Changing security certificates on Synthetic TEA Agents
By default, TEA Agents use pregenerated, self-signed certificates for authentication with App Visibility Manager. You can use your own custom certificates.
You can update certificates before installing your TEA Agents, or you can update certificates on TEA Agents that are already installed.
- To update certificates before installing TEA Agents, follow the instructions in To create the custom certificate folder in the TEA Agent installer.
- To update certificates for previously installed TEA Agents, follow the instructions in To replace security files on previously installed TEA Agents.
This topic contains the following sections:
Before you begin
Install the TEA Agent.
- Prepare the following files and place them in a folder that is accessible to your TEA Agent computer:
- keystoreFileName.jks, where keystoreFileName is your custom keystore file name
- truststoreFileName.jks, where truststoreFileName is your custom truststore file name
To create the custom certificate folder in the TEA Agent installer
This procedure creates the ..\Disk1\files\security\custom folder. The custom certificate is then included in your TEA Agent installation. The files are also used by the installer and the other utilities on the TEA Agent for communicating with App Visibility components.
- From the ..\Disk1\utility\ReplaceCertificateTool folder of your TEA Agent installer files, right-click the ReplaceCertificateTool batch file and select Run as administrator.
- Enter 1 to select Create Certificate folder with the encrypted passphrase.
Enter the required parameters:
The [liveData] macro is a standalone macro and it cannot be used inline. Click on this message for details.The certificate replacement utility:
- Creates the ..\Disk1\files\security\custom folder
- Creates .pem files for the TEA Agent
- Encrypts the keystore passphrase
- Creates the cert.properties file with the new .jks files, .pem files, and encrypted keystore passphrase
- Puts the .pem files, .jks files, and cert.properties file in the custom folder
- (Recommended) Perform the procedure in To test the connection to your App Visibility portal.
To test the connection to your App Visibility portal
Perform the following test to check the connection to your App Visibility portal using the certificates in the ..\Disk1\files\security\custom folder.
- From the ..\Disk1\utility\ReplaceCertificateTool folder of your TEA Agent installer files, right-click the ReplaceCertificateTool batch file and select Run as administrator.
- Enter 2 to select Test connection to App Visibility.
Enter the required parameters or press Enter to accept the default values:
The [liveData] macro is a standalone macro and it cannot be used inline. Click on this message for details.The certificate replacement tests the connection with the App Visibility portal.
To replace security files on previously installed TEA Agents
- If you are running the TEA Agent as a process, stop the TEA Agent process. See Starting-and-stopping-a-synthetic-TEA-Agent-as-a-process for more details.
- If you have not created the custom certificate folder, perform the steps in To create the custom certificate folder in the TEA Agent installer.
- From the ..\Disk1\utility\ReplaceCertificateTool folder of your TEA Agent installer files, right-click the ReplaceCertificateTool batch file and select Run as administrator.
- Enter 3 to select Apply custom certificate to TEA Agent.
Enter the required parameter or press Enter to accept the default values:
The [liveData] macro is a standalone macro and it cannot be used inline. Click on this message for details.The certificate replacement utility:- Stops the TEA Agent service
- Copies the .pem files and .jks files from the ..\Disk1\files\security\custom folder to your TEA Agent working folder
- Updates the cert.properties file with your new certificates
- Restarts the TEA Agent service
- If you run the TEA Agent as a process, stop the TEA Agent service (which was started automatically by the certificate replacement utility), and restart the TEA Agent process. See Starting-and-stopping-a-synthetic-TEA-Agent-as-a-process for more details.
To encrypt a keystore passphrase
Use this procedure to encrypt your TEA Agent passphrase if you want to build a cert.properties file manually.
- From the ..\Disk1\utility\ReplaceCertificateTool folder of your TEA Agent installer files, right-click the ReplaceCertificateTool batch file and select Run as administrator.
- Enter 4 to select Keystore passphrase encryption only.
Enter the required parameter:
The [liveData] macro is a standalone macro and it cannot be used inline. Click on this message for details.The certificate replacement tool displays the encrypted passphrase. Copy the passphrase and paste it where you need it.
Related topics
Security planning for Presentation Server
Starting-and-stopping-services
Changing-security-certificates-in-App-Visibility-componentsReplacing security certificates in BMC PATROL for Application Management 10.5