During this task we will upload a CA provided or self-signed certificate.
Certificates must be uploaded to Access Gateway before they can be associated with applications.
To upload a certificate.
- Use SSH connect to the Access Gateway Management console.
See Command Line Management Console reference for a complete list of command line console commands.
- Enter 2 to go to the Services sub-menu.
- Enter 1 to go to the NGINX sub-menu.
- Enter 6 to update an SSL certificate.
All existing certificates will be displayed and will resemble:
Available Certificates: -----------------------  admin.crt  gateway_info.crt  localhost.crt . . . [a] Add new certificate [x] Exit [#, a, x]:
- Select a command to perform:
- x - Exit the add/modify certificates sub-menu.
- a - Add a new certificate.
- # - Modify an existing certificate.
You can add certificates using cut and paste operations.
Both the certificate and the key must be in Privacy Enhanced Mail (PEM) format.
Depending on your OS, the command sequence for copy and paste operations may be different.
This applies only to copy and paste operations and not completing the entry of certificate contents.
- In a text editor, open the new certificate file.
- Within the editor, select and copy the contents of the certificate file.
- Return to the command line console and paste the certificate file contents.
- Press Ctrl + d to save the certificate contents.
The command line console will open a new editor for the certificates associated key contents.
- In a text editor, open the key file.
- Within the editor, select and copy the contents of the key
- Return to the command line console and paste the key file contents.
- When complete, press Ctrl + d to save the key contents.
The hostname and certificate type are pulled automatically for the certificate.
If an existing certificate is being updated, a prompt stating A certificate for this domain already exists, do you wish to
replace it? [Y,N] appears. To proceed with the certificate update, press the y
followed by Enter.
When modifying an existing certificate, you are presented with three options:
- [d] - Delete certificate
- [u] - Update certificate
- [x] - Return without change.
To exit without change, enter x.
To update a certificate, enter u.
Follow the prompts to copy and paste the replacement certificates key and certificate file, both of which must be in PEM format.
To delete a certificate, enter d.
Follow the prompt to confirm the delete or cancel.