Hello experts,
we often face some troubles with https-calls out of pi (7.11). And it's still not clear to me if it is always necessary to import all certificates
of a https address. I thought it should be enough to import only the chain above a server certificate. For example:
Shouldn't it be enough to import the Thawte SSL CA and the root?
Another problem is, that we sometimes need to restart the as java nodes, to get imported certs to be kind of "activated".
I think this shouldn't be so, but it is...
Is there any document or website explaning the kind of keystore topics (howto) in detail.
What is needed to be imported, when do we need a restart etc.?
Thanks in advance.
Kind regards
Markus
Request clarification before answering.
Hello Markus,
You have to import all certificates. You have to start with the Primayr Root CA, then the SSL CA and then the techsupport.endress.com. It is important to keep the sequence.
Looking at this thread I think it is safer to restart: http://scn.sap.com/thread/2063256
Sorry, I do not know about any document describing this in detail but there are numerous threads on scn on that topic.
Best regards,
Peter
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.