API Gateway uses private keys in the keystore for signing messages, SSL/TLS communication, and JWT generation. When a certificate associated with a private key is nearing expiry, it must be renewed. This article provides the procedure to renew the private key while maintaining the existing alias name to avoid reconfiguring policies that reference that specific alias.
This is a "How To" article for a maintenance procedure; no technical fault is associated with this request.
To renew a private key and maintain the same alias without disrupting policy references, follow these steps:
Preparation
Replacement Procedure
Cluster Synchronization (Mandatory)
# service ssg restart