lhmathys Posted March 20, 2013 Posted March 20, 2013 Hello! I have an SSL certificate issued from GoDaddy that I've imported into the ISY 994i Pro using the new dashboard. However, the ISY is still not using my certificate when I open the java admin console. The console gives me a warning dialog that tells me that the ISY is using a default SSL certificate and it is a security risk. What have I missed? Thanks for the help! Larry
Michel Kohanim Posted March 20, 2013 Posted March 20, 2013 Hi Larry, Can you tell me: 1. Was the certificate in PKCS12 format? 2. Did you import it for Server or Client? With kind regards, Michel
lhmathys Posted March 20, 2013 Author Posted March 20, 2013 Hi Michel, 1. As far as I know, all certificates from GoDaddy are PKCS12 2. I did the import from the Network dialog, clicked the "CA Certificates" button, then used the "CA Certificates" dialog to import my certificate. Note: I used GoDaddy's bundle certificate which should give the entire certificate chain. Thanks for the help! Larry Hi Larry, Can you tell me: 1. Was the certificate in PKCS12 format? 2. Did you import it for Server or Client? With kind regards, Michel
Michel Kohanim Posted March 20, 2013 Posted March 20, 2013 Hi Larry, CA Certificates are those that ISY uses in case you check the "Verify" button for Client/Server settings. This means that ISY will expect the other party respond with a valid certificate the path to which ends with a CA certificate you imported. What you want to do instead is: Network, click on Server Certificate, then click on the Import Cert. button and point it to your GoDaddy certificate. With kind regards, Michel
lhmathys Posted March 20, 2013 Author Posted March 20, 2013 I think you're right - rather than re-key my certificate, I just imported the certificate without creating a new CSR. I'll just re-key the certificate and go from there. Larry
lhmathys Posted March 20, 2013 Author Posted March 20, 2013 Well this is new - how do I delete a client certificate? I don't see that anywhere... Regards, Larry
Michel Kohanim Posted March 21, 2013 Posted March 21, 2013 Hi Larry, For security reasons we had to remove that function. Can you please send an email to support and we'll send you the instructions. With kind regards, Michel
Recommended Posts