<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trusted External Certificate Import in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5427071#M53201</link>
    <description>&lt;P&gt;Any word on when these will be supported?&lt;/P&gt;</description>
    <pubDate>Fri, 23 Dec 2011 15:58:56 GMT</pubDate>
    <dc:creator>Michael Kutyna</dc:creator>
    <dc:date>2011-12-23T15:58:56Z</dc:date>
    <item>
      <title>Trusted External Certificate Import</title>
      <link>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/4728739#M42751</link>
      <description>We are wanting the ability to publish HPSIM externally via ISA.  In order to do that I will need the HPSIM server to have an external authority certificate instead of a self signed certificate.  The problem is that HPSIM generates the certificate as 1024 and external certificate authorities now require 2048 for the encryption so when I went to go try to get a certifice Globalsign slapped my hand and Oh not you don't it doesn't meet the 2048 or higher standard.  Well I do not see a way in HP SIM to tell it that I want that encrypiton level, even though it states in the manual that you can have 2048 or less.&lt;BR /&gt;&lt;BR /&gt;Is there a way to get HPSIM to generate a request for 2048.,</description>
      <pubDate>Mon, 20 Dec 2010 20:19:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/4728739#M42751</guid>
      <dc:creator>Robert W. Eastman Jr._2</dc:creator>
      <dc:date>2010-12-20T20:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted External Certificate Import</title>
      <link>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5298713#M52481</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm in front of the same problem. I would like to have an official certificate signed by a trusted CA, but for SAN (Subject Alternate Name) certificate they only accept at least 2048 bit certificate.&lt;/P&gt;&lt;P&gt;Is ther a way to create / replace the SIM certifcate by one of 2048 bit size?&lt;/P&gt;&lt;P&gt;Could we just replace the private key and it's certificate by one generated using openssl?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any hint.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2011 11:57:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5298713#M52481</guid>
      <dc:creator>jasmo</dc:creator>
      <dc:date>2011-08-12T11:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted External Certificate Import</title>
      <link>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5299333#M52489</link>
      <description>&lt;P&gt;Oddly enough this came up in conversation today between a couple of us who have been asked this very question. The 2048 bit CSR is coming, but isn't here today in SIM. I posed the question internally and if come up with a work around I'll pass it on if no one beats me to the punch and posts it here.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Aug 2011 02:41:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5299333#M52489</guid>
      <dc:creator>jim goodman</dc:creator>
      <dc:date>2011-08-13T02:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted External Certificate Import</title>
      <link>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5313555#M52591</link>
      <description>&lt;P&gt;Does HP know what release of HPSIM that we will be able to produce a 2048 certificate request?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2011 13:44:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5313555#M52591</guid>
      <dc:creator>Robert W. Eastman Jr._2</dc:creator>
      <dc:date>2011-08-26T13:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted External Certificate Import</title>
      <link>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5427071#M53201</link>
      <description>&lt;P&gt;Any word on when these will be supported?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2011 15:58:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5427071#M53201</guid>
      <dc:creator>Michael Kutyna</dc:creator>
      <dc:date>2011-12-23T15:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted External Certificate Import</title>
      <link>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5436783#M53224</link>
      <description>&lt;P&gt;i m sure next version which will be coming soon. 7.0&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2012 10:22:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5436783#M53224</guid>
      <dc:creator>Change_happens</dc:creator>
      <dc:date>2012-01-03T10:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted External Certificate Import</title>
      <link>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5511065#M53320</link>
      <description>&lt;P&gt;&lt;BR /&gt;Using HP SIM 6.3 with 2048 bit third party CA signed cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-1. optional - on Windows 2008r2 you might prefer not to reconfigure java Connector port 280 to port 80, Windows 2008r2 supports WinRM - remote management - which also runs over port 80, IIS has special code to support dual purposing the use of port 80 for an application and the WinRM service. But you can install the URL Rewrite module in IIS and add a rule to redirect connections to the Default website automatically to the java Connector port 443 - Another gotcha is the 50000 connector port has challenging syntax which doesn't process a non-slashed URL properly change it to the traditional &amp;gt;&amp;lt;/Connector&amp;gt; format and everything will be fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;0. optional - change URL port to https default port&lt;/P&gt;&lt;P&gt;edit C:\Program Files\HP\Systems Insight Manager\jboss\server\hpsim\deploy\jboss-web.deployer\server.xml change two instances of 50000 to 443&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. get &amp;lt;current password&amp;gt; for private key and keystore from C:\Program Files\HP\Systems Insight Manager\jboss\server\hpsim\deploy\jboss-web.deployer\server.xml search for "keystorePass="&lt;BR /&gt;&lt;BR /&gt;2. create a 2048 bit private keypair and keystore&lt;BR /&gt;cd C:\Program Files\HP\Systems Insight Manager\j2re\bin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;keytool -genkey -keyalg RSA -keysize 2048 -keypass &amp;lt;current password&amp;gt; -validity 1000 -alias tomcat -keystore hp.keystore&lt;BR /&gt;&lt;BR /&gt;Enter keystore password: &amp;lt;current password&amp;gt;&lt;BR /&gt;Re-ener new password: &amp;lt;current password&amp;gt;&lt;BR /&gt;First and last name: hpsim.domain.com&lt;BR /&gt;Name of Organization Unit: department&lt;BR /&gt;Name of Organization: company&lt;BR /&gt;Name of City or Locale: city&lt;BR /&gt;Name of State or Province: state&lt;BR /&gt;Two letter Country Code: us&lt;BR /&gt;&lt;BR /&gt;3. create a signing request&lt;/P&gt;&lt;P&gt;cd C:\Program Files\HP\Systems Insight Manager\j2re\bin&lt;BR /&gt;keytool -certreq -alias tomcat -keyalg RSA -keystore hp.keystore -file hpsim.csr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. get request signed&lt;BR /&gt;&lt;BR /&gt;5. import the CA root and intermediate and signed cert into hp.keystore - portcle is a really nice opensource GUI tool for managing keystores&lt;BR /&gt;&lt;BR /&gt;6. rename old keystore&lt;/P&gt;&lt;P&gt;cd C:\Program Files\HP\Systems Insight Manager\config\certstor&lt;/P&gt;&lt;P&gt;ren hp.keystore old.hp.keystore&lt;BR /&gt;&lt;BR /&gt;7. install new keystore&lt;/P&gt;&lt;P&gt;copy C:\Program Files\HP\Systems Insight Manager\j2re\bin\hp.keystore&lt;/P&gt;&lt;P&gt;C:\Program Files\HP\Systems Insight Manager\config\certstor\hp.keystore&lt;BR /&gt;&lt;BR /&gt;8. synchronize certs&lt;BR /&gt;cd C:\Program Files\HP\Systems Insight Manager\bin&lt;BR /&gt;mxcert -s&lt;BR /&gt;&lt;BR /&gt;9. restart hp sim&lt;BR /&gt;C:\Program Files\HP\Systems Insight Manager\bin&amp;gt;sc stop "HP Systems Insight Manager"&lt;BR /&gt;wait about 2 minutes&lt;BR /&gt;C:\Program Files\HP\Systems Insight Manager\bin&amp;gt;sc start "HP Systems Insight Manager"&lt;BR /&gt;wait about 2 minutes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;verify with log file C:\Program Files\HP\Systems Insight Manager\logs\mxdomainmgr.0&lt;BR /&gt;&lt;BR /&gt;Look at the bottom of the file for:&lt;BR /&gt;&lt;BR /&gt;28 Jan 00:43:46,230 INFO&amp;nbsp; [Server] JBoss (MX MicroKernel) [4.2.3.GA (build: SVNTag=JBoss_4_2_3_GA date=200807181439)] Started in 58s:812ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://hpsim.domain.com/"&gt;https://hpsim.domain.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2012 05:18:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/5511065#M53320</guid>
      <dc:creator>John T Willis</dc:creator>
      <dc:date>2012-02-10T05:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted External Certificate Import</title>
      <link>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/6845197#M60753</link>
      <description>&lt;P&gt;Great manual..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was successfull only by&amp;nbsp;doing steps 3-5 right in Portecle.app.&lt;/P&gt;&lt;P&gt;Steps 2,6,7 aren't required if you work directly with existing keystore:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\Program Files\HP\Systems Insight Manager\config\certstor\hp.keystore&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2016 13:21:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trusted-external-certificate-import/m-p/6845197#M60753</guid>
      <dc:creator>i3laze</dc:creator>
      <dc:date>2016-03-25T13:21:57Z</dc:date>
    </item>
  </channel>
</rss>

