Administer > SA Core and component security > SA Core recertification

SA Core recertification

SA provides a Core Recertification Tool that allows you to recertify SA Cores and Agents. The Core Recertification Tool automates and speeds the process of issuing new security certificates.

This tool is separate from and compatible with the existing Agent Recertification tool. For more information, see Agent recertification.

Carrying out a Core Recertification does not require additional SA downtime. SA services will be fully available during the complete procedure. The following service restarts are required, but can be synchronized with internal maintenance windows:

1. Phases 3 and 7: Automatic restarts for mesh-wide SA gateways.

2. Phases 4, 8, and 12: Automatic restarts for mesh-wide SA Agents.

3. Phases 6: Automatic restarts for primary spin components of each SA facility.

4. Phases 6, 9, and 13: Manual mesh restarts.

Major advantages of the Core Recertification Tool are:

  • The ability to regenerate all SA certificates before their expiration, which effectively shortens their life span.
  • The ability to mitigate certificate compromises.

This release of Core Recertification Tool does not support customized Core installations. Any customization that has been done outside the realm of the SA Installer, which requires certain SA certificates and keys to be on a different host or under a different directory, will not be supported by this tool.

SA will warn administrators about upcoming certificate expiration through System Diagnosis on the Data Access Engine. The warning period is configurable (crypto.expire.warn_days) with the default being 300 days.

There are two use cases for re-certifying a core; the crypto material is expiring or a security breach has exposed the crypto. In the case of a security breach phases 11 through 13 must be executed.