SSL Self-signed Certificate Regeneration¶
When Morpheus is deployed it generates a 10 year self-signed non-trusted SSL certificate. Below details the process to regenerate this certificate and key.
This procedure replaces the certificate presented by the appliance through NGINX. It does not add a certificate authority for outbound integrations. For an integration trust failure, use Import Trusted Certificates; reconfigure imports the CA, and morpheus-ui must then be restarted so the running JVM loads the updated truststore.
Replacing both the certificate and private key¶
Delete the certificate and key files in
/etc/morpheus/ssl/that end in.crtand.keyRun Reconfigure
morpheus-ctl reconfigureRestart NGINX
morpheus-ctl restart nginx
Replacing only the certificate¶
Delete the certificate file in
/etc/morpheus/ssl/it ends in.crtRun Reconfigure
morpheus-ctl reconfigureRestart NGINX
morpheus-ctl restart nginx