How To Regenerate EEM Certificates for CA Workload Automation AE and CA Workload Control Center

Document ID:  TEC1139738
Last Modified Date:  07/08/2017
{{active ? 'Hide' : 'Show'}} Technical Document Details

Products

  • CA Workload Automation AE

Releases

  • CA Workload Automation AE:Release:11.3.6
  • CA Workload Automation AE:Release:11.3.5
  • CA Workload Automation AE:Release:11.4

Components

  • WORKLOAD CONTROL CENTER:UWCC
  • CA Workload Automation AE (AutoSys):ATSYS
  • AUTOSYS RELEATED EEM:ATSEEM
Introduction:

After making changes to your EEM instance, it is recommended to regenerate the EEM certificates used by CA Workload Automation AE (Autosys) and CA Workload Control Center. 

Changes to your EEM instance can include (but are not limited to):

  • upgrading the EEM version
  • changing the certificate key lengths (1024 to 2048)
  • changing the digest algorithm (SHA1 to SHA256)
  • placing it within a failover/multiwrite cluster
Environment:
CA Embedded Entitlements Manager r12.x CA Workload Automation AE r11.3.x CA Workload Control Center r11.3.x CA Workload Control Center r11.4.x
Instructions:

REGENERATE EEM CERTIFICATES FOR AUTOSYS

$autosys_secure

CA WAAE Security Utility

Please select from the following options:

[1] Revert to NATIVE instance security.

[2] Manage CA EEM security settings.

[3] Change database password.

[4] Change remote authentication method.

[5] Manage user@host or user@domain users.

[6] Get encrypted password.

[0] Exit CA WAAE Security Utility.

2

 

Manage CA EEM security settings

 

Please select from the following options:

[1] Manage CA EEM server settings.

[2] Manage cached credentials.

[9] Exit from "Manage CA EEM security settings" menu.

[0] Exit CA WAAE Security Utility.

1

 

Manage CA EEM server settings

 

Please select from the following options:

[1] Show current CA EEM server settings.

[2] Set CA EEM server location and regenerate certificate.

[3] Set unauthenticated user mode.

[9] Exit from "Manage CA EEM server settings" menu.

[0] Exit CA WAAE Security Utility.

2

 

Input the CA EEM server name(s) (or hit enter to cancel):  (The EEM server hostname(s))

Input the CA EEM administrator name (or hit enter to cancel):  EiamAdmin

Input the CA EEM administrator password: (the password will be hidden while you type)

 

Confirm the CA EEM administrator password: (the password will be hidden while you type)

 Note: Specify all EEM cluster nodes as comma separated values, in case of EEM Multi-Write configuration(eemserver1,eemserver2). 

 

CAUAJM_I_60200 CA EEM certificate generated successfully.

CAUAJM_W_60190 The CA EEM server location remains unchanged.

  

Please select from the following options:

[1] Show current CA EEM server settings.

[2] Set CA EEM server location and regenerate certificate.

[3] Set unauthenticated user mode.

[9] Exit from "Manage CA EEM server settings" menu.

[0] Exit CA WAAE Security Utility.

>0

 

REGENERATE EEM CERTIFICATES FOR WCC

Navigate to $CA_WCC_INSTALL_LOCATION/safex directory.

Rename/move the wcc.pem and wcc.key files if exist.

The following command will generate the new wcc.pem and wcc.key files:

./safex –h eem_hostname(s) –u EiamAdmin –p password –f IssueCertificate.xml

Note: Specify all EEM cluster nodes as comma separated values, in case of EEM Multi-Write configuration(eemserver1,eemserver2).

The password (-p) is for EiamAdmin.

For example:

#./safex –h eem_server_hostname(s) –u EiamAdmin –p <EiamAdmin_user_password> –f IssueCertificate.xml

 

Setting Translation file:./safex.tr

Setting back end to "localhost"

 

Setting locale to "en_us"

 

OK:Successfully Authenticated

OK: action[Attach] with ApplicationInstance label[WCC0004]

OK: action[IssueCertificate] for ApplicationInstance label[WCC0004] user[]

OK: action[Detach] from ApplicationInstance label[WCC0004]

OK:Total objects Added 0

OK:Total objects Modified 0

OK:Total objects Removed 0

OK:Total objects Skipped 0

OK:Total objects Exported 0

Navigate to the directory $CA_WCC_INSTALL_LOCATION/data/config 

Rename/move the existing wcc.pem and wcc.key certificates.

Move the newly generated certificate wcc.pem and the key wcc.key files from $CA_WCC_INSTALL_LOCATION/safex to the current location ($CA_WCC_INSTALL_LOCATION/data/config)

Set the file ownership permissions to same as the previous files.

Register the CA WCC to use newly certificates

# ./wcc_config.sh -u ejmcommander -p ejmcommander --eemhostname eem_hostname(s) --eemappid WCC0004 --eemcertname wcc.pem --eemcertkey wcc.key -eemadmin EiamAdmin --eempassword EiamAdmin_user_password

 

Logging in as 'ejmcommander' - SUCCESS

 

EEM server has been changed successfully.

 - FINISHED

The changes will be applied only after restart.

Execute the following command to restart the services.

-----------------------------------------------------------------------

unisrvcntr restart CA-wcc-services

 

-----------------------------------------------------------------------

As indicated in the command output, Restart the WCC services using the command 'unisrvcntr restart CA-wcc-services'

Please help us improve!

Will this information enable you to resolve your issue?

Please tell us what we can do better.

{{feedbackText.length ? feedbackText.length : '0'}}/255

{{status}}

Not what you were looking for?

Search Again >

Product Information

Support by Product >

Communities

Join a Community >

Chat with CA

Just give us some brief information and we'll connect you to the right CA ExpertCA sales representative.

Our hours of availability are 8AM - 5PM CST.

All Fields Required

connecting

We're matching your request.

Unfortunately, we can't connect you to an agent. If you are not automatically redirected please click here.

  • {{message.agentProfile.name}} will be helping you today.

    View Profile


  • Transfered to {{message.agentProfile.name}}

    {{message.agentProfile.name}} joined the conversation

    {{message.agentProfile.name}} left the conversation

  • Your chat with {{$storage.chatSession.messages[$index - 1].agentProfile.name}} has ended.
    Thank you for your interest in CA.


    Rate Your Chat Experience.

    {{chat.statusMsg}}

agent is typing