Skip To Content

Replace the ArcGIS Data Store SSL certificate

When you create a data store, the Data Store Configuration wizard accesses ArcGIS Data Store using a self-signed SSL certificate. Similarly, when the hosting server communicates with the data store, or individual machines within the data store communicate with each other, a self-signed SSL certificate is used. This is sufficient for most organizations. Some organizations, however, require all interactions be secured through an SSL certificate verified and signed by a certifying authority (CA) or one generated for their own domain. Such organizations can use the updatesslcertificate utility to replace the self-signed certificate with a CA-signed or domain certificate after configuring a data store on a machine.

The certificate file must be in PKCS12 format with a file extension of .pfx or .p12, and you must import it to ArcGIS Data Store.

Follow these steps to update the SSL certificate on a single ArcGIS Data Store machine:

  1. Obtain an SSL certificate from a certifying authority or generate a domain certificate.
  2. Create a PKCS12 format file and set a password and alias for the file.
  3. Run the updatesslcertificate utility to replace the self-signed SSL certificate for an ArcGIS Data Store machine.

    In this example, the certificate file, casignedcert.pfx, is in the tempfiles directory, has the alias myfilealias, and is secured with the password Sec00rit.

    ./updatesslcertificate.sh /usr/tempfiles/casignedcert.pfx "Sec00rit" myfilealias

  4. If you have multiple ArcGIS Data Store machines, update the certificate for each one.

Verify you can access the Data Store Configuration wizard

Open a browser and type the URL to the Data Store Configuration wizard. The URL is in the format https://<fully qualified data store machine name>:2443/arcgis/datastore. If the wizard opens without returning a security warning, the SSL certificate was successfully updated.