<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic QlikServiceCluster Certificate in Single-Node Environment - Security Scan Issues in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/QlikServiceCluster-Certificate-in-Single-Node-Environment/m-p/2533742#M32307</link>
    <description>&lt;P class=""&gt;Hello Qlik Community,&lt;/P&gt;&lt;P class=""&gt;We have a customer running Qlik Sense Enterprise on Windows&amp;nbsp;in a single-node environment without app distribution. They are experiencing issues with their internal security scans, which flag the self-signed certificates generated by Qlik Sense, i.e. the QlikServiceCluster certificate and self-signed certificate for the server.&lt;/P&gt;&lt;P class=""&gt;Their security policy only allows certificates that are either:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Signed by their internal CA, or&lt;/LI&gt;&lt;LI&gt;Signed by a globally trusted CA&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;Our questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Is the QlikServiceCluster certificate actually required in a single-node setup without app distribution?&lt;/STRONG&gt; Since there's no multi-node communication or cluster functionality being used, we're wondering if this certificate serves any purpose in this scenario.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Can we safely remove or replace the QlikServiceCluster certificate&lt;/STRONG&gt; without breaking the Qlik Sense installation or causing issues with services?&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;What is the officially recommended approach&lt;/STRONG&gt; for customers who have strict certificate policies and cannot use self-signed certificates for internal communication?&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Are there any configuration options or best practices&lt;/STRONG&gt; to handle this situation while maintaining full supportability?&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;We understand that replacing proxy certificates for HTTPS is straightforward via QMC, but we're specifically concerned about the internal service communication certificates.&lt;/P&gt;&lt;P class=""&gt;Any guidance from Qlik or the community would be greatly appreciated!&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Environment details:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Qlik Sense Enterprise on Windows&lt;UL&gt;&lt;LI&gt;May 2024&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Single-node installation&lt;/LI&gt;&lt;LI&gt;No app distribution configured&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;Thank you in advance for your help!&lt;/P&gt;</description>
    <pubDate>Fri, 17 Oct 2025 13:38:26 GMT</pubDate>
    <dc:creator>SBr</dc:creator>
    <dc:date>2025-10-17T13:38:26Z</dc:date>
    <item>
      <title>QlikServiceCluster Certificate in Single-Node Environment - Security Scan Issues</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikServiceCluster-Certificate-in-Single-Node-Environment/m-p/2533742#M32307</link>
      <description>&lt;P class=""&gt;Hello Qlik Community,&lt;/P&gt;&lt;P class=""&gt;We have a customer running Qlik Sense Enterprise on Windows&amp;nbsp;in a single-node environment without app distribution. They are experiencing issues with their internal security scans, which flag the self-signed certificates generated by Qlik Sense, i.e. the QlikServiceCluster certificate and self-signed certificate for the server.&lt;/P&gt;&lt;P class=""&gt;Their security policy only allows certificates that are either:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Signed by their internal CA, or&lt;/LI&gt;&lt;LI&gt;Signed by a globally trusted CA&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;Our questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Is the QlikServiceCluster certificate actually required in a single-node setup without app distribution?&lt;/STRONG&gt; Since there's no multi-node communication or cluster functionality being used, we're wondering if this certificate serves any purpose in this scenario.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Can we safely remove or replace the QlikServiceCluster certificate&lt;/STRONG&gt; without breaking the Qlik Sense installation or causing issues with services?&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;What is the officially recommended approach&lt;/STRONG&gt; for customers who have strict certificate policies and cannot use self-signed certificates for internal communication?&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Are there any configuration options or best practices&lt;/STRONG&gt; to handle this situation while maintaining full supportability?&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;We understand that replacing proxy certificates for HTTPS is straightforward via QMC, but we're specifically concerned about the internal service communication certificates.&lt;/P&gt;&lt;P class=""&gt;Any guidance from Qlik or the community would be greatly appreciated!&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Environment details:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Qlik Sense Enterprise on Windows&lt;UL&gt;&lt;LI&gt;May 2024&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Single-node installation&lt;/LI&gt;&lt;LI&gt;No app distribution configured&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;Thank you in advance for your help!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 13:38:26 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikServiceCluster-Certificate-in-Single-Node-Environment/m-p/2533742#M32307</guid>
      <dc:creator>SBr</dc:creator>
      <dc:date>2025-10-17T13:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: QlikServiceCluster Certificate in Single-Node Environment - Security Scan Issues</title>
      <link>https://community.qlik.com/t5/Management-Governance/QlikServiceCluster-Certificate-in-Single-Node-Environment/m-p/2533743#M32308</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I won't advise removing the self-signed cert. This is required for internal service communications (even on single node).&lt;/P&gt;&lt;P&gt;It gets used by the Qliksense services ONLY. (not remote/application access)&lt;/P&gt;&lt;P&gt;For application access (QMC/Hub), you can change/use a SSL cert.&lt;/P&gt;&lt;P&gt;But the self-sign cert has to remain.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 13:45:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/QlikServiceCluster-Certificate-in-Single-Node-Environment/m-p/2533743#M32308</guid>
      <dc:creator>SivenM2020</dc:creator>
      <dc:date>2025-10-17T13:45:04Z</dc:date>
    </item>
  </channel>
</rss>

