<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment? in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474820#M28968</link>
    <description>&lt;P&gt;Indeed the self-signed certificate is used by the authentication&amp;nbsp;mechanism between Qlik Sense services.&amp;nbsp;&lt;BR /&gt;Remove it then will broke Qlik Sense.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Complete process is available here:&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773" target="_blank"&gt;How to change the certificate used by the Qlik Sen... - Qlik Community - 1712773&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To recreate the certificate:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-recreate-or-just-delete-certificates-in-Qlik-Sense-No/ta-p/1712692" target="_blank"&gt;How to recreate or just delete certificates in Qli... - Qlik Community - 1712692&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Good luck !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Aug 2024 14:02:41 GMT</pubDate>
    <dc:creator>mpc</dc:creator>
    <dc:date>2024-08-06T14:02:41Z</dc:date>
    <item>
      <title>What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474676#M28965</link>
      <description>&lt;P&gt;I'm having trouble understanding what the self-signed certificate is used for in an on-prem Qlik Sense server environment. More precisely, I'm referring to the self-signed certificate which is stored in &lt;STRONG&gt;Certificates (Local Computer)&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Personal&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Certificates&lt;/STRONG&gt; location in Microsoft Management Console (MMC).&lt;/P&gt;
&lt;P&gt;&lt;A title="Service certificates" href="https://help.qlik.com/en-US/sense-admin/May2024/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/service-certificates.htm" target="_blank" rel="noopener"&gt;Service certificates documentation&lt;/A&gt;&amp;nbsp;has this sentence about the self-signed certificate:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;The service certificate and service private key are&amp;nbsp;&lt;/SPAN&gt;used for server authentication when your service acts as a server, that is, when another service calls an API in your service.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I find that sentence a bit too confusing.&lt;/P&gt;
&lt;P&gt;Does anyone know, in layman's terms, what exactly a self-signed certificate used for in an on-prem Qlik Sense server environment?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 16:21:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474676#M28965</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2025-01-29T16:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474728#M28966</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you connect to Qlik Sense, it's establish a secure connection between your computer and Qlik Sense. To do that, it's need a certificate, a file which says "Yes, I'm Qlik Sense".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;But as you can see when connecting, your browser display an error. It's because it's Qlik Sense who says "Yes I'm Qlik Sense". That called a self-signed certificate.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;To truly secure the connection, you need to install a certificate signed by a external provider. Like an ID Card signed by your Government. It will say "Me, the third party, garantuee that this server is Qlik Sense"&lt;/P&gt;
&lt;P&gt;I hope I'm more clear than the doc.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 08:11:43 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474728#M28966</guid>
      <dc:creator>mpc</dc:creator>
      <dc:date>2024-08-06T08:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474818#M28967</link>
      <description>&lt;P&gt;Thanks for the reply&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/251190"&gt;@mpc&lt;/a&gt;!&lt;/P&gt;
&lt;P&gt;I did a bit of experimenting today and the results I got suggest that the self-signed certificate is doing &lt;STRONG&gt;more&lt;/STRONG&gt; than securing communications between Qlik Sense server and client PCs.&lt;/P&gt;
&lt;P&gt;I have an internal Certification Authority (CA) at my company and I went through the process of creating Certificate Signing Request, installing the certificate I received from internal CA, and configured Qlik Sense proxy settings to use the certificate generated by the internal CA. Doing so resolves the whole &lt;EM&gt;"connection is not secure"&lt;/EM&gt; message, but what I did next &lt;STRONG&gt;broke my Qlik Sense server&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;After installing the certificate from internal CA, I went ahead and &lt;STRONG&gt;deleted the original self-signed certificate&lt;/STRONG&gt; and &lt;STRONG&gt;restarted my Qlik Sense server&lt;/STRONG&gt;. The thought was &lt;EM&gt;"since Qlik Sense is now using the new cert, I no longer need the original one."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;However, when I deleted the original self-signed certificate, both Hub and QMC broke:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mbespartochnyy_1-1722951611943.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/170282i1702FAA2AFD662A7/image-size/large?v=v2&amp;amp;px=999" role="button" title="mbespartochnyy_1-1722951611943.png" alt="mbespartochnyy_1-1722951611943.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mbespartochnyy_2-1722951868485.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/170283i488C4B35AA45EA71/image-size/large?v=v2&amp;amp;px=999" role="button" title="mbespartochnyy_2-1722951868485.png" alt="mbespartochnyy_2-1722951868485.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They broke even though &lt;STRONG&gt;all of Qlik Sense services are running fine&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mbespartochnyy_0-1722951586069.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/170281i85784614B6CD1D0F/image-size/large?v=v2&amp;amp;px=999" role="button" title="mbespartochnyy_0-1722951586069.png" alt="mbespartochnyy_0-1722951586069.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This suggests that the self-signed certificate is &lt;STRONG&gt;doing more than securing communications between a Qlik Sense server and client PCs&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Do you know what else the self-signed certificate is used for?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 13:45:56 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474818#M28967</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2024-08-06T13:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474820#M28968</link>
      <description>&lt;P&gt;Indeed the self-signed certificate is used by the authentication&amp;nbsp;mechanism between Qlik Sense services.&amp;nbsp;&lt;BR /&gt;Remove it then will broke Qlik Sense.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Complete process is available here:&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773" target="_blank"&gt;How to change the certificate used by the Qlik Sen... - Qlik Community - 1712773&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To recreate the certificate:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-recreate-or-just-delete-certificates-in-Qlik-Sense-No/ta-p/1712692" target="_blank"&gt;How to recreate or just delete certificates in Qli... - Qlik Community - 1712692&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Good luck !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 14:02:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474820#M28968</guid>
      <dc:creator>mpc</dc:creator>
      <dc:date>2024-08-06T14:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474829#M28969</link>
      <description>&lt;P&gt;The certificate is used as an authentication mechanism between services -- eg between the Proxy Service and the Repository Servive to generate a list of Apps for the Hub. The certificate is used like a key card and sent with the API call. If the call presents the certificate, then it's trusted.&lt;/P&gt;
&lt;P&gt;-Rob&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 14:34:50 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474829#M28969</guid>
      <dc:creator>rwunderlich</dc:creator>
      <dc:date>2024-08-06T14:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474854#M28970</link>
      <description>&lt;P&gt;Thank you both! It's starting to become clearer. It sounds like the self-signed certificate is used to &lt;STRONG&gt;authenticate the identity of server&lt;/STRONG&gt; on which Qlik Sense is installed and to &lt;STRONG&gt;encrypt communications between Qlik Sense services&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;What about &lt;STRONG&gt;encryption of data connection strings and credentials&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P&gt;I read through the&amp;nbsp;&lt;SPAN&gt;&lt;A title="How to recreate or just delete certificates in Qlik Sense - No access to QMC or Hub" href="https://community.qlik.com/t5/Official-Support-Articles/How-to-recreate-or-just-delete-certificates-in-Qlik-Sense-No/ta-p/1712692" target="_blank" rel="noopener"&gt;How to recreate or just delete certificates in Qlik Sense - No access to QMC or Hub&lt;/A&gt; document which, at the very beginning, mentions this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mbespartochnyy_1-1722957975396.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/170288i54F06BA4FCAC5411/image-size/large?v=v2&amp;amp;px=999" role="button" title="mbespartochnyy_1-1722957975396.png" alt="mbespartochnyy_1-1722957975396.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It sounds like the self-signed certificate might also play a role in encrypting data within QSR database. The rest of the document seems to suggest that &lt;STRONG&gt;credentials&lt;/STRONG&gt; used when creating data connections are also encrypted using (I assume the self-signed) certificate.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mbespartochnyy_3-1722958523607.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/170293i928E6D757E8D6BAC/image-size/large?v=v2&amp;amp;px=999" role="button" title="mbespartochnyy_3-1722958523607.png" alt="mbespartochnyy_3-1722958523607.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Is the self-signed certificate also used to &lt;STRONG&gt;encrypt credentials&lt;/STRONG&gt; for data connections or is the self-signed certificate only used for server authentication and to secure communications between Qlik Sense services?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 15:39:19 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474854#M28970</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2024-08-06T15:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474931#M28971</link>
      <description>&lt;P&gt;You're right, it's also encrypt credentials for data connection. Then, deleting and recerating it force you to retype credentials&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 06:13:46 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2474931#M28971</guid>
      <dc:creator>mpc</dc:creator>
      <dc:date>2024-08-07T06:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2475549#M28972</link>
      <description>&lt;P&gt;It sounds like in an on-prem Qlik Sense server environment, there are &lt;STRONG&gt;three&lt;/STRONG&gt; roles that the self-signed certificate serves. They are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Secure communications between the Qlik Sense server and client PCs.&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;That is unless the self-signed certificate is replaced by a certificate generated by a trusted third-party or by an internal Certification Authority.&lt;/LI&gt;
&lt;LI&gt;Side Note:&amp;nbsp;Recreating the self-signed certificate won't cause any issues here.&lt;/LI&gt;
&lt;LI&gt;Another Side Note: Changing the third party certificate, if one is used, will require changes to proxy settings in QMC in order for Qlik Sense to use the new certificate.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Secure communications between Qlik Sense services.&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Applies to both a single node site and to a multi-node site.&lt;/LI&gt;
&lt;LI&gt;Side Note: Recreating the self-signed certificate won't cause any issues here.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Secure credentials of data connections&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Side Note: Recreating the self-signed certificate will result in a need to re-enter password for every password-protected data connection.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There are no other known roles that self-signed certificate plays in an on-prem Qlik Sense server environment. Is that accurate?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 13:58:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2475549#M28972</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2024-08-09T13:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2506601#M28973</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;We've been picked up by an external PenTest for using self signed certificates.&amp;nbsp; We have a third part SSL installed for the Hub/QMC - can this be used to replace the self signed cert?&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 12:27:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2506601#M28973</guid>
      <dc:creator>Senor_Dai</dc:creator>
      <dc:date>2025-02-19T12:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is Qlik's self-signed certificate used for in an on-prem Qlik Sense server environment?</title>
      <link>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2506606#M28974</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can to it by register the cert in the QMC &amp;gt; Proxy &amp;gt; Security section. You must not uninstall the Qlik self-signed one&lt;/P&gt;
&lt;P&gt;Best&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 12:47:10 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/What-is-Qlik-s-self-signed-certificate-used-for-in-an-on-prem/m-p/2506606#M28974</guid>
      <dc:creator>mpc</dc:creator>
      <dc:date>2025-02-19T12:47:10Z</dc:date>
    </item>
  </channel>
</rss>

