SSL Certificates in Portfolio

SSL Certificates in Portfolio

The process of getting a certificate involves creating a request file, sending the request to a Certificate Authority, receiving a certificate file in return, and then importing the certificate file.

Creating the Request

To create the request file:

  1. Click Global Settings, then click SSL Certificate.

  2. Click Create Certificate Request.

  3. Fill in the basic information:

    • Fully Qualified Domain Name: For the Portfolio server system (such as portfolio.example.com)

    • Organization Name: The name of your organization. This may be displayed on the server, but does not need to be a legal entity (“ExampleCorp” is OK, you don’t need to use “Example Corporation LLC”).

    • Organizational Unit: The name of the group within your organization responsible for the Portfolio server. This could be the same as the Organization Name.

    • City or Locality

    • State or Province

    • Two-letter Country Code

    • Subject Alternative Names: List here any additional hosts that you want to be covered by the same certificate. If you have multiple servers (Portfolio or any other web server), you can add their names here. You can also add different ways to address one server (IP address, DNS name, or LDAP Distinguished Name [dn] or Common Name [cn]). Separate individual entries with commas.

  4. Click Create. This will generate a .CSR file; when prompted to download the file, click OK.

    You can download the file at any time; click Download in the Certificate Status panel.

Obtaining your Certificate

Send the .CSR file to your Certificate Authority and request a PKCS12 bundle in .pfx or .p12 format for Tomcat or Apache

Importing your Certificate

The Certificate Authority will return a certificate file to you that you can import into Portfolio.

To import the certificate file:

  1. Click Global Settings, then click SSL Certificate.

  2. Click Import Certificate.

  3. Click Select and select your certificate file, then click Import.

When the import is complete, the Certificate Status page will update to show the new certificate.

Replacing an existing certificate

To replace a certificate, generate a new request and import the new certificate as you did in these instructions.

You will need to do this when your existing certificate expires.

    • Related Articles

    • Using a wildcard SSL Certificate for Portfolio

      If a certificate from Microsoft Certificate Manager is exported as a PKCS12 certificate file, with the entire certificate chain and the key pair in the file, keytool can convert it into a JKS keystore for Portfolio. To get the certificate alias for ...
    • Adding SSL for secure connections

      By default, Portfolio uses a self-signed certificate for secure client connections. You can request and add a signed certificate in Portfolio Administration, without resorting to the command line. This certificate allows secure (i.e., https) ...
    • Internet Access : Firewall + Reverse Proxy Considerations

      PortfolioDAM employees do not provide Firewall and / or Reverse Proxy configuration assistance. Contact your Corporate LAN / WAN Network Infrastructure Team for assistance with granting external ( Internet ) access to your Portfolio instance. Table ...
    • Portfolio checklist

      Use this checklist to help you make sure you are ready to install and configure Portfolio. License Administrator Be sure to have the Extensis account information (email address and password) for your Portfolio License Administrator. You need this ...
    • Portfolio Glossary

      Following are some terms used throughout Portfolio and its documentation. Some are technical (“computer”) terms that relate to Portfolio features and services, some are fundamental concepts within Portfolio, and some are terms that relate to Digital ...