Enable customer-signed SSL certificates
Certificate file location
It is advisable to keep the cert files (.crt/.key) in /etc/pki/tls/certs/ custom folder. The configuration script allows for this place to be different but if it is not here, it will not be backed up on upgrade.
Configuration file
The configuration file which is used for this process is /usr/bin/certs/certs.conf.
It needs to be updated with user’s custom values for the correct certs to be added.
Sample file:
Configuration script
The script that does the configuration is /usr/bin/certs/add-https-certs.sh.
Running just the script without any arguments will give possible actions.
Usage:
Actions:
Once the configuration file has been updated, run the script:
Progress will be displayed on the CLI. If successful, there is no need to do anything else, the certs will be in place and in use.
The HTTPS port used is 31443, so to see certs once added use: https://myunitIP.com:31443
As well as configuring the HTTPS web access the same certificate also configures HTTPS packaged output, see HTTPS Packaged Output.