IQService Certificates expiring

Which IIQ version are you inquiring about?

8.2p3

Please share any images or screenshots, if relevant.

Share all details about your problem, including any error messages you may have received.

We have our certificates on our two IQService servers that are going to be expiring on 8/22. I can’t find any good documentation on how to replace these, we’ve renewed Apache TomCat services but the IQService doesn’t have Apache tomcat running on it.

Do we know where these certs live on the IQService servers(01 and 02)? I’m looking to just generate a new .cer, .key and .pfx. This is our first time renewing these certs so we’re open to any help.

1 Like

Hi @colsmith,

About the certs on IQService you can follow this guide:
https://community.sailpoint.com/t5/IdentityIQ-Connectors/IQService-TLS-and-Client-Authentication-Configuration/ta-p/75273

basically you can install directly the new certs.

Also, if you have update Apache tomcat on UI/Task servers, remember to copy conf folder from the older installation. In this folder you have a file called server.conf and in there the path of certs. You can refer to this guide, Edit the Tomcat Configuration File section:
https://tomcat.apache.org/tomcat-9.0-doc/ssl-howto.html

It Really depends on how the company manage Certs.

you can simple create a request submit it to the AD team and they creat the certificate.
Just remember to have the same attributes as the expired one.

When you say install directly the new certs- what do you mean? We were not able to find the cert in the IIS Manager but we do see it in the Windows Certificate Manager on the local machine.

We’ve got a .pfx created with the password generated by the AD team - is there documentation on how to add this to the keystore for the IQService servers?

  1. IIS is running but there is no Certificate in IIS
  2. The IQService doesn’t utilize Apache Tomcat so is there an embedded software where the keystore exists? Unsure as to where the cert is placed in the IQService server.

It looks like those certs are for the hosting of SailPoint. That means only UI and Task servers will need the certs. The Database and IQService server, if they are separate, do not need those certs. But remember, when creating a cert, specify all the server names that are using SailPoint.

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.