15.4 Configuring SSL Communication with Browsers and the Identity Server

  1. In Administration Console Dashboard, click Devices > Identity Servers > Edit.

  2. Change Protocol to HTTPS (the system changes the port to 8443).

  3. In the SSL Certificate line, click the Browse icon > Replace and select the Identity Server certificate.

  4. Restart Tomcat.

    If your Identity Server and Administration Console are on the same machine, log in to Administration Console again.

  5. After the Identity Server health turns green, go to Access Gateway > Edit > Service Provider Certificates > Trusted Roots.

  6. Click Add to select the trusted root certificate of the certificate authority that signed Identity Server certificate.

    (Conditional) If you imported intermediate certificates for the CA, select them also.

    IMPORTANT:If the external certificate authority writes the DN in reverse order (the cn element is displayed first), you receive an error message that the certificate names do not match. You can ignore this warning, if the order of the DN elements is the cause.

  7. Update Access Gateway.