Procedure steps: 1. Get keystore passowrd 2. Rename existing keystore file 3. Generate new keystore with "Citi" required paramaters 4. Submit CMP to get your self created certificated signed/validated by Citi cert process 5. Import Citi prod certificates and your new signed certificate into U4V keystore 6. Cycle U4V to bring in new keystore and validate all works (be sure U4V shortcut is using FQDN or server name not localhost or IP address) 1. Get keystore passowrd ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Look in file domain.xml in directory (D drive in NAM) D:\Program Files\EMC\SMAS\jboss\domain\configuration Open with wordpad and search for @keystore Edit to the password in domain.xml (for example @Keystore-2) 2. Rename existing keystore file --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Rename keystore to kerystore.orig in directory D:\Program Files\EMC\SMAS\jboss\standalone\configuration 3. Generate new keystore with "Citi" required paramaters --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Edit to CSIID/Application ID associated with the U4V server (for example NAM SAN 149141) Edit to location of the server (Georgetown for example) Edit to state/province (two letters uppercase) Edit to country (two letters uppercase like US) Edit to the fully qualified domain name of the U4V server (namgemc01.nam.nsroot.net for example) Edit to the U4V server name (namgemc01 for example) Edit to target directory for output of self generated cert file (for example D:\temp) Open a command prompt and change to the following directory. D: cd Program Files\EMC\SMAS\jre\bin Run the following 4 commands to regenerate tomcat and U4V keystore entries along with outputing your self signed file (last command just lists whats in your new keystore) keytool -genkeypair -alias tomcat -keyalg RSA -sigalg SHA512withRSA -keysize 2048 -validity 3650 -ext bc=ca:true -dname "CN=, OU=, O=Citigroup\ Inc., L=, ST=, C=" -keypass -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass keytool -certreq -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -alias tomcat -sigalg SHA512withRSA -file \-self.csr -storepass keytool -genkeypair -alias univmaxrestforwardingclient -keyalg RSA -sigalg SHA512withRSA -keysize 2048 -validity 36500 -ext bc=ca:true -dname "CN=univmaxrestforwardingclient, OU=CTD, O=EMC, L=HOPKINTON, ST=MA, C=US" -keypass -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass keytool -list -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass 4. Submit CMP to get your self created certificated signed/validated by Citi cert process ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Open CMP - Venafi MS-PKI On Demand Device Certificate - 163513 - Create/Revoke Certificate See main U4V document for CMP screenshots. You will need the contents from file \-self.csr to copy into the CMP Note: If FQDN from target server in CMP is "not" all lowercase add lowercase FQDN and server name to CMP alias/alternate name list. 5. Import Citi prod certificates and your new signed certificate into U4V keystore ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- See main U4V document for reply to CMP screenshots. save ouptut from CMP reply as .csr copy .csr and directory "Citi Prod CAs Base64" to on a. Open a command prompt and change to the following directory b. Run the first command standalone as it will prompt you to reply "yes" to trust the root certificate (defalt is no and your keystore will be invalid if you reply no). c. The run the remaining 4 command together (last is just a keystore list command). D: cd Program Files\EMC\SMAS\jre\bin keytool -import -alias root -trustcacerts -file "\Citi Prod CAs Base64\CitiInternalRootCA_b64.cer" -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass keytool -import -alias intermiediate1 -trustcacerts -file "\Citi Prod CAs Base64\CitiInternalPolicyCA_b64.cer" -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass keytool -import -alias intermiediate2 -trustcacerts -file "\Citi Prod CAs Base64\CitiInternalDeviceCA01_b64.cer" -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass keytool -import -alias tomcat -trustcacerts -file \.csr -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass keytool -list -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass 6. Cycle U4V to bring in new keystore and validate all works (be sure U4V shortcut is using FQDN or server name not localhost or IP address) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Just FYI stuff below nothing else to do ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ (FYI) Sample delete command if you need to remove a bad keystore entry keytool -delete -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -alias intermiediate3 -storepass keytool -delete -keystore "C:\Unisphere for VMAX\EMC\SMAS\jboss\standalone\configuration\keystore" -alias intermiediate3-storepass APACHKIADU4V04.apac.nsroot.net@Keystore-2 (FYI) If everything just gets 100% messed up including trying to revert back to the original keystore you can run the following commands to rebuild the default keystore as it was delivered from EMC D: cd Program Files\EMC\SMAS\jre\bin keytool -genkeypair -alias tomcat -keyalg RSA -sigalg SHA512withRSA -keysize 2048 -validity 3650 -ext bc=ca:true -dname "CN=, OU=CTD, O=EMC, L=HOPKINTON, ST=MA, C=US" -keypass -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass keytool -genkeypair -alias univmaxrestforwardingclient -keyalg RSA -sigalg SHA512withRSA -keysize 2048 -validity 36500 -ext bc=ca:true -dname "CN=univmaxrestforwardingclient, OU=CTD, O=EMC, L=HOPKINTON, ST=MA, C=US" -keypass -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass =================== ldnctispa001.eur.nsroot.net@Keystore-2 keytool -list -keystore "D:\Program Files\EMC\SMAS\jboss\standalone\configuration\keystore" -storepass ldnctispa001.eur.nsroot.net@Keystore-2 D:\Program Files\EMC\SMAS\jre\bin>keytool -list -keystore "D:\Program Files\EMC\ SMAS\jboss\standalone\configuration\keystore" -storepass ldnctispa001.eur.nsroot .net@Keystore-2 Keystore type: JKS Keystore provider: SUN Your keystore contains 2 entries tomcat, Oct 27, 2015, PrivateKeyEntry, Certificate fingerprint (SHA1): 00:D3:6E:91:55:93:5A:23:D5:55:3C:02:65:09:B0:4E: D2:85:28:DC univmaxrestforwardingclient, Oct 27, 2015, PrivateKeyEntry, Certificate fingerprint (SHA1): C0:8C:AB:BF:9F:90:19:BF:3D:2E:57:79:40:1F:AE:BA: 3C:3B:41:02 D:\Program Files\EMC\SMAS\jre\bin>