When configuring an External Administrator Store using admin ui wizard, gets error on screen:
"An error occurred while updating the list of trusted CA certificates. Please ensure the trusted certificate you are using is valid. If the problem persists, check the error logs for additional details."
Click on Show Certificates, nothing is there.
Release : 12.8
Component : SITEMINDER WAM UI
Import new root CA:
keytool -import -trustcacerts -alias <alias> -keystore /opt/siteminderui/siteminder/adminui/standalone/configuration/trustStore.jks -file <RootCA.cer>
List keystore to check it is there:
keytool -list -v -keystore /opt/siteminderui/siteminder/adminui/standalone/configuration/trustStore.jks -storepass changeit
Keystore type: jks
Keystore provider: SUN
Your keystore contains 1 entry
Alias name: rootca
Creation date: May 18, 2020
Entry type: trustedCertEntry
Owner: CN=dc-LOD, DC=dc, DC=com
Issuer: CN=dc-LOD, DC=dc, DC=com
Serial number: 1dbc9821.......
Valid from: Thu Sep 26 11:30:03 PDT 2019 until:......
Certificate fingerprints:
MD5: FA:70:03:69:B5:6E:5B:A6:2F:22:A3:........
...
Signature algorithm name: SHA256withRSA
Subject Public Key Algorithm: 2048-bit RSA key
Version: 3
Extensions:
...
If after steps above, you get a different error " A connection to the LDAP directory 'ad.demo.com:636' could not be established for user 'ad_service_account', please check the connection details and try again."
That is a defect fixed in 12.8sp4, adminui needs an upgrade.
https://techdocs.broadcom.com/us/en/symantec-security-software/identity-security/siteminder/12-8/release-notes/known-issues/known-issues-for-policy-server.html
https://knowledge.broadcom.com/external/article/57273/the-root-ca-for-our-company-active-direc.html
https://knowledge.broadcom.com/external/article?articleId=136378
https://ca-broadcomcsm.wolkenservicedesk.com/wolken/esd/knowledgebase_search?articleId=211488