The TrustStore tab in the Network Security panel displays all the CA certificates that the Delphix Engine trusts. Click on the Actions (...) menu in the top right to reveal the options for editing the TrustStore contents:
Delphix Engine generates alerts when certificates in the Keystore or truststore are expired or about to expire:
- A warning level alert is generated if certificates are expiring in 60 days.
- Critical level alerts are generated if certificates expire in 14 days or have already expired.
Adding a Certificate
- From the Actions menu select Add Certificate.
- In the Add Certificate wizard paste the PEM contents of the CA certificate you want to add. The PEM contents must have the appropriate header and footer included.
- If you are adding a non-root CA certificate, its signer must already exist in the truststore. So, if you are adding a chain with multiple certificates, you must add them individually starting from the root CA. If not, you will get an error saying that we could not establish a chain of trust.
- Click Next to view a Summary tab where you can confirm the certificate contents.
- Click Submit .
Deleting a Certificate
Use this option to delete the selected CA certificate.
Deleting any certificate that breaks an existing chain of trust is not allowed.
- From the Actions menu select Delete Certificate .
- The default Delphix CA cannot be deleted. Note that deleting any certificate that breaks an existing chain of trust is also not allowed.
In the Confirmation dialog select Delete.Unlike the network security settings, any changes to the TrustStore will not require a stack restart.