Home > 8e6 R3000 Certificate Migration

8e6 R3000 Certificate Migration

Tags:  


Background:


The following instructions are important when migrating or upgrading between different R3000 models. A reminder that 8e6 does NOT support use of backup/restore mechanism for upgrading between different R3000 models (use synchronization instead -- with caveats). The SSL certificates used for web-based authentication must be manually migrated -- instructions below.

Specifics:

Back up the following two files via R3000 command-line:

  • /usr/local/shadow/etc/server.pem

  • /usr/local/shadow/etc/serverkey.pem

Note: The locations for these two files are defined in the Apache server configuration file:

  • /usr/local/shadow/www/conf/block_httpd.conf

8e6 does not allow the GUI to 'upload the key'. The normal mechanism for creating a commercial certificate is to issue the CSR from the R3000 itself through the System->Authentication->Authentication SSL Certificate->Third Party Certificate path.

Final Step -- restart services:

The final step is to restart the R3000 services. Execute the following on R3000 command-line as user 'root':

  • kill.R3000

Note: this custom 8e6 command will terminate all R3000 processes. The 8e6 "watchdog" scripts -- automatically executed via cron -- will identify services are down and restart everything. This typically take couple minutes. You can watch progress with 'top' command.



 RSS of this page