Self-signed temporary SA Agent certificates

In third-party certificate mode, SA normally installs the SA Agent using a certificate signed by your external Certificate Authority (CA). However, if your CA cannot sign certificates at Agent installation time, SA can use the following self-signed CAs to provision the servers. 

  • Bootstrap CA – signs the Bootstrap certificate which the SA Agents use to register with the SA Core.
  • Agent CA – signs the temporary SA Agent certificates.

Allowing temporary self-signed SA Agent registration

To enable SA Agents to register to the SA core with a temporary, self-signed certificate, go to Administration > System Configuration > Configuration Parameters > Data Access Engine (spin) and set the spin.agent.bootstrap_enabled parameter to 1. For more information see The spin.agent.bootstrap_enabled parameter.

Replacing self-signed temporary certificates with third-party ones

After registering the SA Agents with self-signed temporary certificates, you can switch the SA Agent to third-party mode using SA scripts. You can switch the SA Agents to third-party certificate mode either from the Command Line Interface or from the Agent Deployment Tool: