Browser cert not migrated after upgrading.
search cancel

Browser cert not migrated after upgrading.

book

Article ID: 385314

calendar_today

Updated On:

Products

Data Loss Prevention Core Package

Issue/Introduction

After upgrading, a custom browser keystore <certname>.jks was not migrated. 

Environment

Browser certificate previously imported into <custom keystore name>.jks

Cause

If, when a browser certificate is made and imported into a keystore named anything other than .keystore, the new keystore will not be migrated, as only .keystore is migrated. 

  • While it can be made to work, changing the keystore name to import your browser certificate is not supported. 

Resolution

Solution 1:

Manually move your custom browser keystore and restart services.

 

Solution 2(recommended):

  • Relocate the existing .keystore file typically located in ../tomcat/conf/ 
  • Manually move the keystore from the previous installation to /tomcat/conf
  • Rename the newly moved keystore to .keystore
  • Correct Protect.properties to point to this keystore
  • This will prevent future upgrades from failing at this step. 

 

Additional Information

Documented instructions to keep .keystore file named as .keystore. 

Generating a unique browser certificate

"

  • The -keystore parameter specifies the name and location of the keystore file which must be 
    .keystore located in this directory. This is specified by using 
    -keystore .keystore"