Infogix Assure, Insight, Perceive and ER utilize both democert and cacerts keystores, depending on the action performed in the product.
The democert within Infogix installation files is used in the following scenarios:
- Internal product processing
- Server-util script executions triggered by the product
The cacerts within Java's installation directory is used in the following scenarios
- Server-util script executions triggered by a user (command prompt / terminal)
- Assure client script executions
Without having the necessary certificates in the correct locations, you will run across the following error message when connecting to an HTTPS endpoint:
Caused by: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
Updating Democert with new certificates
Assure, Insight, Perceive and ER servers have their own copy of democert stored within the following location:
Please note that the file within the directory above is utilized during the deployment process and will not be overwritten by performing a "clean". The deployment process will place this keystore within the locations below. You do not need to individual update these keystores - a deploy will perform this task for you.
Updating Cacerts with new certificates
Any command-line execution of scripts within Assure's, Insight's, Perceive's or ER's server-util directory or any scripts triggered by Assure client will leverage the cacerts within your server's default Java location, as specified by the java_home server variable.
Please note that for Assure client installations, Assure will utilize the local server's Java home cacerts as opposed to the Assure server's Java home cacerts. This is important as end-users who utilize the Assure client will be required to update their cacerts to allow communication to a SSL server setup.
Java's cacerts is located within the following location:
To update cacerts with new certificates, please utilize the following article for details regarding how to import certificates. A redeploy of the Infogix products is not required for this change to take effect.