Self-signed SSL Certificate Installation (2024)

Pricing Get Quote

Email Download Link

Knowledge Base

Self Service Password Management » Knowledge Base

  • Free Edition
  • Quick Links
    • Get Quote
    • Extend Trial License
    • Online Demo
    • Request Support
    • Compare Edition
    • Success Stories
    • ROI Calculator
  • Password Self-Service
    • Self-service password reset
    • Self-service account unlock
    • Active Directory Change password
    • Password Expiration Notification
    • Password Policy Enforcer
    • Endpoint multi-factor authentication
    • Windows/macOS/Linux Logon Integration
    • Multi-factor Authentication
    • Windows Logon Two-factor Authentication
    • Remote Password Reset
    • Endpoint multi-factor authentication for macOS
    • Cached Credentials Update
    • Mobile Password Management
  • Documents
    • Help Documents
    • Success Stories
    • Video Zone
    • Knowledge Base
    • White Papers
    • Solution Briefs
  • Key Topics
    • Business Benefits of Self Service
    • Identity Password Management
    • ADSelfService Plus Screenshots
  • Related Products
    • ADManager Plus
    • ADAudit Plus Real-time Active Directory Auditing and UBA
    • Exchange Reporter Plus
    • EventLog Analyzer
    • M365 Manager Plus
    • DataSecurity Plus
    • RecoveryManager Plus Enterprise backup and recovery tool
    • SharePoint Manager Plus SharePoint Reporting and Auditing
    • AD360
    • Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
    • AD Free ToolsActive Directory FREE Tools

Self-signed(Internal CA) SSL certificates for ADSelfService Plus can be applied in five steps. They are:

Step 1: Enable SSL in ADSelfService Plus

  • Log in to ADSelfService Plus with admin credentials.
  • Navigate to Admin tab → Product Settings → Connection.[Refer image]
  • Select Enable SSL Port [HTTPS] checkbox.
  • Click Save and restart ADSelfService Plus.
  • Note: The default port for https connection in our application is 9251.

Step 2: Generate a CSR file

  • Start ADSelfService Plus and login as admin.
  • Again, navigate to Admin → Product Settings → Connection.
  • Click SSL Certification Tool button.
  • In the SSL Tool & Guide page that opens up, enter all the mandatory fields. [Refer image]
  • Provide a value for the validity of the certificates in days(optional).
  • Update the value for Public Key Length as 2048 bits(recommended).
  • Click Generate CSR.
  • Two files namely SelfService.csr and SelfService.keystore will be created.
  • Note: The two files will be created at different locations.
    • SelfService.csr at <installation directory>webapps\adssp \Certficates\SelfService.csr
    • SelfService.keystore at <installation directory>jre\bin

Step 3: Submit the CSR to your certificate authority

  • Log in to Microsoft Certificate Services (https:\\server-name\certsrv).
  • Click Request a Certificate → Advanced Certificate Request.[Refer image]
  • Click Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file.
  • Paste the contents of your SelfService.csr file in the Saved Request field.[Refer image]
  • It's always recommended to open the CSR file from its native location using a text editor rather than opening from the browser.
  • When you copy the contents of SelfService.csr file, please ensure that no additional space from the end of the file is also copied along with it.
  • Set the certificate template as Web Server and click Submit.
  • In the Certificate Issued page that appears, select DER encoded. [Refer image]
    • Click Download certificate to download the certificate in CER file format.
    • Click Download certificate chain to download the certificates in a P7B file format,
  • Place the certificate files at <Install Directory>\jre\bin.
  • Note: Convert your certificate from CER to P7B format. Follow the steps given here.

Step 4: Import the CA signed Internal certificates to the keystore

  • Open an elevated command prompt and navigate to <Install Directory>\jre\bin.
  • Back up the SelfService.keystore file.
  • Execute the following command to import the internal certificate to keystore file :
    • Keytool -import -alias tomcat -trustcacerts -file certnew.p7b -keystore selfservice.keystore
  • Execute the following command to add your internal CA's root file to the list of trusted CAs in the Java cacerts file:
    • keytool -import -alias tomcat -keystore ..\lib\security\cacerts -file certnew.cer
  • Note: Use "changeit" as the password when you install the Chain Certificate.

Step 5: Bind the certificate with ADSelfService Plus

  • Copy the SelfService.Keystore file to <Install Directory>\conf.
  • Back up the server.xml and web.xml files.
  • Edit the server.xml file (at <Install Directory>\conf) by replacing the values of the following SSL connector tags :
    • "keystoreFile" with "./conf/SelfService.keystore".
    • "keystorePass" with the password you entered while generating CSR.
    • Eg: <Connector SSLEnabled="true" acceptcount="100" clientauth="false" connectiontimeout="20000" debug="0" disableuploadtimeout="true" enablelookups="false" keystorefile="./conf/selfservice.keystore" keystorepass="keystore_password" maxsparethreads="75" maxthreads="150" minsparethreads="25" name="SSL" port="9251" scheme="https" secure="true" sslprotocol="TLS" sslprotocols="TLSv1,TLSv1.1,TLSv1.2"> <connector>
  • Restart ADSelfService Plus and check if the certificates are installed correctly.

Request for Support

Need further assistance? Fill this form, and we'll contact you rightaway.

Highlights

Password self-service

Free Active Directory users from attending lengthy help desk calls by allowing them to self-service their password resets/ account unlock tasks.Hassle-free password change for Active Directory users with ADSelfService Plus ‘Change Password’ console.

One identity with Single sign-on

Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications with their Active Directory credentials. Thanks to ADSelfService Plus!

Password/Account Expiry Notification

Intimate Active Directory users of their impending password/account expiry by mailing them these password/account expiry notifications.

Password Synchronizer

Synchronize Windows Active Directory user password/account changes across multiple systems, automatically, includingOffice 365, G Suite, IBM iSeries and more.

Password Policy Enforcer

Ensure strong user passwords that resist various hacking threats with ADSelfService Plus by enforcing Active Directory users to adhere to compliant passwords via displaying password complexity requirements.

Directory Self-Update &Corporate Search

Portal that lets Active Directory users update their latest information and a quick search facility to scout for information about peers by using search keys, like contact number, of the personality being searched.

« Home

Knowledge Base »

ADSelfService Plus trusted by

Embark on a journey towards identity security and Zero Trust

Password management Adaptive MFA Enterprise SSO Self-service & security Related products

  • Self-service password reset
  • Self-service account unlock
  • Web-based domain password change
  • Password expiration notifications
  • Password synchronization
  • Password policy enforcer
  • Cached credentials update
  • Reporting and auditing
  • Password self-service from logon screens
  • Mobile password management
  • Password security and compliance
  • Active Directory password audit
  • Active Directory MFA
  • Conditional access
  • Passwordless authentication
  • Two-factor authentication
  • Endpoint MFA
  • MFA for remote and local Windows logons
  • MFA for remote and local macOS and Linux logons
  • MFA for VPN and OWA logons
  • FIDO2 MFAC
  • MFA for UAC
  • Offline MFA
  • Device-based MFA
  • SAML SSO
  • OAuth and OIDC SSO
  • MFA for cloud apps
  • Passwordless authentication
  • Just-in-time provisioning
  • SIEM integration
  • ITSM integration
  • IAM integration
  • Self-service group management
  • Directory self-update
  • Employee search
  • Organization chart
  • Approval-based workflow for self-service
  • Post-action notifications
  • Security and its importance
  • Endpoint security
  • Active Directory FREE Tools
  • All Windows AD Tools
  • Active Directory Auditing
  • SharePoint Management and Auditing Solution
  • Real-time Log Analysis and Reporting Solution
  • Download

  • Live Demo
  • Compare Editions
  • Free Edition
  • Get Quote
  • Buy Now
Self-signed SSL Certificate Installation (2024)
Top Articles
How to manually configure WireGuard on Windows | Proton
3. Causes, risks and vulnerable groups
Automated refuse, recycling for most residences; schedule announced | Lehigh Valley Press
Top 11 Best Bloxburg House Ideas in Roblox - NeuralGamer
Matgyn
Hotels Near 625 Smith Avenue Nashville Tn 37203
Metra Union Pacific West Schedule
Satyaprem Ki Katha review: Kartik Aaryan, Kiara Advani shine in this pure love story on a sensitive subject
Myexperience Login Northwell
Devotion Showtimes Near Mjr Universal Grand Cinema 16
Seething Storm 5E
Lichtsignale | Spur H0 | Sortiment | Viessmann Modelltechnik GmbH
How to Watch Braves vs. Dodgers: TV Channel & Live Stream - September 15
Concacaf Wiki
litter - tłumaczenie słowa – słownik angielsko-polski Ling.pl
Osrs Blessed Axe
Richmond Va Craigslist Com
Rapv Springfield Ma
Walmart Windshield Wiper Blades
Cashtapp Atm Near Me
New Stores Coming To Canton Ohio 2022
Google Flights Missoula
Harem In Another World F95
Farmer's Almanac 2 Month Free Forecast
Craigslist Sparta Nj
Adt Residential Sales Representative Salary
Jc Green Obits
eugene bicycles - craigslist
Kitchen Exhaust Cleaning Companies Clearwater
Stockton (California) – Travel guide at Wikivoyage
Superhot Free Online Game Unblocked
Shoe Station Store Locator
Housing Intranet Unt
Angel del Villar Net Worth | Wife
Abga Gestation Calculator
Life Insurance Policies | New York Life
2430 Research Parkway
After Transmigrating, The Fat Wife Made A Comeback! Chapter 2209 – Chapter 2209: Love at First Sight - Novel Cool
Half Inning In Which The Home Team Bats Crossword
Lichen - 1.17.0 - Gemsbok! Antler Windchimes! Shoji Screens!
Usf Football Wiki
Kelley Blue Book Recalls
MSD Animal Health Hub: Nobivac® Rabies Q & A
Garland County Mugshots Today
Professors Helpers Abbreviation
8 4 Study Guide And Intervention Trigonometry
Marine Forecast Sandy Hook To Manasquan Inlet
Great Clips Virginia Center Commons
Grace Charis Shagmag
WHAT WE CAN DO | Arizona Tile
Latest Posts
Article information

Author: Manual Maggio

Last Updated:

Views: 6482

Rating: 4.9 / 5 (69 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Manual Maggio

Birthday: 1998-01-20

Address: 359 Kelvin Stream, Lake Eldonview, MT 33517-1242

Phone: +577037762465

Job: Product Hospitality Supervisor

Hobby: Gardening, Web surfing, Video gaming, Amateur radio, Flag Football, Reading, Table tennis

Introduction: My name is Manual Maggio, I am a thankful, tender, adventurous, delightful, fantastic, proud, graceful person who loves writing and wants to share my knowledge and understanding with you.