By default, on first time start-up, it creates a self-signed certificate. This self-signed certificate will not be trusted by the user browsers. Step 1: Create a Keystore file. Step 2: Create. Before requesting for a certificate from a CA, you need to create tomcat specific ".

When it asks for first and last name, this is NOT your first and last name, but rather it is your Fully Qualified Domain Name for the site you are securing. On entering the required information, confirm that the information is correct by entering 'y' or 'yes' when prompted. At the end of executing the above command, you will be prompted to enter keystore password. Try giving the password same as your key password. Make sure to remember the password you choose.

NOTE: We request you to make a backup copy of the sdp. This backed up keystore can be used if the certificate installation goes wrong or when you renew your certificates the next year. Note : If you have the Private Key as a. The following screenshot describes the process for a. Download the certificate files received from the CA via e-mail to the directory where your keystore sdp.

The certificates must be installed to this exact keystore. If you try to install it to a different keystore it will not work. The certificates you had downloaded must be installed to your keystore in the correct order for your certificate to be trusted. If the certificates are not installed in the correct order, then the certificate will not authenticate properly.

These certificates are usually in the format. If your certificate is with the extension. P7b Certificate to export the certs to a. Looking at the above certification path we can infer that we need to import two other certificates before the domain certificate. First is the Root , next the Intermediate and finally the Domain Certificate.

Some CAs may also use another certificate called Cross Intermediate. Installing the Root Certificate file Each time you install a certificate to your keystore you will be prompted for the keystore password, which you chose while generating your CSR. Type the following command to install the Root certificate file:. You will get a confirmation stating that the "Certificate was added to keystore". Install the Primary or the Domain Certificate file Type the following command to install the Primary certificate file:.

If you want to trust the certificate, then choose y or yes. Your Certificates are now installed to your keystore file sdp. Copy the sdp. From the command prompt, execute changeWebServerPort. Finally, update the name of the keystore and the password, you gave in Step 1, while generating sdp. If you want to trust the certificate, then choose y or yes.

Your Certificates are now installed to your keystore file sdp. Configuring the Server in version and above. Configuring the Server in versions below For versions earlier than For versions Install a. P7b Certificate. Some CA will provide the certificates with an extension.

In such a case you can double click on this file to open a console which will list all the required certificates. You can export these certificates to Base encoded X. Go to [ServiceDesk Plus Home] jre bin domain.

Select the export file format as Base encoded X. Click Next. The certificate export wizard is completed successfully. You can check for the settings you have specified. Click Finish. Commands to install certificates of some common vendors. Note: These instructions might change depending on the Certificates issued by the CA. Answer : This could be because the Java version used in the application does not support the algorithm used to encrypt the password in the.

Follow the steps given below for the suggested workaround:. Import the SSL certificate to your machine as instructed here. Export the same using Microsoft Management Console as. Learn how to do this here. Use the new.

When importing domain certificate in keytool, an error stating Failed to establish chain from reply occurs as shown below:. Answer : Check if the keytool in the Java version used in the application supports the signature algorithm used in the certificates root, intermediate, and domain. The suggested workaround is to get new root, intermediate, and domain certificates that use algorithms supported by the Java version used in the application.

If you cannot get new certificates, use the same keystore and certificate with a keytool provided by a Java version that supports the signature algorithm to import the domain certificate. UI import of the keystore generated using a Java version different from that of the application would fail. Click here for steps to create and import the SSL certificate to the keystore.

Importing the. The following exception trace was found in importssl0 log file:. Answer : This could be because the java version used in the product does not support the key size. In other words, the certificate could have been generated from a different java version of a different key size. Download the policy files for ServiceDesk Plus from the below links:. For builds below version For builds above version

