This documentation supports the 11.3 version of BMC Discovery.

To view an earlier version of the product, select the version from the Product version menu.

Replacing a default Certificate Authority bundle

The Certificate Authority (CA) bundle is required when using Web Authentication (SSO). You must upload a list of PEM-encoded X.509 public certificates for each root and intermediate Certificate Authority in the chain in order for clients to be successfully verified. 

To replace a default CA

  1. From the main menu, click the Administration icon 
    The Administration page opens. 
  2. In the Security section, click HTTPS .
  3. On the HTTPS Configuration page, click Upload in the CA Certificates row.
  4. Click Browse next to CA Certificate Bundle File and select the certificate bundle returned by the certificate signing authority.
  5. Click Apply.
    The new certificate bundle is uploaded.


If you are using Microsoft Certificate Services, you must use the Download CA certificate chain option with Base 64 encoding. This produces a PKCS #7 encoded file (.p7b) that is automatically converted to the correct format during the upload.

Was this page helpful? Yes No Submitting... Thank you