cancel
Showing results for 
Search instead for 
Did you mean: 

Renew SSL cert changing key length to 2048 bits without downtime

suzy_bijnens
Active Participant
0 Kudos

Hi gurus,

Since 01.01.2011 a key length of 2048 bits is required for SSL certificates. I need to renew our Entrust certificates, but our system is set up for key lengths of 1024 bits.

I've changed the profile parameter sec/rsakeylengthdefault to 2048 and restarted the system. To let the setting take effect in STRUST, I have to replace PSE. Only then I can create a certificate request that is accepted by Entrust.

After dynamically changing the profile parameter to 1024 again, restoring the previous PSE does not seem to be possible (although the old certificate is not expired yet), I cannot import it as a certificate response any more.

This means, I cannot use this method in the productive system (buying a certificate and distributing it to our customers takes a week). The communication cannot go down for a week.

I can use windows to generate a certificate request with the required length, but I'm not sure that the certificate response can be uploaded in STRUST (after replacing PSE) without problems.

Can you please advice on this?

Thank you,

Suzy

Accepted Solutions (0)

Answers (1)

Answers (1)

marksmyth
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hello Suzy

I will forward this thread to the [Netweaver Administrator|; forum. You should get a better response to this query on that forum.

Regards

XI/PI Moderator

suzy_bijnens
Active Participant
0 Kudos

OK, thanks Mark.

Rgds,

Suzy