Configure a third-party CA certificate
You can use a self-signed or a third-party certificate to validate your Resiliency manager.
Consider the following points:
For Windows, you can give a certificate as a file path or install the third-party certificate in the Trusted root certificates authorities.
To switch from a self-signed certificate to a third-party certificate for an already added Resiliency Platform, you can edit the Resiliency Platform.
To configure a third-party CA certificate
- Copy a PKCS #7 or P7B file having certificates of the trusted root certificates authorities that are bundled together. This file may either be PEM or DER encoded.
- Create a CA file containing the PEM encoded certificates of the trusted root certificate authorities that are concatenated together.
- In the bp.conf file, create the following entries, where /certificate.pem is the file name:
ECA_TRUST_STORE_PATH = /certificate.pem
Verify that the nbwebsvc account has the permissions to access the path that ECA_TRUST_STORE_PATH refers.