Nexus Certificate Manager
8.15 8.14 8.13
8.15 8.14 8.13

Install Certificate Manager Web UI

This article describes how to install and configure the Web UI component in Smart ID Certificate Manager. 

See Certificate Manager Web UI communication flow for a detailed description of the communication between system components.

Prerequisites

Setup HERMOD with PWGY

  1. Verify that prerequisites required endpoints is configured and responding.

    1. CM SDK connectivity from PGWY to CM is working, server DNS is configured in TLS cert.

    2. Protocol Gateway (PGWY) ping responding https://<server-dns>:8443/pgwy/ping.

    3. Protocol Gateway (PGWY) api responding http://<server-dns>:8080/pgwy/swagger/swagger.yaml.

    4. Hermod health https://<server-dns>:20400/hermod/rest/ms.

    5. Create a Login & Signing Officer in CM

        1. Drag drop or Import the Officer.p12 to personal desktop app.

  2. Create Hermod Trust, Create Hermod TLS certificate and P12.

    1. Add Tls p12 in conf folder of tomcat - (path to add in server.xml of tomcat)
      Add boot and issuing CA cert to trust store JKS and java security
        keytool -importcert -alias bootcaB -cacerts -storepass changeit -file cacerts/<your_cert.cer>
        
      

Required Configurations

Open Ports 8080, 8443, 20400 and set connectors in Server.xml
HTML
<Connector port="8080" protocol="HTTP/1.1"
    connectionTimeout="20000"
    redirectPort="8443"
    maxParameterCount="1000"/>
  
<--- PWGY settings--->
<Connector port="8443"
	protocol="org.apache.coyote.http11.Http11NioProtocol"
	maxThreads="150" SSLEnabled="true">
<SSLHostConfig
	honorCipherOrder="true"
	ciphers="HIGH:!3DES:!DES:!SHA1:!SHA256:!SHA384:!SEED"
	protocols="TLSv1.3,TLSv1.2"
	truststoreFile="conf/new_tls.jks"
	truststorePassword="1234"
	certificateVerification="none">
<Certificate
	certificateKeystoreFile="conf/PGWYTLS.p12"
	certificateKeystorePassword="1234"
	certificateKeystoreType="PKCS12"
	type="RSA" />
</SSLHostConfig>
</Connector>
  
<--- HERMOD settings--->
<Connector port="20400"
	protocol="org.apache.coyote.http11.Http11NioProtocol"
	SSLEnabled="true"
	defaultSSLHostConfigName="localhost"
	maxThreads="150"
	scheme="https"
	secure="true">
 <SSLHostConfig
	hostName="localhost"
	sslProtocol="TLS"
	truststoreFile="conf/new_tls.jks"
	truststorePassword="1234"
	certificateVerification="none">
<Certificate
	certificateKeystoreFile="conf/hermodTLS.p12"
	certificateKeystorePassword="1234"
	certificateKeystoreType="PKCS12"/>
</SSLHostConfig>
</Connector>	


generate client details X-API-Key to add in application.yaml and auth.properties

Generate client details X-API-Key https://<server-DNS>:20400/hermod/rest/util/generateclient/pgwy-auth

Add to application yaml

  hermod:
    allowed-clients:
      # X-Api-Key: Y2xpZW50OjU1NmYxODI4NmM5NjQzMDY5MWJhN2VlYjJiODgzMmQ3NzExMjI1NTM5YTdmNDljMmEzMmVkZWNjM2Q0NjI4ZjI=
      - client-id: pgwy-auth
        key: 0e12b3a181c447f1b7d1745858d8583e197743db5663447a9cd99b5d7548b18c
        # Optional username:password to be supplied for basic authentication in callbacks
        # callback-basic-auth: username:password
        # The callback URL base for this specific client
        callback-url: https://<server-DNS>:8443/pgwy/auth/callback

Add Xapi key to auth.prop

Set start = true

default.authservice.apikey = x-api -key here
default.authservice.apiurl = https://<server-DNS>:20400/hermod/rest


Example configuration required for Application.yml
 ### application.yaml  ###   
location: \webapps\hermod\WEB-INF\classes\...
check these sections in appliucation yaml 
---------
server:
  port: 20400
  servlet:  
    context-path: /hermod
    
  ssl:
    # This could be false as ssl is handled in tomcat 20400 port https
    enabled: true 
    key-store: C:/Program Files/Apache Software Foundation/Tomcat 10.1/certificates/hermodTLS.p12
    key-store-password: "1234"
    key-store-type: PKCS12    
--------------
application:

  hermod:
    allowed-clients:
      # X-Api-Key: Y2xpZW50OjU1NmYxODI4NmM5NjQzMDY5MWJhN2VlYjJiODgzMmQ3NzExMjI1NTM5YTdmNDljMmEzMmVkZWNjM2Q0NjI4ZjI=
      - client-id: pgwy-auth
        key: 0e12b3a181c447f1b7d1745858d8583e197743db5663447a9cd99b5d7548b18c
        # Optional username:password to be supplied for basic authentication in callbacks
        # callback-basic-auth: username:password
        # The callback URL base for this specific client
        callback-url: https://<server-DNS>:8443/pgwy/auth/callback
-----------------
    message-server-library:
      public-url: https://<server-DNS>:20400/hermod/rest/ms
-----------------

Install and deploy WAR file for CM Web UI

  1. Download cm-web-ui-2.0.1.zip from the Nexus support portal.

  2. Unzip and copy webui.war to the "<CATALINA_BASE>/webapps" subdirectory of the Tomcat installation

Login and Signing Officer

Configuring the CM Web UI

  1. HERMOD

  2. Restart Tomcat check logs.

  3. verify that CM-WEBUI is available at https://<server-DNS>>:8443/webui and autenticate using officer.







Last updated: