CAPKI requirement For Service Manager 12.3x

book

Article ID: 197722

calendar_today

Updated On:

Products

CA Automic Workload Automation - Automation Engine CA Automic Workload Automation - Automation Engine

Issue/Introduction

Is it required to install CAPKI for Service Manager 12.3x?
We understand Information security services, such as the TLS implementation of the ServiceManager, require features provided by the CAPKI package. You need to install CAPKI on all computers in which the Automation Engine Server Processes or the ServiceManager and any of its clients will run.
However, if we plan not to use TLS, do we still need to install CAPKI?

Environment

Release : 12.3

Component : AUTOMATION ENGINE

Resolution

As verified by our Product Management:

The documentation for CAPKI - Securing the Service manager states 
You can configure the compatibility of the Automation Engine using the SMGR_SUPPORT_LEGACY_SECURITY parameter in the UC_SYSTEM SETTINGS variable
which enables compatibility with legacy ServiceManagers for version prior to 12.2.0 (TLS 1.2).


If you install the 12.3 Service Manager without the CAPKI, the new ServiceManager Dialog Program has an indicator which visualizes whether it is connected to a secure or a legacy (insecure) ServiceManager
It will still work, it will just say it is not a secure connection

Additional Information

https://docs.automic.com/documentation/webhelp/english/AA/12.3/DOCU/12.3/Automic%20Automation%20Guides/help.htm#ServiceManager/CAPKI.htm