Procedure steps: 1. Get keystore passowrd 2. Rename existing keystore file 3. Generate new keystore with "Citi" required paramaters 4. Submit CMP to get your self created certificated signed/validated by Citi cert process 5. Import Citi prod certificates and your new signed certificate into U4V keystore 6. Cycle U4V to bring in new keystore and validate all works (be sure U4V shortcut is using FQDN or server name not localhost or IP address) 1. Get keystore passowrd ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Look in file domain.xml in directory (D drive in NAM) C:\Unisphere for VMAX\EMC\SMAS\jboss\domain\configuration Open with wordpad and search for @keystore Edit APACSGU4V04.apac.nsroot.net@Keystore-2 to the password in domain.xml (for example APACSGU4V04.apac.nsroot.net@Keystore-2) 2. Rename existing keystore file --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Rename keystore to kerystore.orig in directory cdstandalone\configuration 3. Generate new keystore with "Citi" required paramaters --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Edit 164176 to CSIID/Application ID associated with the U4V server (for example NAM SAN 149141) Edit Singapore to location of the server (Georgetown for example) Edit SG to state/province (two letters uppercase) Edit SG to country (two letters uppercase like US) Edit APACSGU4V04.apac.nsroot.net to the fully qualified domain name of the U4V server (namgemc01.nam.nsroot.net for example) Edit APACSGU4V04 to the U4V server name (namgemc01 for example) Edit C:\temp to target directory for output of self generated cert file (for example D:\temp) Open a command prompt and change to the following directory. D: cd Program Files\EMC\SMAS\jre\bin Run the following 4 commands to regenerate tomcat and U4V keystore entries along with outputing your self signed file (last command just lists whats in your new keystore) keytool -genkeypair -alias tomcat -keyalg RSA -sigalg SHA512withRSA -keysize 2048 -validity 3650 -ext bc=ca:true -dname "CN=APACHKIADU4V04.apac.nsroot.net, OU=164176, O=Citigroup\ Inc., L=Hong\ Kong, ST=HK, C=HK" -keypass APACHKIADU4V04.apac.nsroot.net@Keystore-2 -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 keytool -certreq -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -alias tomcat -sigalg SHA512withRSA -file C:\temp\APACSGU4V04-self.csr -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 keytool -genkeypair -alias univmaxrestforwardingclient -keyalg RSA -sigalg SHA512withRSA -keysize 2048 -validity 36500 -ext bc=ca:true -dname "CN=univmaxrestforwardingclient, OU=CTD, O=EMC, L=HOPKINTON, ST=MA, C=US" -keypass APACHKIADU4V04.apac.nsroot.net@Keystore-2 -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 keytool -list -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 https://apachkiadu4v04:8443/univmax/ 4. Submit CMP to get your self created certificated signed/validated by Citi cert process ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Open CMP - Venafi MS-PKI On Demand Device Certificate - 163513 - Create/Revoke Certificate See main U4V document for CMP screenshots. You will need the contents from file C:\temp\APACSGU4V04-self.csr to copy into the CMP Note: If FQDN from target server in CMP is "not" all lowercase add lowercase FQDN and server name to CMP alias/alternate name list. 5. Import Citi prod certificates and your new signed certificate into U4V keystore ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- See main U4V document for reply to CMP screenshots. save ouptut from CMP reply as APACSGU4V04.csr copy APACSGU4V04.csr and directory "Citi Prod CAs Base64" to C:\temp on APACSGU4V04 a. Open a command prompt and change to the following directory b. Run the first command standalone as it will prompt you to reply "yes" to trust the root certificate (defalt is no and your keystore will be invalid if you reply no). c. The run the remaining 4 command together (last is just a keystore list command). keytool -import -alias root -trustcacerts -file "C:\temp\Citi Prod CAs Base64\CitiInternalRootCA_b64.cer" -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 keytool -import -alias intermiediate1 -trustcacerts -file "C:\temp\Citi Prod CAs Base64\CitiInternalPolicyCA_b64.cer" -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 keytool -import -alias intermiediate2 -trustcacerts -file "C:\temp\Citi Prod CAs Base64\CitiInternalDeviceCA03_b64.cer" -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 keytool -import -alias tomcat -trustcacerts -file C:\temp\APACHKIADU4V04.csr -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 keytool -list -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 6. Cycle U4V to bring in new keystore and validate all works (be sure U4V shortcut is using FQDN or server name not localhost or IP address) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Just FYI stuff below nothing else to do ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ (FYI) Sample delete command if you need to remove a bad keystore entry keytool -delete -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -alias tomcat -storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 (FYI) If everything just gets 100% messed up including trying to revert back to the original keystore you can run the following commands to rebuild the default keystore as it was delivered from EMC D: cd Program Files\EMC\SMAS\jre\bin keytool -genkeypair -alias tomcat -keyalg RSA -sigalg SHA512withRSA -keysize 2048 -validity 3650 -ext bc=ca:true -dname "CN=APACSGU4V04.apac.nsroot.net, OU=CTD, O=EMC, L=HOPKINTON, ST=MA, C=US" -keypass APACSGU4V04.apac.nsroot.net@Keystore-2 -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACSGU4V04.apac.nsroot.net@Keystore-2 keytool -genkeypair -alias univmaxrestforwardingclient -keyalg RSA -sigalg SHA512withRSA -keysize 2048 -validity 36500 -ext bc=ca:true -dname "CN=univmaxrestforwardingclient, OU=CTD, O=EMC, L=HOPKINTON, ST=MA, C=US" -keypass APACSGU4V04.apac.nsroot.net@Keystore-2 -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass APACSGU4V04.apac.nsroot.net@Keystore-2