<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://www.aras.com/community/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to update expire Aras certifies</title><link>https://www.aras.com/community/f/development/37411/how-to-update-expire-aras-certifies</link><description>How can I update expired Aras certificates</description><dc:language>ja-JP</dc:language><generator>Telligent Community 12</generator><item><title>RE: How to update expire Aras certifies</title><link>https://www.aras.com/community/thread/8541?ContentTypeID=1</link><pubDate>Fri, 15 Jul 2022 09:44:16 GMT</pubDate><guid isPermaLink="false">916d3f7e-8ddc-42f8-8d45-380822f51406:5f11c531-3f1c-4dad-a547-4b1112a09704</guid><dc:creator>AngelaIp</dc:creator><description>&lt;p&gt;When I have read the &amp;quot;&lt;span&gt;harmlessly phrased&lt;/span&gt;&amp;quot; question the first time one month ago, my face got white and chills ran down my back. I was really scared after I checked the certificates of my old server. Thanks for confirming the disaster!&lt;/p&gt;
&lt;p&gt;I agree that Aras should publish something &amp;quot;official&amp;quot; regarding the certificates. I will try to reach somebody. Or I write something by myself in cause they don&amp;acute;t react.&lt;/p&gt;
&lt;pre class="tw-data-text tw-text-large tw-ta" id="tw-target-text" dir="ltr"&gt;&lt;/pre&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to update expire Aras certifies</title><link>https://www.aras.com/community/thread/8539?ContentTypeID=1</link><pubDate>Fri, 15 Jul 2022 08:27:08 GMT</pubDate><guid isPermaLink="false">916d3f7e-8ddc-42f8-8d45-380822f51406:8a706cd5-4e6b-402c-8595-b2f386bfd517</guid><dc:creator>benjamin.brooking</dc:creator><description>&lt;p&gt;Thanks so much for posting this answer. Our production Innovator server ran into this problem yesterday - the symptom from the users was an HTTP 500 error when accessing files from the Vault which had been fine minutes before. After a lot of head-scratching I traced it back to a failing OAuth token request, and then the expired certificates.&lt;/p&gt;
&lt;p&gt;Aras really need to add this information and that certificate generator more clearly somewhere, or better yet have the installer create a scheduled task. That was a stressful night!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to update expire Aras certifies</title><link>https://www.aras.com/community/thread/8430?ContentTypeID=1</link><pubDate>Wed, 22 Jun 2022 12:44:59 GMT</pubDate><guid isPermaLink="false">916d3f7e-8ddc-42f8-8d45-380822f51406:90193665-ef00-49c0-abc7-be0b18b3399c</guid><dc:creator>AngelaIp</dc:creator><description>&lt;p&gt;Hi Hkhan,&lt;/p&gt;
&lt;p&gt;many thanks for sharing this information! I made a quick test and the resulting certs lock fine.&lt;/p&gt;
&lt;p&gt;I am a little bit proud that my earlier&amp;nbsp;&lt;span&gt;openssl&amp;nbsp;idea wasn&amp;acute;t so wrong at all. It&amp;acute;s exactly the same concept that Aras uses.&lt;span class="emoticon" data-url="https://www.aras.com/community/cfs-file/__key/system/emoji/1f604.svg" title="Smile"&gt;&amp;#x1f604;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Best wishes!&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Angela&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to update expire Aras certifies</title><link>https://www.aras.com/community/thread/8428?ContentTypeID=1</link><pubDate>Tue, 21 Jun 2022 17:22:31 GMT</pubDate><guid isPermaLink="false">916d3f7e-8ddc-42f8-8d45-380822f51406:feaf0396-4cf7-4726-8d03-7d34864e0267</guid><dc:creator>hkhan</dc:creator><description>&lt;p&gt;Hello Angelalp,&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;I contacted Aras for help and the following is the solution they provided&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;To generate new certificates:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span&gt;&lt;/span&gt;Download from the FTP site i have added to this page&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;&lt;/span&gt;Open a command prompt window as Administrator&lt;/li&gt;
&lt;li&gt;Navigate to the folder containing CreateOAuthCertificates.bat&lt;/li&gt;
&lt;li&gt;Execute the following command to generate certificates:&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;CreateOAuthCertificates.bat&amp;nbsp;&amp;lt;ServerName&amp;gt; &amp;lt;Password&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp; Where:&lt;/p&gt;
&lt;p&gt;ServerName&amp;nbsp;&amp;ndash; the name of the server for which a certificate should be generated (OAuthServer, InnovatorServer, VaultServer, AgentService, SelfServiceReporting).&lt;/p&gt;
&lt;p&gt;Password&amp;nbsp;&amp;ndash; the password for the private certificate.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Note: Each run of the batch file generates a pair of certificates in the&amp;nbsp;{Current_Directory}\Output\&amp;nbsp;directory, for example:&amp;nbsp;OAuthServer.cer&amp;nbsp;(public certificate) and&amp;nbsp;OAuthServer.pfx&amp;nbsp;(private certificate protected by the password). You will need to run this for each part of the application components.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Once the Certificates have been created copy them the corresponding directories.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Deploying the OAuthServer Certificates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Copy OAuthServer.pfx to OAuthServer\App_Data\Certificates\&lt;/li&gt;
&lt;li&gt;Copy the OAuthServer.pfx to the following folders:&lt;ul&gt;
&lt;li&gt;OAuthServer\App_Data\Certificates\&lt;/li&gt;
&lt;li&gt;Innovator\Server\App_Data\Certificates\&lt;/li&gt;
&lt;li&gt;SelfServiceReporting\App_Data\Certificates\&lt;/li&gt;
&lt;li&gt;VaultServer\App_Data\Certificates\&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Specify the password in oauth\server\tokenSigning\certificate\@password attribute of OAuthServer\OAuth.config file.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Deploying the Aras Innovator Server Certificates&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Copy InnovatorServer.pfx to Innovator\Server\App_Data\Certificates\.&lt;/li&gt;
&lt;li&gt;Copy InnovatorServer.cer to OAuthServer\App_Data\Certificates\.&lt;/li&gt;
&lt;li&gt;Specify password in oauth\client\secret\certificate\@password attribute of Innovator\Server\OAuth.config file.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Deploying the Vault Server Certificates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Copy VaultServer.pfx to VaultServer\App_Data\Certificates\.&lt;/li&gt;
&lt;li&gt;Copy VaultServer.cer to OAuthServer\App_Data\Certificates\.&lt;/li&gt;
&lt;li&gt;Specify password in oauth\client\secret\certificate\@password attribute of VaultServer\OAuth.config file.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Deploying the Agent Service Certificates&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Copy AgentService.pfx to AgentService\App_Data\Certificates\.&lt;/li&gt;
&lt;li&gt;Copy AgentService.cer to OAuthServer\App_Data\Certificates\.&lt;/li&gt;
&lt;li&gt;Specify password in oauth\client\secret\certificate\@password attribute of AgentService\OAuth.config file.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Deploying the Self Service Reporting Certificates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Copy SelfServiceReporting.pfx to SelfServiceReporting\App_Data\Certificates\.&lt;/li&gt;
&lt;li&gt;Copy SelfServiceReporting.cer to OAuthServer\App_Data\Certificates\.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Specify password in oauth\client\secret\certificate\@password attribute of SelfServiceReporting\OAuth.config file.&lt;a href="https://www.aras.com/cfs-file/__key/communityserver-discussions-components-files/3/GenerateOAuthCertificates-_2800_1_2900_.zip"&gt;www.aras.com/.../GenerateOAuthCertificates-_2800_1_2900_.zip&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to update expire Aras certifies</title><link>https://www.aras.com/community/thread/8427?ContentTypeID=1</link><pubDate>Tue, 21 Jun 2022 16:26:44 GMT</pubDate><guid isPermaLink="false">916d3f7e-8ddc-42f8-8d45-380822f51406:c22de315-51bc-488d-b296-1a0046b199e5</guid><dc:creator>AngelaIp</dc:creator><description>&lt;p&gt;Hi Haider and Hkhan,&lt;/p&gt;
&lt;p&gt;were you able to find a solution for this one?&lt;/p&gt;
&lt;p&gt;I need to find a solution...till 2024. So there is no real hurry. But&amp;nbsp;I think this topic will become relevant for many users who don&amp;acute;t update on a regular basis. So it&amp;acute;s better to be prepared.&lt;/p&gt;
&lt;p&gt;I haven&amp;acute;t&amp;nbsp;done any tests regarding custom certificates yet. And so far I haven&amp;acute;t seen any document related to certificates in&amp;nbsp;&lt;a href="https://www.aras.com/support/documentation/"&gt;https://www.aras.com/support/documentation/&lt;/a&gt;&amp;nbsp;. Not sure if Aras is aware of the issue.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#ff0000;font-size:150%;"&gt;IMPORTANT: For anyone who came across this post by accident: If you use the same Innovator 12+ instance&amp;nbsp;for around 2 years, check the validity of your certificates. You might be affected by the topic of this post too.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Hope this posts gets more attention.&lt;/p&gt;
&lt;p&gt;Thanks again for bringing up the topic!&lt;/p&gt;
&lt;p&gt;Angela&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to update expire Aras certifies</title><link>https://www.aras.com/community/thread/8394?ContentTypeID=1</link><pubDate>Fri, 10 Jun 2022 10:03:52 GMT</pubDate><guid isPermaLink="false">916d3f7e-8ddc-42f8-8d45-380822f51406:d2151667-e1ef-4c59-9a95-7c028a616f08</guid><dc:creator>AngelaIp</dc:creator><description>&lt;p&gt;OMG, thanks for this hint! Haven&amp;acute;t noticed yet that the certificates can expire.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Unfortunately I don&amp;acute;t know how to create new certificates. I know that installing Innovator creates a new set of certificates. In worst case reinstall Innovator and relink your database.&lt;/p&gt;
&lt;p&gt;But I assume that there must be a better solution. Maybe we can create our own with openssl or similar?? &lt;br /&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://stackoverflow.com/questions/10175812/how-to-generate-a-self-signed-ssl-certificate-using-openssl"&gt;https://stackoverflow.com/questions/10175812/how-to-generate-a-self-signed-ssl-certificate-using-openssl&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Can you describe the effects of the invalid certificates? I assume not all features of Innovator will work anymore? (ConversionServer? Vault?)&lt;/p&gt;
&lt;p&gt;I have moved my own instances from Windows Server 2012 to 2022 a few weeks ago, so I am right now not affected. But I would be&amp;nbsp;interested in a solution too! I wonder why we haven&amp;acute;t heard anything from Aras regarding this issue.&amp;nbsp;I guess many Innovator 12 installation are more or less 2 years old and can face this trap soon.&lt;/p&gt;
&lt;p&gt;Angela&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to update expire Aras certifies</title><link>https://www.aras.com/community/thread/8391?ContentTypeID=1</link><pubDate>Fri, 10 Jun 2022 06:06:12 GMT</pubDate><guid isPermaLink="false">916d3f7e-8ddc-42f8-8d45-380822f51406:fddab781-cc15-47bf-be7b-2aecd8d27eb5</guid><dc:creator>hkhan</dc:creator><description>&lt;p&gt;E:\Aras\OAuthServer\App_Data\Certificates&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;the certificate under this directory are expired how can i update this?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>