2023-02-24T07:58:01Z</dc:date>
    <item>
      <title>Replace the self signed certificate with a signed certificate</title>
      <link>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/6785256#M5213</link>
      <description>&lt;P&gt;How do I Replace in IRS 7.4.0 the self signed certificate with a signed certificate?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 09:31:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/6785256#M5213</guid>
      <dc:creator>Vincent Jansen</dc:creator>
      <dc:date>2015-09-16T09:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Replace the self signed certificate with a signed certificate</title>
      <link>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/6785338#M5214</link>
      <description>&lt;P&gt;I believe this topic is covered in the online "Help" in the Insight Remote Support tool itself. &amp;nbsp;Select Help at the top, then search for "Certificate".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are some steps listed there for importing certificates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are a few options depending on what you're trying to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 13:34:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/6785338#M5214</guid>
      <dc:creator>toddg1</dc:creator>
      <dc:date>2015-09-16T13:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Replace the self signed certificate with a signed certificate</title>
      <link>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/6785870#M5217</link>
      <description>&lt;P&gt;No info how to replace the HP self signed certificate. I search for "Certificate" in the online help in IRS self. The results are below.&lt;/P&gt;&lt;P&gt;In the install guide is only written how to add the HP self signed certificate to the trusted stores on the client site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The results for "Certificate" in the online help in IRS self:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Your search for &lt;SPAN class="query"&gt;"Certificate"&lt;/SPAN&gt; returned &lt;SPAN class="total-results"&gt;8&lt;/SPAN&gt; result(s).&lt;/P&gt;&lt;P&gt;&lt;!--   
                    &amp;amp;amp;lt;ul id=&amp;amp;amp;quot;resultList&amp;amp;amp;quot;&amp;amp;amp;gt;
                        &amp;amp;amp;lt;li&amp;amp;amp;gt;
                            &amp;amp;amp;lt;h3 class=&amp;amp;amp;quot;title&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;lt;a href=&amp;amp;amp;quot;#TopicA.htm&amp;amp;amp;quot; target=_blank&amp;amp;amp;gt;Topic A&amp;amp;amp;lt;/a&amp;amp;amp;gt;&amp;amp;amp;lt;/h3&amp;amp;amp;gt;
                            &amp;amp;amp;lt;span class=&amp;amp;amp;quot;ratingStarsContainer&amp;amp;amp;quot;&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarFilled&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarFilled&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarFilled&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarFilled&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarEmpty&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                17 reviews
                            &amp;amp;amp;lt;/span&amp;amp;amp;gt;
                            &amp;amp;amp;lt;div class=&amp;amp;amp;quot;description&amp;amp;amp;quot;&amp;amp;amp;gt;Lorem ipsum dolor sit amet, consectetur adipiscing elit. Donec a dictum dolor. Suspendisse potenti. Donec commodo, mi et pulvinar lobortis, velit magna sodales lectus, sit amet interdum magna urna eget leo. Pellentesque risus eros, vehicula non tempus at, bibendum in neque. In mollis malesuada facilisis.&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                            &amp;amp;amp;lt;div class=&amp;amp;amp;quot;url&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;lt;cite&amp;amp;amp;gt;TopicA.htm&amp;amp;amp;lt;/cite&amp;amp;amp;gt;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                        &amp;amp;amp;lt;/li&amp;amp;amp;gt;
                        &amp;amp;amp;lt;li&amp;amp;amp;gt;
                            &amp;amp;amp;lt;h3 class=&amp;amp;amp;quot;title&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;lt;a href=&amp;amp;amp;quot;#TopicB.htm&amp;amp;amp;quot; target=_blank&amp;amp;amp;gt;Topic B&amp;amp;amp;lt;/a&amp;amp;amp;gt;&amp;amp;amp;lt;/h3&amp;amp;amp;gt;
                            &amp;amp;amp;lt;span class=&amp;amp;amp;quot;ratingStarsContainer&amp;amp;amp;quot;&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarFilled&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarFilled&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarFilled&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarEmpty&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                &amp;amp;amp;lt;div class=&amp;amp;amp;quot;ratingStar ratingStarEmpty&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;amp;#160;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                                5 reviews
                            &amp;amp;amp;lt;/span&amp;amp;amp;gt;
                            &amp;amp;amp;lt;div class=&amp;amp;amp;quot;description&amp;amp;amp;quot;&amp;amp;amp;gt;Duis nec massa est, id hendrerit neque. Sed ornare adipiscing turpis eu luctus. Phasellus eu viverra lectus. Nunc purus risus, scelerisque non porttitor vitae, fringilla luctus augue.&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                            &amp;amp;amp;lt;div class=&amp;amp;amp;quot;url&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;lt;cite&amp;amp;amp;gt;TopicB.htm&amp;amp;amp;lt;/cite&amp;amp;amp;gt;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                        &amp;amp;amp;lt;/li&amp;amp;amp;gt;
                        &amp;amp;amp;lt;li&amp;amp;amp;gt;
                            &amp;amp;amp;lt;h3 class=&amp;amp;amp;quot;title&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;lt;a href=&amp;amp;amp;quot;#TopicA.htm&amp;amp;amp;quot; target=_blank&amp;amp;amp;gt;Topic A&amp;amp;amp;lt;/a&amp;amp;amp;gt;&amp;amp;amp;lt;/h3&amp;amp;amp;gt;
                            &amp;amp;amp;lt;div class=&amp;amp;amp;quot;description&amp;amp;amp;quot;&amp;amp;amp;gt;Lorem ipsum dolor sit amet, consectetur adipiscing elit. Donec a dictum dolor. Suspendisse potenti. Donec commodo, mi et pulvinar lobortis, velit magna sodales lectus, sit amet interdum magna urna eget leo. Pellentesque risus eros, vehicula non tempus at, bibendum in neque. In mollis malesuada facilisis.&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                            &amp;amp;amp;lt;div class=&amp;amp;amp;quot;url&amp;amp;amp;quot;&amp;amp;amp;gt;&amp;amp;amp;lt;cite&amp;amp;amp;gt;TopicA.htm&amp;amp;amp;lt;/cite&amp;amp;amp;gt;&amp;amp;amp;lt;/div&amp;amp;amp;gt;
                        &amp;amp;amp;lt;/li&amp;amp;amp;gt;
                    &amp;amp;amp;lt;/ul&amp;amp;amp;gt;
                       --&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://wpzkh0910:7906/remotesupport/resources/help/en/InsightRSHelp.htm#GUI_rsadmin.htm?Highlight=Certificate" target="_blank"&gt;Command line tools&lt;/A&gt;&lt;DIV&gt;Command line tools Insight RS has a command line utility that can be used to configure settings and run jobs.&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;GUI_rsadmin.htm&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://wpzkh0910:7906/remotesupport/resources/help/en/InsightRSHelp.htm#MonitoredDevices/Config_HP-UX.html?Highlight=Certificate" target="_blank"&gt;Configuring Integrity HP-UX servers&lt;/A&gt;&lt;DIV&gt;Configuring Integrity HP-UX servers Before attempting to configure Insight Remote Support for your HP-UX monitored device, read the following information.&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;MonitoredDevices/Config_HP-UX.html&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://wpzkh0910:7906/remotesupport/resources/help/en/InsightRSHelp.htm#MonitoredDevices/Config_E-Series_Switch.html?Highlight=Certificate" target="_blank"&gt;Configuring ProVision-based networking switches&lt;/A&gt;&lt;DIV&gt;Configuring ProVision-based networking switches ProVision-based networking switches (formerly E-series/ProCurve) require SNMP for discovery and event monitoring. ProVision-based switches ship with SNMP installed and enabled.&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;MonitoredDevices/Config_E-Series_Switch.html&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://wpzkh0910:7906/remotesupport/resources/help/en/InsightRSHelp.htm#ConfigurationWizards/GUI_Endpoint_Intro.htm?Highlight=Certificate" target="_blank"&gt;Complete the Monitored Device Setup Wizard&lt;/A&gt;&lt;DIV&gt;Complete the Monitored Device Setup Wizard The Monitored Device Setup Wizard checks whether Insight RS can communicate with devices in your environment based on the configured credentials and verifies the devices are ready to be monitored by HP Insight Remote Support. The Monitored Device Setup Wizard can be left unattended for large environments. The results can be viewed in the final screen of the wizard or on the Discovery screen in the Insight RS Console.&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;ConfigurationWizards/GUI_Endpoint_Intro.htm&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://wpzkh0910:7906/remotesupport/resources/help/en/InsightRSHelp.htm#Discovery/GUI_Discovery_ManageCredentials.htm?Highlight=Certificate" target="_blank"&gt;Manage discovery credentials&lt;/A&gt;&lt;DIV&gt;Manage discovery credentials Each device in your environment requires protocols that Insight Remote Support uses to communicate with the device. Each of these protocols must have associated credential information.&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;Discovery/GUI_Discovery_ManageCredentials.htm&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://wpzkh0910:7906/remotesupport/resources/help/en/InsightRSHelp.htm#MonitoredDevices/Config_SDX.html?Highlight=Certificate" target="_blank"&gt;Configuring Integrity Superdome X servers&lt;/A&gt;&lt;DIV&gt;Configuring Integrity Superdome X servers The Integrity Superdome X system has implemented single-source event reporting such that all event indications are reported through the Integrity Superdome X Onboard Administrator (OA). The OA monitors the core system hardware and generates WS-Management alert indications when it determines that an important event occurs. The Linux WS-Man providers and Windows WinRM providers monitor partition IO devices and report their events through the OA as well.&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;MonitoredDevices/Config_SDX.html&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://wpzkh0910:7906/remotesupport/resources/help/en/InsightRSHelp.htm#CollectionServices/GUI_CollSchedTab_Intro.htm?Highlight=Certificate" target="_blank"&gt;Manage Collection Schedules&lt;/A&gt;&lt;DIV&gt;Manage Collection Schedules For more information about collections, see About collections. On the Collection Services → Collection Schedules tab, you can:&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;CollectionServices/GUI_CollSchedTab_Intro.htm&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://wpzkh0910:7906/remotesupport/resources/help/en/InsightRSHelp.htm#MonitoredDevices/Config_Integrity_Linux.html?Highlight=Certificate" target="_blank"&gt;Configuring Integrity Linux servers&lt;/A&gt;&lt;DIV&gt;Configuring Integrity Linux servers To configure your Integrity Linux servers to be monitored by Insight RS,&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 05:27:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/6785870#M5217</guid>
      <dc:creator>Vincent Jansen</dc:creator>
      <dc:date>2015-09-18T05:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Replace the self signed certificate with a signed certificate</title>
      <link>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/6788291#M5224</link>
      <description>&lt;P&gt;&lt;A target="_blank"&gt;Create and import &lt;SPAN class="SearchHighlight SearchHighlight1"&gt;certificate&lt;/SPAN&gt;s&lt;/A&gt;&lt;/P&gt;&lt;P&gt;----------------------------------&lt;/P&gt;&lt;P&gt;&lt;A href="http://h17007.www1.hp.com/docs/enterprise/servers/InsightRS/webhelp/InsightRSHelp.htm#GUI_rsadmin.htm?Highlight=certificate" target="_blank"&gt;http://h17007.www1.hp.com/docs/enterprise/servers/InsightRS/webhelp/InsightRSHelp.htm#GUI_rsadmin.htm?Highlight=certificate&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 19:54:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/6788291#M5224</guid>
      <dc:creator>Gurbaxis</dc:creator>
      <dc:date>2015-09-24T19:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Replace the self signed certificate with a signed certificate</title>
      <link>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/7138290#M6188</link>
      <description>&lt;P&gt;This document is classified as "Public" but somehow it does not seem to be available to the public!&amp;nbsp; &lt;LI-EMOJI id="lia_disappointed-face" title=":disappointed_face:"&gt;&lt;/LI-EMOJI&gt;&lt;/P&gt;&lt;P&gt;Title: IRS - How to configure IRS using company signed certificate?&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;Object Name:&lt;/STRONG&gt;mmr_ns-0112182&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Document Type:&lt;/STRONG&gt;Support Information&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Original Owner:&lt;/STRONG&gt;NonStop NSK Hardware&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Disclosure Level:&lt;/STRONG&gt;Public&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Version State:&lt;/STRONG&gt;final&lt;/DIV&gt;&lt;DIV&gt;Environment&lt;/DIV&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFact"&gt;FACT:&lt;/SPAN&gt;NonStop&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFact"&gt;FACT:&lt;/SPAN&gt;T0918 NonStop Leveraged FW and SW&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFact"&gt;FACT:&lt;/SPAN&gt;Insight Remote Support (IRS)&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFact"&gt;FACT:&lt;/SPAN&gt;rsadmin&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFact"&gt;FACT:&lt;/SPAN&gt;SSL&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFact"&gt;FACT:&lt;/SPAN&gt;TLS&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFact"&gt;FACT:&lt;/SPAN&gt;OpenSSL&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFact"&gt;FACT:&lt;/SPAN&gt;RSA&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFact"&gt;FACT:&lt;/SPAN&gt;Private Key&lt;/P&gt;&lt;DIV&gt;Questions/Symptoms&lt;/DIV&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelGoal"&gt;GOAL:&lt;/SPAN&gt;How to configure IRS using company signed certificate?&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelGoal"&gt;GOAL:&lt;/SPAN&gt;How to configure IRS using Third Party CA signed certificate?&lt;/P&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelGoal"&gt;GOAL:&lt;/SPAN&gt;How to import certificates signed by a Private or Third Party CA to IRS?&lt;/P&gt;&lt;DIV&gt;Cause&lt;/DIV&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelCause"&gt;CAUSE:&lt;/SPAN&gt;IRS is configured with self-signed certificate by default. Company (i.e. Private CA) or Third-Party signed certificates need to be configured due to organizational security enforcement.&lt;/P&gt;&lt;DIV&gt;Answer/Solution&lt;/DIV&gt;&lt;P class="KCSparagraph"&gt;&lt;SPAN class="KCSlabelFix"&gt;FIX:&lt;/SPAN&gt;&lt;BR /&gt;There are 3 possible scenarios in which a customer would like to import their own certificates to Insight Remote Support (IRS):&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Scenario #1: Create a private key and CSR by using the rsadmin utility, and import the signed certificate.&lt;BR /&gt;&lt;BR /&gt;In this scenario, you would use the rsadmin utility to generate the private key and Certificate Signing Request (CSR), and then import the certificates received from your corporate Certificate Authority (CA) into the IRS database. The steps are as follows:&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 1: Checking the default configuration key settings related to the certificate:&lt;BR /&gt;&lt;BR /&gt;rsadmin config -displayAll | find "uca.cert"&lt;BR /&gt;&lt;BR /&gt;Example output:&lt;BR /&gt;&lt;BR /&gt;GLOBAL uca.cert.checkrevocationstatus.cache.timeout =&amp;gt; 86400&lt;BR /&gt;GLOBAL uca.cert.country =&amp;gt; US&lt;BR /&gt;GLOBAL uca.cert.email =&amp;gt;&lt;BR /&gt;GLOBAL uca.cert.locality =&amp;gt; Palo Alto&lt;BR /&gt;GLOBAL uca.cert.organization =&amp;gt; Hewlett-Packard&lt;BR /&gt;GLOBAL uca.cert.organizationunit =&amp;gt; Insight Remote Support&lt;BR /&gt;GLOBAL uca.cert.signaturealgorithm =&amp;gt; SHA256WITHRSAENCRYPTION&lt;BR /&gt;GLOBAL uca.cert.stateorprov =&amp;gt; California&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 2: Issue the following commands to update the configuration keys that define certificate fields in the CSR. These fields need to be provided by your corporate CA.&lt;BR /&gt;&lt;BR /&gt;For example:&lt;BR /&gt;&lt;BR /&gt;rsadmin config -set uca.cert.organization="Hewlett Packard Enterprise Company"&lt;BR /&gt;rsadmin config -set uca.cert.organizationunit="Global NonStop Solution Center"&lt;BR /&gt;rsadmin config -set uca.cert.locality="Palo Alto"&lt;BR /&gt;rsadmin config -set uca.cert.stateorprov="California"&lt;BR /&gt;rsadmin config -set uca.cert.country="US"&lt;BR /&gt;rsadmin config -set uca.cert.email="nonstopsupport@hpe.com"&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 3: Verify that the configuration key settings were changed prior to generating the CSR:&lt;BR /&gt;&lt;BR /&gt;rsadmin config -displayAll | find "uca.cert"&lt;BR /&gt;&lt;BR /&gt;Example output:&lt;BR /&gt;&lt;BR /&gt;GLOBAL uca.cert.checkrevocationstatus.cache.timeout =&amp;gt; 86400&lt;BR /&gt;GLOBAL uca.cert.country =&amp;gt; US&lt;BR /&gt;GLOBAL uca.cert.email =&amp;gt; nonstopsupport@hpe.com&lt;BR /&gt;GLOBAL uca.cert.locality =&amp;gt; Palo Alto&lt;BR /&gt;GLOBAL uca.cert.organization =&amp;gt; Global NonStop Solution Center&lt;BR /&gt;GLOBAL uca.cert.organizationunit =&amp;gt; Hewlett Packard Enterprise Company&lt;BR /&gt;GLOBAL uca.cert.signaturealgorithm =&amp;gt; SHA256WITHRSAENCRYPTION&lt;BR /&gt;GLOBAL uca.cert.stateorprov =&amp;gt; California&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 4: Generate the CSR by executing the following command:&lt;BR /&gt;&lt;BR /&gt;rsadmin cert -csr&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 5: Take the resulting Base64 encoded CSR to your corporate CA for signing and request a Base64 encoded response. There are two possible responses:&lt;BR /&gt;&lt;BR /&gt;a) A certificate chain containing the signed certificate and the CA certificate(s).&lt;BR /&gt;&lt;BR /&gt;The file will typically be in a P7b format. In that case, issue the following command:&lt;BR /&gt;&lt;BR /&gt;rsadmin cert -csr -response &amp;lt;servchain.p7b&amp;gt;&lt;BR /&gt;&lt;BR /&gt;b) A signed certificate, Root CA and (if any) Intermediate CA certificate(s) in separate files.&lt;BR /&gt;&lt;BR /&gt;In that case, you need to import the Root CA and (if any) Intermediate CA certificate(s) into the IRS database and then import the signed certificate.&lt;BR /&gt;&lt;BR /&gt;i) Import the Root CA and (if any) Intermediate CA certificate(s). They must be imported in the appropriate order.&lt;BR /&gt;&lt;BR /&gt;rsadmin cert -alias &amp;lt;IntCAname&amp;gt; -import -trustfile &amp;lt;intcert.pem&amp;gt;&lt;BR /&gt;rsadmin cert -alias &amp;lt;RootCAname&amp;gt; -import -trustfile &amp;lt;cacert.pem&amp;gt;&lt;BR /&gt;&lt;BR /&gt;ii) Import the signed certificate&lt;BR /&gt;&lt;BR /&gt;rsadmin cert -csr -response &amp;lt;servcert.pem&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 6: Restart IRS services&lt;BR /&gt;&lt;BR /&gt;net stop hprsmain&lt;BR /&gt;net stop hprsreceivers&lt;BR /&gt;net start hprsmain&lt;BR /&gt;net start hprsreceivers&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Scenario #2: Create a private key and CSR by using a tool other than rsadmin, and import the signed certificate and private key.&lt;BR /&gt;&lt;BR /&gt;In this scenario, you would use your own tool (e.g. OpenSSL) to generate the private key and Certificate Signing Request (CSR), and then import the private key and the signed certificates received from the corporate Certificate Authority (CA) into the IRS database. The steps are as follows:&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 1: Create the private key and CSR by using your own tool. The details of the CSR depend on the corporate requirements so check with your Certificate Authority on how to create your private key and CSR. If you were to use OpenSSL, here is an example of creating a SHA256 private key and CSR:&lt;BR /&gt;&lt;BR /&gt;$ openssl req -out csr.pem -new -sha256 -newkey rsa:2048 -keyout servkey.pem&lt;BR /&gt;Generating a RSA private key&lt;BR /&gt;...+++++&lt;BR /&gt;......................+++++&lt;BR /&gt;writing new private key to 'servkey.pem'&lt;BR /&gt;Enter PEM pass phrase:&lt;BR /&gt;Verifying - Enter PEM pass phrase:&lt;BR /&gt;-----&lt;BR /&gt;You are about to be asked to enter information that will be incorporated&lt;BR /&gt;into your certificate request.&lt;BR /&gt;What you are about to enter is what is called a Distinguished Name or a DN.&lt;BR /&gt;There are quite a few fields but you can leave some blank&lt;BR /&gt;For some fields there will be a default value,&lt;BR /&gt;If you enter '.', the field will be left blank.&lt;BR /&gt;-----&lt;BR /&gt;Country Name (2 letter code) [XX]:US&lt;BR /&gt;State or Province Name (full name) []:California&lt;BR /&gt;Locality Name (eg, city) [Default City]:Palo Alto&lt;BR /&gt;Organization Name (eg, company) [Default Company Ltd]:Hewlett Packard Enterprise Company&lt;BR /&gt;Organizational Unit Name (eg, section) []:Global NonStop Solution Center&lt;BR /&gt;Common Name (eg, your name or your server's hostname) []:server.hpe.com&lt;BR /&gt;Email Address []:nonstopsupport@hpe.com&lt;BR /&gt;&lt;BR /&gt;Please enter the following 'extra' attributes&lt;BR /&gt;to be sent with your certificate request&lt;BR /&gt;A challenge password []:&lt;BR /&gt;An optional company name []:&lt;BR /&gt;&lt;BR /&gt;$&lt;BR /&gt;&lt;BR /&gt;Note: In the above example, you have to enter a "pass phrase" and the details of the CSR. Some entries might be optional such as the email address. The "challenge password" and "company name" are also optional and in the example above are blank (just press the ENTER key).&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 2: Submit the CSR to your corporate CA.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 3: Once you receive your certificates, create the P7b certificate chain using OpenSSL (in this example, &amp;lt;servcert.pem&amp;gt; is the Server certificate, &amp;lt;intcert.pem&amp;gt; is the Intermediate CA, and &amp;lt;cacert.pem&amp;gt; is the Root CA):&lt;BR /&gt;&lt;BR /&gt;openssl crl2pkcs7 -nocrl -certfile &amp;lt;servcert.pem&amp;gt; -certfile &amp;lt;intcert.pem&amp;gt; -certfile &amp;lt;cacert.pem&amp;gt; -out &amp;lt;servchain.p7b&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 4: Stop the IRS services:&lt;BR /&gt;&lt;BR /&gt;net stop hprsmain&lt;BR /&gt;net stop hprsreceivers&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 5: Import the certificate chain (p7b) certificate using rsadmin:&lt;BR /&gt;&lt;BR /&gt;rsadmin cert -alias jetty -import -trustfile &amp;lt;servchain.p7b&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 6: Remove the pass phrase from the private key using OpenSSL if that's not already done (in this example, &amp;lt;servkey.pem&amp;gt; is the private key encrypted with &amp;lt;servkeypass&amp;gt;, which is the "pass phrase" used in Step 1):&lt;BR /&gt;&lt;BR /&gt;openssl rsa -in &amp;lt;servkey.pem&amp;gt; -out &amp;lt;servkey_nopass.pem&amp;gt; -passin pass:&amp;lt;servkeypass&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 7: Import the new private key &amp;lt;servkey_nopass.pem&amp;gt;:&lt;BR /&gt;&lt;BR /&gt;rsadmin cert -alias jetty -import -trustkey &amp;lt;servkey_nopass.pem&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 8: Start the IRS services:&lt;BR /&gt;&lt;BR /&gt;net start hprsmain&lt;BR /&gt;net start hprsreceivers&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Scenario #3: Create a private key and CSR by using your own tool (e.g. OpenSSL) and import a self-signed certificate signed with SHA256.&lt;BR /&gt;&lt;BR /&gt;To create and import a self-signed certificate signed with SHA256, execute the following commands:&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 1: Create a self-signed certificate with RSA private key using OpenSSL and remove the pass phrase (in this example, &amp;lt;servkey.pem&amp;gt; is the private key encrypted with &amp;lt;servkeypass&amp;gt;, which is the "pass phrase" entered after executing the first command):&lt;BR /&gt;&lt;BR /&gt;openssl req -x509 -nodes -sha256 -days 365 -newkey rsa:2048 -keyout &amp;lt;servkey.pem&amp;gt; -out &amp;lt;servcert.pem&amp;gt;&lt;BR /&gt;openssl rsa -in &amp;lt;servkey.pem&amp;gt; -out &amp;lt;servkey_nopass.pem&amp;gt; -passin pass:&amp;lt;servkeypass&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 2: Stop the IRS services:&lt;BR /&gt;&lt;BR /&gt;net stop hprsmain&lt;BR /&gt;net stop hprsreceivers&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 3: Delete the current Insight RS client certificate:&lt;BR /&gt;&lt;BR /&gt;rsadmin cert -delete -alias jetty&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 4: Import a new Insight RS client certificate:&lt;BR /&gt;&lt;BR /&gt;rsadmin cert -import -alias jetty -trustfile &amp;lt;servcert.pem&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 5: Import the new private key:&lt;BR /&gt;&lt;BR /&gt;rsadmin cert -import -alias jetty -trustkey &amp;lt;servkey_nopass.pem&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Step 6: Start the IRS services:&lt;BR /&gt;&lt;BR /&gt;net start hprsmain&lt;BR /&gt;net start hprsreceivers&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;© Copyright 2021 Hewlett Packard Enterprise Development Company, L.P.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 08 Jun 2021 00:39:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/7138290#M6188</guid>
      <dc:creator>Lawrance Lee_1</dc:creator>
      <dc:date>2021-06-08T00:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Replace the self signed certificate with a signed certificate</title>
      <link>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/7182964#M6349</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.hpe.com/t5/user/viewprofilepage/user-id/427" target="_self"&gt;&lt;SPAN class=""&gt;Lawrance Lee -&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I have senario 2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I have my p7b file with the whole certificate chain and i also have exported the private key and have taken the password off.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;However when i import the p7b certs file i get the following results:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp; *************&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;C:\Program Files\HP\RS\BIN&amp;gt;rsadmin cert -alias jetty -import -trustfile c:\certificate.p7b&lt;/P&gt;&lt;P&gt;p7b chain trusting 'IRSRootCA'&lt;/P&gt;&lt;P&gt;p7b chain trusting 'IRSIssuingCA'&lt;/P&gt;&lt;P&gt;Cannot validate certificate chain.&amp;nbsp; Not importing "jetty".&lt;/P&gt;&lt;P&gt;Could not validate cert [1]: subject/issuer name chaining check failed&lt;/P&gt;&lt;P&gt;Certificate import failed&lt;/P&gt;&lt;P&gt;Jetty and Receiver restart pending&lt;/P&gt;&lt;P&gt;Cert import failed alias=jetty file=c:\certificate.p7b&lt;/P&gt;&lt;P&gt;&amp;nbsp; *******************&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 19:48:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/7182964#M6349</guid>
      <dc:creator>Dave15</dc:creator>
      <dc:date>2023-02-17T19:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Replace the self signed certificate with a signed certificate</title>
      <link>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/7183433#M6353</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2114570"&gt;@Dave15&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for posting!&amp;nbsp;&lt;SPAN&gt;Since you have posted in an old topic and there is no response yet, I would recommend you to create a new topic using the create "New Discussion" button, so the experts can check and assist you further.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 07:58:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/insight-remote-support/replace-the-self-signed-certificate-with-a-signed-certificate/m-p/7183433#M6353</guid>
      <dc:creator>Sunitha_Mod</dc:creator>
      <dc:date>2023-02-24T07:58:01Z</dc:date>
    </item>
  </channel>
</rss>

