Posted on 09-22-2011 08:00 AM
Hello all,
I recently got a certificate for my JSS server. I've tried to import it (seemed to work) and it even showed up in the JSS when I looked under servers. Clients however still could not connect to the JSS with this cert installed. I also had generated the CSR through server admin (I needed this as we use the JSS server to store our Full Disk Encryption keys and I needed SSL in place for it). Not sure if this would cause a problem.
I followed these instructions (other than the CSR part), but I'm questioning if this is out of date... http://www.jamfsoftware.com/kb/article.php?id=019
For 1 I noticed a Tomcat install in the /Library/JSS/Tomcat/ folder as opposed to the /Library/Tomcat/ folder. I tried working with both but could not get either to work. Can anyone confirm if these instructions are correct?
Brendon Cunningham
Senior Technical Analyst
Desktop Engineering
508-390-5620
brendon_cunningham at tjx.com
Posted on 09-22-2011 09:15 AM
You can use that certificate for websites served with the Apache ('web') service. The jSS is served with Tomcat which has its own security framework. Converting that certificate key pair is a bit of a hassle if you don't know what you're doing. It will likely be easier to have your SSL/PKI admin revoke that certificate and issue a new one based off of the CSR you create with the JAMF instructions.
JAMF's kb article you reference is correct. The file location may have changed with the recent 8.22 update and if you're on Lion server, but it's bang on procedurally.
j
---
Jared F. Nichols
Desktop Engineer, Client Services
Information Services Department
MIT Lincoln Laboratory
244 Wood Street
Lexington, Massachusetts 02420
781.981.5436
Posted on 09-22-2011 09:19 AM
Thanks I thought that might be the case. I found this on the web....
http://www.monkeymac.com/blog/ssl-cert-with-jss/
I believe this is what you are referring to with regards to the key pair, so I'm going to give it a go.
Brendon Cunningham
Senior Technical Analyst
Desktop Engineering
508-390-5620
brendon_cunningham at tjx.com