2.5

Table Of Contents
Managing SSL Keys and Certificates 18
Data Director enables the Secure Sockets Layer (SSL) protocol for all components, including the Management
Server, the DB Name Server, and the DBVM. SSL secures both internal communications among components
and communications from customers who access the database externally.
By default, Data Director generates an SSL key and certificate for all components. System administrators can
replace the automatically generated key and certificate with a custom key and certificate. When you apply a
custom key and certificate, you cannot use the key and certificate that Data Director generated.
All key certificate pairs have a period of validity. The automatically generated pair expires after five years. To
ensure continued security of data and communications, system administrators must update certificates before
they expire.
Data Director currently supports only RSA keys and X509-formatted certificates. Supported keystore types
include JKS, JCEKS, and PCKS12.
This chapter includes the following topics:
n
“Regenerate Management Server Key and Certificate,” on page 181
n
“Import Management Server Key and Certificate,” on page 182
n
“Edit Management Server Certificate,” on page 183
n
“Regenerate DB Name Server Key and Certificate,” on page 183
n
“Import DB Name Server Key and Certificate,” on page 184
n
“Edit DB Name Server Certificate,” on page 184
n
“Regenerate DBVM Key and Certificate,” on page 185
n
“Import DBVM Key and Certificate,” on page 185
n
“Edit DBVM Certificate,” on page 186
Regenerate Management Server Key and Certificate
System administrators can regenerate the Management Server SSL key and certificate before it expires, to
ensure continuous security of communications.
Prerequisites
Verify that no custom key and certificate has been applied to the Management Server.
Procedure
1 Click System Settings.
2 Expand Other Settings and click Security.
VMware, Inc.
181