<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create HTTPS cert with internal CA in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415019#M11005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have a look at this post:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.qlik.com/message/1223753"&gt;Sense unable to locate a ssl certificate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Same error as you're seeing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Oct 2017 09:50:21 GMT</pubDate>
    <dc:creator>simon_minifie</dc:creator>
    <dc:date>2017-10-24T09:50:21Z</dc:date>
    <item>
      <title>Create HTTPS cert with internal CA</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415015#M11001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there.&lt;/P&gt;&lt;P&gt;We have a PFsense Firewall wich does have a build in CA. So my plan is to use this CA to create a certificate that i can deploy using GPO and then use it to run HTTPS on several internal websites, inlcuding QS. However i cant seem to get it working.&lt;/P&gt;&lt;P&gt;First of, im pretty new to how certificates work but im trying to learn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created a Root-CA and a Suborinate-CA on the firewall. I then exported the root-CA certificate and installed on my local desktop machine. I then created a server-certificate using the subordinate CA. From pfsense i can then export the crt file and i can export an .key file.&lt;/P&gt;&lt;P&gt;I the used openSSL.exe to merge theese two into one file and imported in on the qliksense server. I took the thumbprint and added it to the QS Proxy (as i have done on several customers befor without any problem). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when i load the page and check what certificate it uses. It looks like its still uses the serlf-signed cert (The CA seems to be the sense-server). So what am I doing wrong? Do i need to convert my certificates to a specific format or something?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Oct 2017 13:48:23 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415015#M11001</guid>
      <dc:creator>gustavgager</dc:creator>
      <dc:date>2017-10-23T13:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Create HTTPS cert with internal CA</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415016#M11002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gustav,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a look at the Proxy security logs. (C:\ProgramData\Qlik\Sense\Log\Proxy)&lt;/P&gt;&lt;P&gt;They usually give an explanation of why a specific certificate can't be used, and why it has reverted to its self-signed one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 09:16:09 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415016#M11002</guid>
      <dc:creator>simon_minifie</dc:creator>
      <dc:date>2017-10-24T09:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Create HTTPS cert with internal CA</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415017#M11003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh good one! Found this in the log:&lt;/P&gt;&lt;P&gt;Couldn't find a valid ssl certificate with thumbprint xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx&lt;/P&gt;&lt;P&gt;But when i check my cert-store (local computer-&amp;gt;personal-&amp;gt;certificates) its there, and the Thumbprint is correct.&lt;/P&gt;&lt;P&gt;So my conclusion is that my cert is not "valid"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 09:35:26 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415017#M11003</guid>
      <dc:creator>gustavgager</dc:creator>
      <dc:date>2017-10-24T09:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Create HTTPS cert with internal CA</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415018#M11004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gustav,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What constitutes a 'valid' cert is sort of outlined here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.qlik.com/en-US/sense/September2017/Subsystems/ManagementConsole/Content/change-proxy-certificate.htm" title="https://help.qlik.com/en-US/sense/September2017/Subsystems/ManagementConsole/Content/change-proxy-certificate.htm"&gt;https://help.qlik.com/en-US/sense/September2017/Subsystems/ManagementConsole/Content/change-proxy-certificate.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the private key isn't present it is usually stated in the logs, so there must be a different reason Sense doesn't like it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 09:48:36 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415018#M11004</guid>
      <dc:creator>simon_minifie</dc:creator>
      <dc:date>2017-10-24T09:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Create HTTPS cert with internal CA</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415019#M11005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have a look at this post:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.qlik.com/message/1223753"&gt;Sense unable to locate a ssl certificate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Same error as you're seeing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 09:50:21 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415019#M11005</guid>
      <dc:creator>simon_minifie</dc:creator>
      <dc:date>2017-10-24T09:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Create HTTPS cert with internal CA</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415020#M11006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes i have imported a key. If i open the Cert i certmanager it say that i have a private key that works with this certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 10:07:21 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415020#M11006</guid>
      <dc:creator>gustavgager</dc:creator>
      <dc:date>2017-10-24T10:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Create HTTPS cert with internal CA</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415021#M11007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Simon. I actually got a bit closer to the problem now.&lt;/P&gt;&lt;P&gt;I had do install the certificate for the root CA and the Sub CA. After that, the cert was identified OK and the services started OK. I was under the impression that if i trust the root CA, then all sub.certs would be automaticly trusted?&lt;/P&gt;&lt;P&gt;However i still cannot get it to work. When i connect to the site, i get the error:&lt;/P&gt;&lt;P&gt;"Missmacthed Adress. The security certificate presented by this website was issued for another server".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added several names including the IP adress. The IP adress works, but the name doesnt &lt;IMG src="https://community.qlik.com/legacyfs/online/emoticons/sad.png" /&gt;&lt;/P&gt;&lt;P&gt;So it looks like the subject alternative name forks. But the CN does not &lt;IMG src="https://community.qlik.com/legacyfs/online/emoticons/sad.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 10:50:50 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415021#M11007</guid>
      <dc:creator>gustavgager</dc:creator>
      <dc:date>2017-10-24T10:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Create HTTPS cert with internal CA</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415022#M11008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A quick update. I got everything working when i added my URL as secondary. The primary CN did not work. Not on to try to get it to work with Nprinting &lt;IMG src="https://community.qlik.com/legacyfs/online/emoticons/silly.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Oct 2017 13:04:19 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-HTTPS-cert-with-internal-CA/m-p/1415022#M11008</guid>
      <dc:creator>gustavgager</dc:creator>
      <dc:date>2017-10-25T13:04:19Z</dc:date>
    </item>
  </channel>
</rss>

