Change Certificates used by TrilioVault
The following TrilioVault services are providing certificates for secured access to the TrilioVault solution.
The TVault-Config service and the Nginx Resource for the Grafana Dashboard are using the same certificate.
The certificate used is a symlink to a host-specific certificate. Each TrilioVault VM has its own self-signed certificate by default which is getting recreated every time the TVault-Config service is restarted.
When the certificate for the TVault-Config and Nginx (Grafana) is to be changed to a customer chosen certificate it is required to deactivate the recreation of the certificates upon service restart.
- 1.Login into the TrilioVault VM via SSH
- 2.Edit the following file:
- 3.Look for create_ssl_certificates() in the main function
- 4.Comment out create_ssl_certificates()
- 5.Repeat for all nodes of the TrilioVault cluster
The resulting main function will look like this:
# configure the networking
http_thread = Thread(target=main_http)
http_thread.daemon = True # thread dies with the program
srv = SSLWSGIRefServer(host='::', port=443)
bottle.run(server=srv, app=app, quiet=False, reloader=False)
Afterward, the certificates can be replaced manually by overwriting the files.
Once the certificates have been replaced by the desired ones restart the TVault-Config service and the Nginx pcs resource.
The certificate provided by the Nginx for the wlm-api service is set during configuration when HTTPS endpoints are configured for the TrilioVault appliance. This certificate is provided to the end-user or Openstack every time an API call to the TrilioVault solution is sent.
The certificate and its related private key can be changed through the OS API certificate tab.
In this tab is the section to Upload Server certificate | Private key. Use this section to update the wlm-api certificate as required.
Upload Server certificate | Private key block