Preserving custom SSL certificates
If you are using custom SSL certificates, learn how to preserve them across Netezza Performance Server upgrade.
Before upgrade
- Log in to the
ipshost
container. - Copy
server-cert.pem
andserver-key.pem
to the persistent storage.-
mkdir /nzscratch/custom_ssl_certs
-
cp -rp /nz/data/security/server-cert.pem /nzscratch/custom_ssl_certs/server-cert.pem
-
cp -rp /nz/data/security/server-key.pem /nzscratch/custom_ssl_certs/server-key.pem
-
After upgrade
Before you start Netezza Performance Server, run the
following commands.
- Changed directories to
/nz/kit/share/security.
cd /nz/kit/share/security
-
Copy the backed up
server-cert.pem
andserver-key.pem
files to /nz/kit/share/security.- For 11.0.7.0 and lower
- If
enable_tls_v12 = 1
or ifenable_tls_v12
is not present, run the following commands:-
mv server-key.pem.sample server-key.pem.sample.BKP
-
mv server-cert.pem.sample server-cert.pem.sample.BKP
-
cp -rp /nzscratch/custom_ssl_certs/server-cert.pem server-cert.pem.sample
-
cp -rp /nzscratch/custom_ssl_certs/server-key.pem server-key.pem.sample
-
- If
enable_crypto_std_v1 =1
, run the following commands:-
mv server-cert-sp800-131a.pem.sample server-cert-sp800-131a.pem.sample.BKP
-
mv server-key-sp800-131a.pem.sample server-key-sp800-131a.pem.sample.BKP
-
cp -rp /nzscratch/custom_ssl_certs/server-cert.pem server-cert-sp800-131a.pem.sample
-
cp -rp /nzscratch/custom_ssl_certs/server-key.pem server-key-sp800-131a.pem.sample
-
- If
- For 11.0.7.1 and later, run the following commands:
-
mv server-cert-sp800-131a.pem.sample server-cert-sp800-131a.pem.sample.BKP
-
mv server-key-sp800-131a.pem.sample server-key-sp800-131a.pem.sample.BKP
-
cp -rp /nzscratch/custom_ssl_certs/server-cert.pem server-cert-sp800-131a.pem.sample
-
cp -rp /nzscratch/custom_ssl_certs/server-key.pem server-key-sp800-131a.pem.sample
-
- For 11.0.7.0 and lower
- Start the system.
-
nzstart
-