<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/ta-p/1715975</link>
    <description>&lt;P&gt;A third-party certificate was configured in the Qlik Sense Proxy, but is not being used.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;The connection is not private" NET::ERR_CERT_COMMON_NAME_INVALID &lt;/FONT&gt;may be displayed on HUB access.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Qlik Sense Enterprise on Windows uses self-signed and self-generated certificates to protect communication between services, as well as user web traffic to the hub and management console.&amp;nbsp; It is possible to use a third-party-issued SSL certificate to protect client web traffic. Using the self-signed certificate will cause a certificate warning to be displayed in the web browser (such as Google Chrome or Internet Explorer).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If the third-party certificate for the Qlik Sense Proxy Service is not fully compatible with Qlik Sense or it does not have the correct attributes and cyphers, the Qlik Sense Repository Service will revert to using the default certificates. The following error may occur in the Proxy Security logs:&lt;BR /&gt;&lt;BR /&gt;Example:&amp;nbsp;&amp;nbsp;&lt;FONT face="courier new,courier"&gt;C:\ProgramData\Qlik\Sense\Log\Proxy\Trace\HOSTNAME_Security_Proxy.txt&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;No private key found for certificate 'CN=qliksense.domain.com' ([CERTIFICATE THUMBPRINT HERE]) Couldn't find a valid ssl certificate with thumbprint [CERTIFICATE THUMBPRINT HERE] Reverting to default Qlik Sense SSLCertificate Set certificate 'CN=qliksenseserver1.domain.com' ([CERTIFICATE THUMBPRINT HERE]) as SSL certificate presented to browser&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;In order for Qlik Sense Enterprise to correctly recognize the third-party certificate as valid, the certificate will have to meet the following requirements:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; Root and Intermediate CA certificates need to be correctly installed. Should any be missing, Qlik Sense proxy will not use the server certificate and will revert back to using the self-signed certificate instead.&lt;BR /&gt;&lt;BR /&gt;Certificates that are known to work well with Qlik Sense have the following attributes:&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Certificates that are x509 version 3. More information including filename extensions under &lt;A href="https://en.wikipedia.org/wiki/X.509" target="_blank" rel="noopener"&gt;https://en.wikipedia.org/wiki/X.509&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Use signature algorithm sha256RSA&lt;/LI&gt;
&lt;LI&gt;Use signature hash algorithm sha256&lt;/LI&gt;
&lt;LI&gt;Signed by a valid, and OS/browser configured , CA&lt;/LI&gt;
&lt;LI&gt;Are valid according to date restrictions (valid from/valid to)&lt;/LI&gt;
&lt;LI&gt;Key in format&amp;nbsp;CryptoAPI (not in CNG)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The certificate itself has to contain private key no matter what Qlik Sense version.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="QS Cert Compatibility.gif" style="width: 800px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/45174iCB26E90955BB54EE/image-size/large?v=v2&amp;amp;px=999" role="button" title="QS Cert Compatibility.gif" alt="QS Cert Compatibility.gif" /&gt;&lt;/span&gt;&lt;/H3&gt;
&lt;H3&gt;&amp;nbsp;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Related Content:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-Change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773" target="_blank" rel="noopener"&gt;How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Feb 2023 12:18:39 GMT</pubDate>
    <dc:creator>Mario_Petre</dc:creator>
    <dc:date>2023-02-21T12:18:39Z</dc:date>
    <item>
      <title>Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/ta-p/1715975</link>
      <description>&lt;P&gt;A third-party certificate was configured in the Qlik Sense Proxy, but is not being used.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;The connection is not private" NET::ERR_CERT_COMMON_NAME_INVALID &lt;/FONT&gt;may be displayed on HUB access.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Qlik Sense Enterprise on Windows uses self-signed and self-generated certificates to protect communication between services, as well as user web traffic to the hub and management console.&amp;nbsp; It is possible to use a third-party-issued SSL certificate to protect client web traffic. Using the self-signed certificate will cause a certificate warning to be displayed in the web browser (such as Google Chrome or Internet Explorer).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If the third-party certificate for the Qlik Sense Proxy Service is not fully compatible with Qlik Sense or it does not have the correct attributes and cyphers, the Qlik Sense Repository Service will revert to using the default certificates. The following error may occur in the Proxy Security logs:&lt;BR /&gt;&lt;BR /&gt;Example:&amp;nbsp;&amp;nbsp;&lt;FONT face="courier new,courier"&gt;C:\ProgramData\Qlik\Sense\Log\Proxy\Trace\HOSTNAME_Security_Proxy.txt&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;No private key found for certificate 'CN=qliksense.domain.com' ([CERTIFICATE THUMBPRINT HERE]) Couldn't find a valid ssl certificate with thumbprint [CERTIFICATE THUMBPRINT HERE] Reverting to default Qlik Sense SSLCertificate Set certificate 'CN=qliksenseserver1.domain.com' ([CERTIFICATE THUMBPRINT HERE]) as SSL certificate presented to browser&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;In order for Qlik Sense Enterprise to correctly recognize the third-party certificate as valid, the certificate will have to meet the following requirements:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; Root and Intermediate CA certificates need to be correctly installed. Should any be missing, Qlik Sense proxy will not use the server certificate and will revert back to using the self-signed certificate instead.&lt;BR /&gt;&lt;BR /&gt;Certificates that are known to work well with Qlik Sense have the following attributes:&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Certificates that are x509 version 3. More information including filename extensions under &lt;A href="https://en.wikipedia.org/wiki/X.509" target="_blank" rel="noopener"&gt;https://en.wikipedia.org/wiki/X.509&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Use signature algorithm sha256RSA&lt;/LI&gt;
&lt;LI&gt;Use signature hash algorithm sha256&lt;/LI&gt;
&lt;LI&gt;Signed by a valid, and OS/browser configured , CA&lt;/LI&gt;
&lt;LI&gt;Are valid according to date restrictions (valid from/valid to)&lt;/LI&gt;
&lt;LI&gt;Key in format&amp;nbsp;CryptoAPI (not in CNG)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The certificate itself has to contain private key no matter what Qlik Sense version.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="QS Cert Compatibility.gif" style="width: 800px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/45174iCB26E90955BB54EE/image-size/large?v=v2&amp;amp;px=999" role="button" title="QS Cert Compatibility.gif" alt="QS Cert Compatibility.gif" /&gt;&lt;/span&gt;&lt;/H3&gt;
&lt;H3&gt;&amp;nbsp;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Related Content:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-Change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773" target="_blank" rel="noopener"&gt;How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 12:18:39 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/ta-p/1715975</guid>
      <dc:creator>Mario_Petre</dc:creator>
      <dc:date>2023-02-21T12:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2039510#M8435</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/39663"&gt;@Andre_Sostizzo&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;I wanted to check in and see if there are any updates to certificate attribute requirements. &lt;STRONG&gt;SHA1&lt;/STRONG&gt; hashing algorithm is not considered reliable anymore and &lt;A href="https://learn.microsoft.com/en-us/windows/win32/seccrypto/cryptographic-service-providers" target="_blank" rel="noopener"&gt;CryptoAPI has been deprecated&lt;/A&gt; for more than two years now.&lt;/P&gt;
&lt;P&gt;I'm assuming newer versions of Qlik Sense support more secure hashing algorithms and CNG providers but I can't find updated list of certificate requirements anywhere.&lt;/P&gt;
&lt;P&gt;Would you be able to either provide a link to updated requirements or update this post that modern versions of Qlik Sense support?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Mikhail B.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2023 02:53:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2039510#M8435</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2023-02-18T02:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040315#M8447</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/50422"&gt;@mbespartochnyy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out!&lt;/P&gt;
&lt;P&gt;Let me look into this for you.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 11:24:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040315#M8447</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2023-02-21T11:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040425#M8449</link>
      <description>&lt;P&gt;Thanks for looking into this, Sonja! I appreciate it.&lt;/P&gt;
&lt;P&gt;Also, a side note, the very last point in the list of requirements above states:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;"&lt;EM&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;The certificate&lt;/STRONG&gt;&lt;/FONT&gt; itself has to contain private key no matter what Qlik Sense version.&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;Certificates, as far as I know, don't contain a&amp;nbsp;&lt;STRONG&gt;private&lt;/STRONG&gt; key. They contain a&amp;nbsp;&lt;STRONG&gt;public&lt;/STRONG&gt; key. More specifically, certificates contain a &lt;STRONG&gt;modulus&lt;/STRONG&gt; and an &lt;STRONG&gt;exponent&lt;/STRONG&gt; which are used to calculate a &lt;STRONG&gt;public&lt;/STRONG&gt; key. &lt;STRONG&gt;Private&lt;/STRONG&gt; key is securely stored on a server and &lt;STRONG&gt;never&lt;/STRONG&gt; shared, unlike a certificate which is shared with every client PC requesting interaction with a server.&lt;/P&gt;
&lt;P&gt;I believe that point should say:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;"&lt;EM&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;The server&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;on which Qlik Sense is installed has to contain private key that is corresponding to public key contained within a certificate no matter what Qlik Sense version.&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;Mikhail B.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 14:46:11 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040425#M8449</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2023-02-21T14:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040444#M8451</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/50422"&gt;@mbespartochnyy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The private key statement does apply and refers to whether or not you import a certificate which has been exported to include a private key. See &lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773#toc-hId--1670032943" target="_blank" rel="noopener"&gt;Requirements, or: What to look out for when getting your cert.&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-manage-the-Certificate-Private-Key/ta-p/1716593" target="_blank" rel="noopener"&gt;How to manage the Certificate Private Key&lt;/A&gt;. If a certificate is used which does not include this, the Qlik Sense Proxy will discard it and revert to the default self-signed certificate.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:18:01 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040444#M8451</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2023-02-21T15:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040549#M8453</link>
      <description>&lt;P&gt;Interesting. I've never heard of certificate containing a&amp;nbsp;&lt;STRONG&gt;private&lt;/STRONG&gt; key. Ever the message in the Certificate window in the GIF in this post and a screenshot in&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773#toc-hId--1670032943" target="_self"&gt; Requirements, or: What to look out for when getting your cert&lt;/A&gt;&amp;nbsp;post that you've mentioned both says:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;"&lt;EM&gt;&lt;STRONG&gt;You&lt;/STRONG&gt; have a private key that &lt;STRONG&gt;corresponds to&lt;/STRONG&gt; this certificate.&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;Public / private key pair is generated &lt;STRONG&gt;on a server&lt;/STRONG&gt; and private key is stored in a secured key store on the server never to be shared with anyone including a CA. &lt;STRONG&gt;Public&lt;/STRONG&gt; key along with &lt;STRONG&gt;server and organization information&lt;/STRONG&gt; is included in a &lt;STRONG&gt;CSR&lt;/STRONG&gt; and sent to a &lt;STRONG&gt;CA&lt;/STRONG&gt; for verification and signing. CA, once verifies identity of a requester, then &lt;STRONG&gt;signs&lt;/STRONG&gt; a certificate containing &lt;STRONG&gt;server's identity&lt;/STRONG&gt; and &lt;STRONG&gt;public key&lt;/STRONG&gt; and send the signed certificate back to the server.&amp;nbsp;A server then uses this signed certificate to distribute it to client PCs. Client PCs validate CA signature from the certificate it receives from the server and, if validations is successful, client PC then use &lt;STRONG&gt;public&lt;/STRONG&gt; key which is included in a certificate to securely exchange &lt;STRONG&gt;session keys&lt;/STRONG&gt;. Server uses its securely saved &lt;STRONG&gt;private&lt;/STRONG&gt; key to decrypt session keys and use the session keys to secure client / server communications from that point on.&lt;/P&gt;
&lt;P&gt;It makes sense for client PCs to ignore certificates if a&amp;nbsp;&lt;STRONG&gt;server doesn't have a corresponding private key&lt;/STRONG&gt; because Qlik Sense server&amp;nbsp;&lt;STRONG&gt;wouldn't be able to decrypt session keys&lt;/STRONG&gt; it receives from client PC. Also a certificate is imported&amp;nbsp;&lt;STRONG&gt;for which&lt;/STRONG&gt;&amp;nbsp;a server &lt;STRONG&gt;does not&lt;/STRONG&gt; own a private key, that server wouldn't be able to use that certificate. I can't find anything on workings of PKI or TLS/SSL that suggest that private keys are ever &lt;STRONG&gt;contained within&lt;/STRONG&gt; a certificate. Not to say that it's not possible. Do you have anything that you can share that would support the idea that private keys are included in certificates?&lt;/P&gt;
&lt;P&gt;Mikhail B.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 18:04:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040549#M8453</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2023-02-21T18:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040596#M8457</link>
      <description>&lt;P&gt;Just reread your message and noticed that you mentioned&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;exporting&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of certificates. Certificates&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;can&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;be exported along with a private key. However export of certificate and private key is a step that someone would take during a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;backup&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;process to ensure successful restoration of a Qlik Sense site rather than installing a newly received certificate from a CA.&lt;/P&gt;
&lt;P&gt;Since the topic of this post is third-party certificates and the requirements of third-party certificates, I don't believe a statement like "&lt;EM&gt;[Third-party] certificate itself has to contain private key...&lt;/EM&gt;" is accurate.&lt;/P&gt;
&lt;P&gt;Mikhail B.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 19:43:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2040596#M8457</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2023-02-21T19:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2157811#M11021</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/50422"&gt;@mbespartochnyy&lt;/a&gt;&amp;nbsp;I'm also facing issue "&lt;SPAN&gt;NET::ERR_CERT_COMMON_NAME_INVALID" . I tried all the ways, but still facing this error on developer&amp;nbsp;tool.&amp;nbsp; any suggestion. pls.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 10:30:16 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2157811#M11021</guid>
      <dc:creator>balajibc64</dc:creator>
      <dc:date>2024-01-03T10:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2157834#M11025</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/216914"&gt;@balajibc64&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please post about your issue in detail in the &lt;A href="https://community.qlik.com/t5/qlik-nprinting/bd-p/qlik-nprinting-discussions" target="_blank" rel="noopener"&gt;Qlik NPrinting&lt;/A&gt; forum.&lt;/P&gt;
&lt;P&gt;Include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The version of the product&lt;/LI&gt;
&lt;LI&gt;What you are attempting to do&lt;/LI&gt;
&lt;LI&gt;What steps you performed&lt;/LI&gt;
&lt;LI&gt;Where the steps fail and where you are seeing errors&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Feel free to tag me in the post.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 11:35:48 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2157834#M11025</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-01-03T11:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2470798#M14268</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp; Are there any news on the question that&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/50422"&gt;@mbespartochnyy&lt;/a&gt;&amp;nbsp;has raised concerning&lt;SPAN&gt;&amp;nbsp;more secure hashing algorithms and CNG providers or an updated list of certificate requirements?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 21:11:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2470798#M14268</guid>
      <dc:creator>tloe_4ebit</dc:creator>
      <dc:date>2024-07-15T21:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2470840#M14269</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/155078"&gt;@tloe_4ebit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recommend logging a support ticket regarding this so that the question reaches our Security Office and is appropriately investigated.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 04:37:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2470840#M14269</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-07-16T04:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2530393#M16343</link>
      <description>&lt;UL&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/50422"&gt;@mbespartochnyy&lt;/a&gt;&amp;nbsp; do you understand how the &lt;SPAN&gt;private keys are included in certificate? Even I need to guide our team to get one&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 10 Sep 2025 14:36:00 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2530393#M16343</guid>
      <dc:creator>fabdulazeez</dc:creator>
      <dc:date>2025-09-10T14:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2530408#M16344</link>
      <description>&lt;P&gt;My understanding is that a &lt;STRONG&gt;private&lt;/STRONG&gt; key is &lt;STRONG&gt;not&lt;/STRONG&gt; included &lt;STRONG&gt;in a certificate&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;As far as I know, when we run a certreq command to create a certificate signing request (CSR) to have a certification authority generate a certificate for Qlik Sense server, the certreq command &lt;STRONG&gt;creates and securely stores a private key&lt;/STRONG&gt; on the server where CSR was created.&lt;/P&gt;&lt;P&gt;The CSR is then sent to the certification authority (CA) and the CA generates a certificate that we can use on a Qlik Sense server.&lt;/P&gt;&lt;P&gt;When we import the certificate from the CA to the Qlik Sense server using Microsoft Management Console, the server does the check to see if &lt;STRONG&gt;the server&lt;/STRONG&gt; has a private key for the imported certificate. If it does, then we see this message:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20. Confirm that You have a private key message is shown.jpg" style="width: 405px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/183570iB48F34E2BBA2874C/image-size/large?v=v2&amp;amp;px=999" role="button" title="20. Confirm that You have a private key message is shown.jpg" alt="20. Confirm that You have a private key message is shown.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When we export a certificate during the backup process, we can export the certificate &lt;STRONG&gt;AND&lt;/STRONG&gt; a private key, but a &lt;STRONG&gt;certificate&lt;/STRONG&gt; and &lt;STRONG&gt;private key&lt;/STRONG&gt; are &lt;STRONG&gt;two&lt;/STRONG&gt; different things. They work together, but they're &lt;STRONG&gt;two distinct pieces&lt;/STRONG&gt;, not one.&lt;/P&gt;&lt;P&gt;If your certificate &lt;STRONG&gt;doesn't&lt;/STRONG&gt; have a corresponding private key, there's a process of "re-binding" a certificate to a private key but it's a bit tricky. If your company has its own internal certification authority (it's very likely that it does), it's probably easier to just &lt;STRONG&gt;create a new CSR&lt;/STRONG&gt;, have your company's CA &lt;STRONG&gt;create a new certificate&lt;/STRONG&gt;, &lt;STRONG&gt;import the new certificate&lt;/STRONG&gt;, and &lt;STRONG&gt;update proxy settings&lt;/STRONG&gt; in QMC to use the new certificate.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 16:59:37 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2530408#M16344</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2025-09-10T16:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2530442#M16346</link>
      <description>&lt;P&gt;We are using a wild card ssl certificate from a third party. So the CSR was not generated on Qlik server as the certificate is used on&amp;nbsp; multiple servers. Can you let me know how can I add private key to the certificate. I have .crt file,.p7b file and ca-bundle&amp;nbsp; file.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/49970"&gt;@Mario_Petre&lt;/a&gt;&amp;nbsp;can you help me on this.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 00:49:11 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/tac-p/2530442#M16346</guid>
      <dc:creator>fabdulazeez</dc:creator>
      <dc:date>2025-09-11T00:49:11Z</dc:date>
    </item>
  </channel>
</rss>

