Renewing the IBM MaaS360 VPN module server certificate
The document provides steps for renewing certificates that are expired and certificates that are about to expire. These certificates are used by the IBM® MaaS360® VPN Module Server, which is configured within the Cloud Extender®.
Verifying the expiration dates
Verify the expiration dates of the IBM MaaS360
VPN module server certificate.
- Log in to the Cloud Extender Node, where the IBM MaaS360 VPN module is configured.
- Go to the directory C:\ProgramData\MaaS360\Cloud
Extender\AR\DATA\VPN.Note: If the path is hidden and not visible, then you need to manually input the path into Windows Explorer.
- Open the file server.crt by double-clicking the file and checking for validity. The valid expiration dates are displayed on the window.
- If the certificate is expired, you must renew the certificate.
Renewing IBM MaaS360 VPN module server certificate
Renew the IBM MaaS360
VPN module server certificate.
- Open Cloud Extender Configuration Tool.
- Click the VPN module tile on the Cloud Extender Configuration Tool to open up the VPN configuration window.
- From the VPN configuration window, click the Edit icon.
- Click Next on the VPN Prerequisites Status screen. The Cluster Details panel is displayed.
- From the Cluster Details window, copy the configuration details. These details are required in the next steps.
- Once the configuration details are recorded, click Cancel and select Yes to confirm.
- Once again, click the VPN module tile on the Cloud Extender Configuration Tool to return to the VPN configuration window.
- In the VPN configuration window, select the Delete icon to delete the existing cluster and then click Yes to confirm.
- Create a cluster by selecting Setup a new VPN cluster, and click Next until the Cluster Details window is displayed.
- Enter the configuration details that were copied in the Step 5 into the Cluster Details window. Assign a unique name to the VPN Cluster.
- Click Next. The Validate and Test VPN Settings window is displayed
- Perform the two tests that are available and verify whether they succeed.
- Click Save to complete the new cluster configuration.
- To verify that the certificates are renewed successfully, go to the directory
C:\ProgramData\MaaS360\Cloud Extender\AR\DATA\VPN, and double-click the
server.crt file.Note: If the newly created file name is VPNCERT.crt, rename it to server.crt.
- The VPN Server certificate renewal is successful. You can now close the Certificate file, MaaS360 Config Tool, and Explorer window and exit from the remote desktop session.
Pushing VPN configurations to devices
Follow the steps to push the VPN configuration to devices through the IBM
MaaS360 Portal.
- From the IBM MaaS360 Portal home page, go to .
- Click view under the policy, which is configured to use VPN. The policy details view is displayed.
- Go to .
- Click Edit.
- In VPN Configuration, select MaaS360 VPN.
- Provide a name to your VPN profile and then select the previously configured cluster name in the Select VPN Server.
- Ensure that Maximum Connection Duration is set to a non-zero value.
- Publish the policy. The policy settings are applied to the devices.
Result: Users can now connect to IBM MaaS360 VPN to confirm access with updated certificates.