<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="header error.png" style="width: 553px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16334i56C495899ABAD08D/image-size/large?v=v2&amp;amp;px=999" role="button" title="header error.png" alt="header error.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Content:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-TOC indent="15" liststyle="none" maxheadinglevel="4"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you’ve just installed &lt;STRONG&gt;Qlik Sense Enterprise&lt;/STRONG&gt;, then this image probably looks familiar. Alternatively, Chrome might display &lt;FONT face="courier new,courier"&gt;The site's security certificate is not trusted&lt;/FONT&gt;, while Firefox may report &lt;FONT face="courier new,courier"&gt;This Connection is Untrusted&lt;/FONT&gt;.&lt;/P&gt;
&lt;P&gt;By default, Qlik Sense uses a self-signed certificate to enable HTTPS access across both the Hub (&lt;FONT face="courier new,courier"&gt;https:// YourSenseServer/hub&lt;/FONT&gt;) and the Management Console (&lt;FONT face="courier new,courier"&gt;&lt;A href="https://YourSenseServer/qmc" target="_blank" rel="noopener"&gt;https://YourSenseServer/qmc&lt;/A&gt;&lt;/FONT&gt;). But self-signed certificates cannot be validated or trusted by web browsers and tend to prompt a warning message.&lt;/P&gt;
&lt;P&gt;To establish a secure HTTPS connection, the browser must trust the SSL/TLS certificate installed on the server. In the case of self-signed certificates, the signing Certificate Authority is not trusted, hence no certificates generated by the CA are trusted.&lt;/P&gt;
&lt;P&gt;To install a &lt;STRONG&gt;trusted&amp;nbsp;&lt;/STRONG&gt;certificate for use with the Qlik Sense Enterprise on Windows Hub and Management Console,&amp;nbsp;we need:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;An additional (signed) certificate.&lt;/LI&gt;
&lt;LI&gt;A brief (5 minute) downtime of the Qlik Sense Proxy.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;These instructions are for replacing the certificate used for accessing the Qlik Sense Hub and Management Console. The certificate used for service communication&amp;nbsp;&lt;EM&gt;cannot&amp;nbsp;&lt;/EM&gt;be replaced.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FmRleBx6gBA0%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DmRleBx6gBA0&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FmRleBx6gBA0%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="600" height="337" scrolling="no" title="Resolving common web browser certificate errors and changing the certificate used by Hub and QMC" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;A href="https://community.qlik.com/t5/Video-Transcripts/Resolving-common-web-browser-certificate-errors-and-changing-the/ta-p/1752481" target="_blank" rel="noopener"&gt;For video Transcript click here&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;About&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;What is the current certificate used for?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;During the initial install, the Qlik Sense Repository Service creates a set of certificates. Their purpose is to secure &lt;STRONG&gt;Service Communication &lt;/STRONG&gt;and &lt;STRONG&gt;Service Authentication.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Qlik Sense uses certificates to authenticate its service across all nodes. See the &lt;A href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Deploy_QSEoW/Certificates.htm" target="_blank" rel="noopener"&gt;Qlik Sense Online Help&lt;/A&gt; for details. In addition, other products (such as Qlik NPrinting) require these certificates to be establish a connection.&lt;/P&gt;
&lt;P&gt;This self-signed certificate is then also used to secure hub and Management Console access through&amp;nbsp;&lt;STRONG&gt;HTTPS&lt;/STRONG&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;We will not modify, replace, or remove the originally created certificates. Doing so will break service communication.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What we’ll do instead is to &lt;STRONG&gt;&lt;EM&gt;add &lt;/EM&gt;&lt;/STRONG&gt;an additional one.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Certificate options, or: What type of certificate is right for me?&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;There are three possible types of certificates for us to use.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A certificate purchased from and &lt;STRONG&gt;signed by a trusted CA&lt;/STRONG&gt; (Certificate Authority) such as VeriSign, Thawte, Geotrust, etc.&lt;/LI&gt;
&lt;LI&gt;A certificate provided and &lt;STRONG&gt;signed by your own Enterprise CA&lt;/STRONG&gt; (Certificate Authority).&lt;/LI&gt;
&lt;LI&gt;And, of course, a &lt;STRONG&gt;self-signed one&lt;/STRONG&gt;. Those can be created by any number of applications, such as Microsoft IIS, but is generally only recommended for test environments. More so, it has the potential side effect of teaching users to ignore browser warnings, which we do not want.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Requirements, or: What to look out for when getting your cert.&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;The certificate must follow these requirements:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/ta-p/1715975" target="_blank" rel="noopener"&gt;Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The certificate itself must contain a private key&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Has an up to date valid from / valid to date range&lt;/LI&gt;
&lt;LI&gt;Is signed by a valid and OS or browser configured Certificate Authority&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When support gets questions, they are most often related to a certificate missing the &lt;STRONG&gt;private key&lt;/STRONG&gt;. Always verify the certificate comes bundled with one when you install it.&lt;/P&gt;
&lt;P&gt;It’ll look like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="private key okay.png" style="width: 328px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16336i21C4A013A9974945/image-size/large?v=v2&amp;amp;px=999" role="button" title="private key okay.png" alt="private key okay.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Where to get a certificate and how to do a CSR?&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;EM&gt;The Certificate Authority you chose will have instructions for this, and if you are looking to get a self-signed one or one from your corporation's CA, then a local administrator can provide the certificate to you.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Either way, you are going to need to generate a &lt;STRONG&gt;Certificate Signing Request&lt;/STRONG&gt; (&lt;STRONG&gt;CSR&lt;/STRONG&gt;) to pass on to your CA. There are tools out there to get that done with, such as &lt;STRONG&gt;certreq&lt;/STRONG&gt; from &lt;STRONG&gt;Microsoft&lt;/STRONG&gt; (found &lt;A href="https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/certreq_1" target="_blank" rel="noopener"&gt;here&lt;/A&gt;), and &lt;STRONG&gt;SSLhopper&lt;/STRONG&gt; has &lt;A href="https://www.sslshopper.com/what-is-a-csr-certificate-signing-request.html" target="_blank" rel="noopener"&gt;a great article&lt;/A&gt; on that, which I often send to customers when they ask us about CSRs and how to do them.&lt;/P&gt;
&lt;P&gt;Once you obtain the certificate, we'll move on to installing it and activating it in Qlik Sense. This will be done in three quick steps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Import&lt;/LI&gt;
&lt;LI&gt;Get the Thumbprint&lt;/LI&gt;
&lt;LI&gt;Provide Thumbprint to the Proxy&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Importing the Certificate&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P&gt;As mentioned before, we are not replacing certificates. The already existing ones will not be deleted. Doing so would break service authentication between the individual Qlik Sense services and render the system… broken.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;The 5 Install Steps&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 1: Getting Started&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P&gt;On the Qlik Sense node running the Qlik Sense Proxy, &lt;STRONG&gt;log on with the user running the Sense services.&lt;/STRONG&gt; This is important since the certificate needs to be accessible for this account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 2: Import the certificate&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P&gt;If the certificate was saved in the &lt;STRONG&gt;.pfx&lt;/STRONG&gt; format, then all you need to do is double click the file. Follow the prompt to import the certificate into the Personal store.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="import.png" style="width: 474px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16337i9BF02CD0C3DA2CC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="import.png" alt="import.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT size="5" color="#339966"&gt;Longer Step 2 (manual import):&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;If you want to import it manually or verify if it was correctly installed:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Launch the &lt;STRONG&gt;Microsoft Management Console&lt;/STRONG&gt; (mmc.exe) on the Proxy node&lt;/LI&gt;
&lt;LI&gt;In the MMC, go to &lt;FONT face="courier new,courier"&gt;File&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Add / Remove Snap-in...&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;Select &lt;FONT face="courier new,courier"&gt;Certificates&lt;/FONT&gt; and click &lt;FONT face="courier new,courier"&gt;Add&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;Select &lt;FONT face="courier new,courier"&gt;Computer account&lt;/FONT&gt;, click &lt;FONT face="courier new,courier"&gt;Next&lt;/FONT&gt;, select &lt;FONT face="courier new,courier"&gt;Local computer&lt;/FONT&gt; and click &lt;FONT face="courier new,courier"&gt;Finish&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mmc.png" style="width: 542px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16339i7D216BBE530914D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="mmc.png" alt="mmc.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;In the MMC, go to &lt;FONT face="courier new,courier"&gt;Certificates (Local Computer)/Personal&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;In the MMC, go to &lt;FONT face="courier new,courier"&gt;Actions&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;All Tasks&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Import...&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;Browse to the certificate file provided to you from your CA&lt;/LI&gt;
&lt;LI&gt;Follow the instructions on the screen to import the certificate, &lt;STRONG&gt;including the private key&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Verify the new certificate has been imported into &lt;FONT face="courier new,courier"&gt;Certificates (Local Computer)&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Personal&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Certificates&lt;/FONT&gt; and that it contains a private key&lt;/LI&gt;
&lt;LI&gt;Double-click the &lt;FONT face="courier new,courier"&gt;Certificate&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Certification Path&lt;/FONT&gt; and confirm it shows "&lt;FONT face="courier new,courier"&gt;This certificate is OK&lt;/FONT&gt;"&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert okay.png" style="width: 385px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16340i520216362D2A7A03/image-size/large?v=v2&amp;amp;px=999" role="button" title="cert okay.png" alt="cert okay.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 3: &lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Getting the Thumbprint&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Well, since we are already in the MMC, let's open the freshly installed certificate again.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Switch to the Details tab and scroll down until you find Thumbprint&lt;/LI&gt;
&lt;LI&gt;Mark the entire thing and copy it into, for example, Notepad.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thumbprint get.png" style="width: 402px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16341i1C6A58D16EA4901C/image-size/large?v=v2&amp;amp;px=999" role="button" title="thumbprint get.png" alt="thumbprint get.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 4: &lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt; Configuring the Qlik Sense Proxy&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Almost done!&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open the &lt;FONT face="courier new,courier"&gt;Qlik Sense Management Console&lt;/FONT&gt; (QMC)&lt;/LI&gt;
&lt;LI&gt;Go to &lt;FONT face="courier new,courier"&gt;Proxies&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;Double click&lt;/EM&gt; the Proxy you want to use (or select and choose &lt;FONT face="courier new,courier"&gt;Edit&lt;/FONT&gt;)&lt;/LI&gt;
&lt;LI&gt;Enable the &lt;FONT face="courier new,courier"&gt;Security&lt;/FONT&gt; options in the &lt;FONT face="courier new,courier"&gt;Properties&lt;/FONT&gt; panel on the right&lt;/LI&gt;
&lt;LI&gt;Paste the certificate &lt;FONT face="courier new,courier"&gt;Thumbprint&lt;/FONT&gt; into the SSL browser certificate thumbprint text box.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Click &lt;FONT face="courier new,courier"&gt;Apply&lt;/FONT&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="add thumbprint.png" style="width: 721px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16343i9BF74FDA5C99DF36/image-size/large?v=v2&amp;amp;px=999" role="button" title="add thumbprint.png" alt="add thumbprint.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The Sense Proxy will now restart&lt;/STRONG&gt;. During the restart, it will be using Windows API calls to correctly bind the new certificate to its SSL ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 5:&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Verification, or: How to prove the certificate was accepted.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;In the web browser:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;When opening the Qlik Sense Hub or QMC, the certificate will now be displayed in the browser. This may look different depending on the web browser, but in Google Chrome you can click the padlock to the left of the URL to verify what certificate is used.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkcert.png" style="width: 450px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16344iD6325B2100107781/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkcert.png" alt="checkcert.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The information displayed needs to match the properties of the certificate you installed.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkcert2.png" style="width: 398px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16345i46718D7D061191F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkcert2.png" alt="checkcert2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;In the log files:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;If you’d rather see what the Qlik Sense Proxy service is doing, then you can directly check up on that, too.&lt;/P&gt;
&lt;P&gt;On the Proxy node, go to &lt;FONT face="courier new,courier"&gt;C:\ProgramData\Qlik\Sense\Log\Proxy\Trace&lt;/FONT&gt; and open the &lt;FONT face="courier new,courier"&gt;Security&lt;/FONT&gt; log file from just after the last start.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It will now print a slightly different message than before:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Security.Proxy.Qlik.Sense.Common.Security.Cryptography.LoggingDigester&amp;nbsp;&amp;nbsp;&amp;nbsp; DOMAIN\_service&amp;nbsp;&amp;nbsp;&amp;nbsp; Setting crypto key for log file secure signing: success&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Security.Proxy.Qlik.Sense.Common.Security.Cryptography.SecretsKey&amp;nbsp;&amp;nbsp;&amp;nbsp; DOMAIN\_service&amp;nbsp;&amp;nbsp;&amp;nbsp; retrieving symmetric key from cert: success&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Security.Proxy.Qlik.Sense.Common.Security.Cryptography.CryptoKey&amp;nbsp;&amp;nbsp;&amp;nbsp; DOMAIN\_service&amp;nbsp;&amp;nbsp;&amp;nbsp; setting crypto key: success&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Security.Proxy.Qlik.Sense.Communication.Security.CertSetup&amp;nbsp;&amp;nbsp;&amp;nbsp; 'CN=localhost' (08C871933A58E072FED7AD65E2DB6D5AD3EAF9FA) as SSL certificate presented to browser, which is a 3rd party SSL certificate&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;And that's it!&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;There isn't much more to it in a standard Qlik Sense Enterprise installation, but if you have more questions, then maybe a few of these articles can help:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Receiving Bad Request 400?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Make sure the URL/FQDN you are using to access the Hub and QMC is correctly added to the WebSocket Allow List:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/How-to-configure-the-WebSocket-origin-allow-list-and-best/ta-p/1716765" target="_blank" rel="noopener"&gt;How to configure the WebSocket origin allow list and best practices &lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I applied my certificate and it seems to be using it correctly, but browsers are still saying the Common Name is Invalid?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/ERR-CERT-COMMON-NAME-INVALID-when-using-3rd-party-certificate/ta-p/1715606" target="_blank" rel="noopener"&gt;ERR_CERT_COMMON_NAME_INVALID when using 3rd party certificate&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Qlik Sense keeps reverting to the default and complains it can't find a valid ssl certificate with the thumbprint.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/Couldn-t-find-a-valid-ssl-certificate-with-thumbprint-and-the/ta-p/1715455" target="_blank" rel="noopener"&gt;Qlik Sense: Couldn't find a valid ssl certificate with thumbprint in Proxy logs, the third party certificate is not used correctly&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;The certificate may not have a Private key or the service account does not have access to it.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/How-to-manage-the-Certificate-Private-Key/ta-p/1716593" target="_blank" rel="noopener"&gt;How to: Manage Certificate Private Key&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The Qlik Sense Service account doesn't have admin privileges and the certificate is not accepted.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/How-to-Change-the-Qlik-Sense-Proxy-certificate-if-the-service/ta-p/1716657" target="_blank" rel="noopener"&gt;How to: Change the Qlik Sense Proxy certificate if the service account does not have local administrative permissions&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Related Content:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Updates-Blog/Qlik-Sense-Hub-and-QMC-with-a-custom-SSL-certificate/ba-p/1608077" target="_blank" rel="noopener"&gt;Qlik Sense Hub and QMC with custom SSL certificate&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/A-certificate-error-or-warning-is-displayed-in-the-browser-when/ta-p/1715412" target="_blank" rel="noopener"&gt;A certificate error or warning is displayed in the browser when accessing the Qlik Sense Hub or Management Console&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/change-to-signed-server-proxy-certificate.htm" target="_blank" rel="noopener"&gt;Qlik Sense - Changing to a signed server proxy certificate&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/September2020/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/change-proxy-certificate.htm" target="_blank" rel="noopener"&gt;Qlik Sense - Changing a proxy certificate&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/ERR-CERT-COMMON-NAME-INVALID-when-using-3rd-party-certificate/ta-p/1715606" target="_blank" rel="noopener"&gt;ERR_CERT_COMMON_NAME_INVALID when using 3rd party certificate&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Qlik-Sense-Compatibility-information-for-third-party-SSL/ta-p/1715975" target="_blank" rel="noopener"&gt;Qlik Sense: Compatibility information for third-party SSL certificates to use with HUB/QMC&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://community.qlik.com/t5/Support-Knowledge-Base/Requirements-for-configuring-Qlik-Sense-with-SSL/ta-p/1715916?_ga=2.9826422.2114727983.1602514418-577020889.1572878749" target="_blank" rel="noopener"&gt;Requirements for configuring Qlik Sense with SSL&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/Couldn-t-find-a-valid-ssl-certificate-with-thumbprint-and-the/ta-p/1715455" target="_blank" rel="noopener"&gt;Couldn't find a valid ssl certificate with thumbprint and the incorrect certificate used on hub&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A title="How to: Change the Qlik Sense Proxy certificate if the service account does not have local administrative permissions" href="https://community.qlik.com/t5/Knowledge-Base/How-to-Change-the-Qlik-Sense-Proxy-certificate-if-the-service/ta-p/1716657" target="_blank" rel="noopener"&gt;How to: Change the Qlik Sense Proxy certificate if the service account does not have local administrative&amp;nbsp;permissions&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/NET-ERR-CERT-AUTHORITY-INVALID/ta-p/1715928" target="_blank" rel="noopener"&gt;NET::ERR_CERT_AUTHORITY_INVALID&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 13 Apr 2026 11:33:49 GMT</pubDate>
    <dc:creator>Bjorn_Wedbratt</dc:creator>
    <dc:date>2026-04-13T11:33:49Z</dc:date>
    <item>
      <title>How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="header error.png" style="width: 553px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16334i56C495899ABAD08D/image-size/large?v=v2&amp;amp;px=999" role="button" title="header error.png" alt="header error.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Content:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-TOC indent="15" liststyle="none" maxheadinglevel="4"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you’ve just installed &lt;STRONG&gt;Qlik Sense Enterprise&lt;/STRONG&gt;, then this image probably looks familiar. Alternatively, Chrome might display &lt;FONT face="courier new,courier"&gt;The site's security certificate is not trusted&lt;/FONT&gt;, while Firefox may report &lt;FONT face="courier new,courier"&gt;This Connection is Untrusted&lt;/FONT&gt;.&lt;/P&gt;
&lt;P&gt;By default, Qlik Sense uses a self-signed certificate to enable HTTPS access across both the Hub (&lt;FONT face="courier new,courier"&gt;https:// YourSenseServer/hub&lt;/FONT&gt;) and the Management Console (&lt;FONT face="courier new,courier"&gt;&lt;A href="https://YourSenseServer/qmc" target="_blank" rel="noopener"&gt;https://YourSenseServer/qmc&lt;/A&gt;&lt;/FONT&gt;). But self-signed certificates cannot be validated or trusted by web browsers and tend to prompt a warning message.&lt;/P&gt;
&lt;P&gt;To establish a secure HTTPS connection, the browser must trust the SSL/TLS certificate installed on the server. In the case of self-signed certificates, the signing Certificate Authority is not trusted, hence no certificates generated by the CA are trusted.&lt;/P&gt;
&lt;P&gt;To install a &lt;STRONG&gt;trusted&amp;nbsp;&lt;/STRONG&gt;certificate for use with the Qlik Sense Enterprise on Windows Hub and Management Console,&amp;nbsp;we need:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;An additional (signed) certificate.&lt;/LI&gt;
&lt;LI&gt;A brief (5 minute) downtime of the Qlik Sense Proxy.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;These instructions are for replacing the certificate used for accessing the Qlik Sense Hub and Management Console. The certificate used for service communication&amp;nbsp;&lt;EM&gt;cannot&amp;nbsp;&lt;/EM&gt;be replaced.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FmRleBx6gBA0%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DmRleBx6gBA0&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FmRleBx6gBA0%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="600" height="337" scrolling="no" title="Resolving common web browser certificate errors and changing the certificate used by Hub and QMC" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;A href="https://community.qlik.com/t5/Video-Transcripts/Resolving-common-web-browser-certificate-errors-and-changing-the/ta-p/1752481" target="_blank" rel="noopener"&gt;For video Transcript click here&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;About&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;What is the current certificate used for?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;During the initial install, the Qlik Sense Repository Service creates a set of certificates. Their purpose is to secure &lt;STRONG&gt;Service Communication &lt;/STRONG&gt;and &lt;STRONG&gt;Service Authentication.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Qlik Sense uses certificates to authenticate its service across all nodes. See the &lt;A href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Deploy_QSEoW/Certificates.htm" target="_blank" rel="noopener"&gt;Qlik Sense Online Help&lt;/A&gt; for details. In addition, other products (such as Qlik NPrinting) require these certificates to be establish a connection.&lt;/P&gt;
&lt;P&gt;This self-signed certificate is then also used to secure hub and Management Console access through&amp;nbsp;&lt;STRONG&gt;HTTPS&lt;/STRONG&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;We will not modify, replace, or remove the originally created certificates. Doing so will break service communication.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What we’ll do instead is to &lt;STRONG&gt;&lt;EM&gt;add &lt;/EM&gt;&lt;/STRONG&gt;an additional one.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Certificate options, or: What type of certificate is right for me?&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;There are three possible types of certificates for us to use.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A certificate purchased from and &lt;STRONG&gt;signed by a trusted CA&lt;/STRONG&gt; (Certificate Authority) such as VeriSign, Thawte, Geotrust, etc.&lt;/LI&gt;
&lt;LI&gt;A certificate provided and &lt;STRONG&gt;signed by your own Enterprise CA&lt;/STRONG&gt; (Certificate Authority).&lt;/LI&gt;
&lt;LI&gt;And, of course, a &lt;STRONG&gt;self-signed one&lt;/STRONG&gt;. Those can be created by any number of applications, such as Microsoft IIS, but is generally only recommended for test environments. More so, it has the potential side effect of teaching users to ignore browser warnings, which we do not want.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Requirements, or: What to look out for when getting your cert.&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;The certificate must follow these requirements:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Compatibility-information-for/ta-p/1715975" target="_blank" rel="noopener"&gt;Qlik Sense Enterprise on Windows: Compatibility information for third-party SSL certificates to use with HUB/QMC&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The certificate itself must contain a private key&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Has an up to date valid from / valid to date range&lt;/LI&gt;
&lt;LI&gt;Is signed by a valid and OS or browser configured Certificate Authority&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When support gets questions, they are most often related to a certificate missing the &lt;STRONG&gt;private key&lt;/STRONG&gt;. Always verify the certificate comes bundled with one when you install it.&lt;/P&gt;
&lt;P&gt;It’ll look like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="private key okay.png" style="width: 328px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16336i21C4A013A9974945/image-size/large?v=v2&amp;amp;px=999" role="button" title="private key okay.png" alt="private key okay.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Where to get a certificate and how to do a CSR?&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;EM&gt;The Certificate Authority you chose will have instructions for this, and if you are looking to get a self-signed one or one from your corporation's CA, then a local administrator can provide the certificate to you.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Either way, you are going to need to generate a &lt;STRONG&gt;Certificate Signing Request&lt;/STRONG&gt; (&lt;STRONG&gt;CSR&lt;/STRONG&gt;) to pass on to your CA. There are tools out there to get that done with, such as &lt;STRONG&gt;certreq&lt;/STRONG&gt; from &lt;STRONG&gt;Microsoft&lt;/STRONG&gt; (found &lt;A href="https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/certreq_1" target="_blank" rel="noopener"&gt;here&lt;/A&gt;), and &lt;STRONG&gt;SSLhopper&lt;/STRONG&gt; has &lt;A href="https://www.sslshopper.com/what-is-a-csr-certificate-signing-request.html" target="_blank" rel="noopener"&gt;a great article&lt;/A&gt; on that, which I often send to customers when they ask us about CSRs and how to do them.&lt;/P&gt;
&lt;P&gt;Once you obtain the certificate, we'll move on to installing it and activating it in Qlik Sense. This will be done in three quick steps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Import&lt;/LI&gt;
&lt;LI&gt;Get the Thumbprint&lt;/LI&gt;
&lt;LI&gt;Provide Thumbprint to the Proxy&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Importing the Certificate&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P&gt;As mentioned before, we are not replacing certificates. The already existing ones will not be deleted. Doing so would break service authentication between the individual Qlik Sense services and render the system… broken.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;The 5 Install Steps&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 1: Getting Started&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P&gt;On the Qlik Sense node running the Qlik Sense Proxy, &lt;STRONG&gt;log on with the user running the Sense services.&lt;/STRONG&gt; This is important since the certificate needs to be accessible for this account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 2: Import the certificate&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P&gt;If the certificate was saved in the &lt;STRONG&gt;.pfx&lt;/STRONG&gt; format, then all you need to do is double click the file. Follow the prompt to import the certificate into the Personal store.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="import.png" style="width: 474px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16337i9BF02CD0C3DA2CC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="import.png" alt="import.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT size="5" color="#339966"&gt;Longer Step 2 (manual import):&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;If you want to import it manually or verify if it was correctly installed:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Launch the &lt;STRONG&gt;Microsoft Management Console&lt;/STRONG&gt; (mmc.exe) on the Proxy node&lt;/LI&gt;
&lt;LI&gt;In the MMC, go to &lt;FONT face="courier new,courier"&gt;File&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Add / Remove Snap-in...&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;Select &lt;FONT face="courier new,courier"&gt;Certificates&lt;/FONT&gt; and click &lt;FONT face="courier new,courier"&gt;Add&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;Select &lt;FONT face="courier new,courier"&gt;Computer account&lt;/FONT&gt;, click &lt;FONT face="courier new,courier"&gt;Next&lt;/FONT&gt;, select &lt;FONT face="courier new,courier"&gt;Local computer&lt;/FONT&gt; and click &lt;FONT face="courier new,courier"&gt;Finish&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mmc.png" style="width: 542px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16339i7D216BBE530914D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="mmc.png" alt="mmc.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;In the MMC, go to &lt;FONT face="courier new,courier"&gt;Certificates (Local Computer)/Personal&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;In the MMC, go to &lt;FONT face="courier new,courier"&gt;Actions&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;All Tasks&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Import...&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;Browse to the certificate file provided to you from your CA&lt;/LI&gt;
&lt;LI&gt;Follow the instructions on the screen to import the certificate, &lt;STRONG&gt;including the private key&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Verify the new certificate has been imported into &lt;FONT face="courier new,courier"&gt;Certificates (Local Computer)&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Personal&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Certificates&lt;/FONT&gt; and that it contains a private key&lt;/LI&gt;
&lt;LI&gt;Double-click the &lt;FONT face="courier new,courier"&gt;Certificate&lt;/FONT&gt; &amp;gt; &lt;FONT face="courier new,courier"&gt;Certification Path&lt;/FONT&gt; and confirm it shows "&lt;FONT face="courier new,courier"&gt;This certificate is OK&lt;/FONT&gt;"&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert okay.png" style="width: 385px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16340i520216362D2A7A03/image-size/large?v=v2&amp;amp;px=999" role="button" title="cert okay.png" alt="cert okay.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 3: &lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Getting the Thumbprint&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Well, since we are already in the MMC, let's open the freshly installed certificate again.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Switch to the Details tab and scroll down until you find Thumbprint&lt;/LI&gt;
&lt;LI&gt;Mark the entire thing and copy it into, for example, Notepad.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thumbprint get.png" style="width: 402px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16341i1C6A58D16EA4901C/image-size/large?v=v2&amp;amp;px=999" role="button" title="thumbprint get.png" alt="thumbprint get.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 4: &lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt; Configuring the Qlik Sense Proxy&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Almost done!&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open the &lt;FONT face="courier new,courier"&gt;Qlik Sense Management Console&lt;/FONT&gt; (QMC)&lt;/LI&gt;
&lt;LI&gt;Go to &lt;FONT face="courier new,courier"&gt;Proxies&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;Double click&lt;/EM&gt; the Proxy you want to use (or select and choose &lt;FONT face="courier new,courier"&gt;Edit&lt;/FONT&gt;)&lt;/LI&gt;
&lt;LI&gt;Enable the &lt;FONT face="courier new,courier"&gt;Security&lt;/FONT&gt; options in the &lt;FONT face="courier new,courier"&gt;Properties&lt;/FONT&gt; panel on the right&lt;/LI&gt;
&lt;LI&gt;Paste the certificate &lt;FONT face="courier new,courier"&gt;Thumbprint&lt;/FONT&gt; into the SSL browser certificate thumbprint text box.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Click &lt;FONT face="courier new,courier"&gt;Apply&lt;/FONT&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="add thumbprint.png" style="width: 721px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16343i9BF74FDA5C99DF36/image-size/large?v=v2&amp;amp;px=999" role="button" title="add thumbprint.png" alt="add thumbprint.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The Sense Proxy will now restart&lt;/STRONG&gt;. During the restart, it will be using Windows API calls to correctly bind the new certificate to its SSL ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT size="5" color="#339966"&gt;&lt;STRONG&gt;Step 5:&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Verification, or: How to prove the certificate was accepted.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;In the web browser:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;When opening the Qlik Sense Hub or QMC, the certificate will now be displayed in the browser. This may look different depending on the web browser, but in Google Chrome you can click the padlock to the left of the URL to verify what certificate is used.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkcert.png" style="width: 450px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16344iD6325B2100107781/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkcert.png" alt="checkcert.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The information displayed needs to match the properties of the certificate you installed.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkcert2.png" style="width: 398px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/16345i46718D7D061191F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkcert2.png" alt="checkcert2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;In the log files:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;If you’d rather see what the Qlik Sense Proxy service is doing, then you can directly check up on that, too.&lt;/P&gt;
&lt;P&gt;On the Proxy node, go to &lt;FONT face="courier new,courier"&gt;C:\ProgramData\Qlik\Sense\Log\Proxy\Trace&lt;/FONT&gt; and open the &lt;FONT face="courier new,courier"&gt;Security&lt;/FONT&gt; log file from just after the last start.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It will now print a slightly different message than before:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Security.Proxy.Qlik.Sense.Common.Security.Cryptography.LoggingDigester&amp;nbsp;&amp;nbsp;&amp;nbsp; DOMAIN\_service&amp;nbsp;&amp;nbsp;&amp;nbsp; Setting crypto key for log file secure signing: success&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Security.Proxy.Qlik.Sense.Common.Security.Cryptography.SecretsKey&amp;nbsp;&amp;nbsp;&amp;nbsp; DOMAIN\_service&amp;nbsp;&amp;nbsp;&amp;nbsp; retrieving symmetric key from cert: success&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Security.Proxy.Qlik.Sense.Common.Security.Cryptography.CryptoKey&amp;nbsp;&amp;nbsp;&amp;nbsp; DOMAIN\_service&amp;nbsp;&amp;nbsp;&amp;nbsp; setting crypto key: success&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Security.Proxy.Qlik.Sense.Communication.Security.CertSetup&amp;nbsp;&amp;nbsp;&amp;nbsp; 'CN=localhost' (08C871933A58E072FED7AD65E2DB6D5AD3EAF9FA) as SSL certificate presented to browser, which is a 3rd party SSL certificate&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;And that's it!&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;There isn't much more to it in a standard Qlik Sense Enterprise installation, but if you have more questions, then maybe a few of these articles can help:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Receiving Bad Request 400?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Make sure the URL/FQDN you are using to access the Hub and QMC is correctly added to the WebSocket Allow List:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/How-to-configure-the-WebSocket-origin-allow-list-and-best/ta-p/1716765" target="_blank" rel="noopener"&gt;How to configure the WebSocket origin allow list and best practices &lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I applied my certificate and it seems to be using it correctly, but browsers are still saying the Common Name is Invalid?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/ERR-CERT-COMMON-NAME-INVALID-when-using-3rd-party-certificate/ta-p/1715606" target="_blank" rel="noopener"&gt;ERR_CERT_COMMON_NAME_INVALID when using 3rd party certificate&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Qlik Sense keeps reverting to the default and complains it can't find a valid ssl certificate with the thumbprint.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/Couldn-t-find-a-valid-ssl-certificate-with-thumbprint-and-the/ta-p/1715455" target="_blank" rel="noopener"&gt;Qlik Sense: Couldn't find a valid ssl certificate with thumbprint in Proxy logs, the third party certificate is not used correctly&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;The certificate may not have a Private key or the service account does not have access to it.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/How-to-manage-the-Certificate-Private-Key/ta-p/1716593" target="_blank" rel="noopener"&gt;How to: Manage Certificate Private Key&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The Qlik Sense Service account doesn't have admin privileges and the certificate is not accepted.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/How-to-Change-the-Qlik-Sense-Proxy-certificate-if-the-service/ta-p/1716657" target="_blank" rel="noopener"&gt;How to: Change the Qlik Sense Proxy certificate if the service account does not have local administrative permissions&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Related Content:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Updates-Blog/Qlik-Sense-Hub-and-QMC-with-a-custom-SSL-certificate/ba-p/1608077" target="_blank" rel="noopener"&gt;Qlik Sense Hub and QMC with custom SSL certificate&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/A-certificate-error-or-warning-is-displayed-in-the-browser-when/ta-p/1715412" target="_blank" rel="noopener"&gt;A certificate error or warning is displayed in the browser when accessing the Qlik Sense Hub or Management Console&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/change-to-signed-server-proxy-certificate.htm" target="_blank" rel="noopener"&gt;Qlik Sense - Changing to a signed server proxy certificate&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/September2020/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/change-proxy-certificate.htm" target="_blank" rel="noopener"&gt;Qlik Sense - Changing a proxy certificate&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/ERR-CERT-COMMON-NAME-INVALID-when-using-3rd-party-certificate/ta-p/1715606" target="_blank" rel="noopener"&gt;ERR_CERT_COMMON_NAME_INVALID when using 3rd party certificate&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Qlik-Sense-Compatibility-information-for-third-party-SSL/ta-p/1715975" target="_blank" rel="noopener"&gt;Qlik Sense: Compatibility information for third-party SSL certificates to use with HUB/QMC&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://community.qlik.com/t5/Support-Knowledge-Base/Requirements-for-configuring-Qlik-Sense-with-SSL/ta-p/1715916?_ga=2.9826422.2114727983.1602514418-577020889.1572878749" target="_blank" rel="noopener"&gt;Requirements for configuring Qlik Sense with SSL&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/Couldn-t-find-a-valid-ssl-certificate-with-thumbprint-and-the/ta-p/1715455" target="_blank" rel="noopener"&gt;Couldn't find a valid ssl certificate with thumbprint and the incorrect certificate used on hub&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A title="How to: Change the Qlik Sense Proxy certificate if the service account does not have local administrative permissions" href="https://community.qlik.com/t5/Knowledge-Base/How-to-Change-the-Qlik-Sense-Proxy-certificate-if-the-service/ta-p/1716657" target="_blank" rel="noopener"&gt;How to: Change the Qlik Sense Proxy certificate if the service account does not have local administrative&amp;nbsp;permissions&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Knowledge-Base/NET-ERR-CERT-AUTHORITY-INVALID/ta-p/1715928" target="_blank" rel="noopener"&gt;NET::ERR_CERT_AUTHORITY_INVALID&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 13 Apr 2026 11:33:49 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773</guid>
      <dc:creator>Bjorn_Wedbratt</dc:creator>
      <dc:date>2026-04-13T11:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1742869#M709</link>
      <description>&lt;P&gt;Hi, Please help. I have installed the certificates but still getting the not secure icon on the browser which is disabling the mobile app from working as well.&lt;/P&gt;&lt;P&gt;If the environment where Qliksense is installed is showing the secured icon and certificate valid, okay, but when connecting over the internet to the hub I still get the certificate invalid error.&lt;/P&gt;&lt;P&gt;Kindly assist on what steps to troubleshoot and resolve this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ayo&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 13:57:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1742869#M709</guid>
      <dc:creator>delmak2000</dc:creator>
      <dc:date>2020-09-10T13:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1744570#M750</link>
      <description>&lt;P&gt;Hello Ayo,&lt;/P&gt;
&lt;P&gt;Just closing the loop here that you've investigated this based on&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Updates-Blog/Qlik-Sense-Hub-and-QMC-with-a-custom-SSL-certificate/ba-p/1608077/page/3#comments" target="_self"&gt;Qlik Sense Hub and QMC with a custom SSL certificate&lt;/A&gt;&amp;nbsp;and are looking into ensuring the certificate you are using has a private key.&lt;/P&gt;
&lt;P&gt;/Sonja&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 07:04:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1744570#M750</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2020-09-17T07:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1745520#M767</link>
      <description>&lt;P&gt;Hi Sonja,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, I have requested the server administrator provide SSL certificates with a private key.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ayo&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 09:35:19 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1745520#M767</guid>
      <dc:creator>delmak2000</dc:creator>
      <dc:date>2020-09-21T09:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1747810#M797</link>
      <description>&lt;P&gt;To whom it may concern: you can automate this with&amp;nbsp;&lt;A href="https://github.com/ahaydon/Qlik-Cli-Windows" target="_self"&gt;ahaydon/Qlik-Cli-Windows&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;In my case I use &lt;A href="https://www.win-acme.com" target="_self"&gt;Win-Acme&lt;/A&gt; to get certs from Let's Encrypt, and as a post-renewal step I added powershell.exe as script, and as parameters: `Update-QlikProxy -id [my-proxy-id] -SslBrowserCertificateThumbprint {Cert.Thumbprint}`&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:36:05 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1747810#M797</guid>
      <dc:creator>davidgasperoni</dc:creator>
      <dc:date>2020-09-28T16:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1771978#M1399</link>
      <description>&lt;P&gt;Hi Sonja and everyone who has helped with the issues I mentioned above.&lt;/P&gt;&lt;P&gt;I have finally installed the SSL and applied the thumbprint on the Qlik sense server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now when accessing the hub or qmc from over the internet the secure icon is available but now when accessing the hub or qmc with the server environment name (i.e default localhost address when installing the Qlik sense earlier) it gives the insecure error now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can this be rectified or I am still missing something.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read and watched all videos concerning SSL and Qliksense but all to no avail.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 16:11:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1771978#M1399</guid>
      <dc:creator>delmak2000</dc:creator>
      <dc:date>2021-01-05T16:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1771985#M1400</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/32222"&gt;@delmak2000&lt;/a&gt;&amp;nbsp;, you cannot reference internal server names in certificates that are issued by publicly trusted Certificate Authorities for security reasons. If you need to not have the certificate error internally and externally, one way you may be able to accomplish this is with a reverse proxy, which offers the internet client it's own certificate, and acts as the man-in-the-middle for the encrypted communication with the QS server from a public location. The most practical way however may be for internal users to use the public name and to have the DNS server resolve that name to the internal IP address.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 16:36:34 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1771985#M1400</guid>
      <dc:creator>Andre_Sostizzo</dc:creator>
      <dc:date>2021-01-05T16:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1771994#M1401</link>
      <description>&lt;P&gt;Thanks, Andre for the prompt response. I did resolve to call the public name on the Qlik sense server environment but I noticed when I tried logging in with the domain user that serves as the root admin and was used for the installation it doesn't re-direct to the hub or the QMC either. But using the server name/localhost will successfully logon to the hub or QMC but with an invalid certificate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any pointers on if the reverse proxy is worth it?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 16:49:24 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1771994#M1401</guid>
      <dc:creator>delmak2000</dc:creator>
      <dc:date>2021-01-05T16:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1808582#M2837</link>
      <description>&lt;P&gt;Hello, I've successfully installed the SSL on my VM hosting QS. I configured the QMC. And now my connection over Intranet is secure. But I've used before Azure Reverse Proxy for one of the Virtual Proxies so users can access from eternal network.&lt;/P&gt;&lt;P&gt;It had it's own certificate which was secure already. After implementing new SSL my Azure Virtual Proxy for Qlik stopped working. I get connection timeout error straight away when I log into the hub. What can be cause of this, how to fix? It worked&amp;nbsp; before implementing custom SSL to Proxy.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/39663"&gt;@Andre_Sostizzo&lt;/a&gt;&amp;nbsp;any idea what can&amp;nbsp; I do?&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 07:42:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1808582#M2837</guid>
      <dc:creator>matKa</dc:creator>
      <dc:date>2021-05-18T07:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1808589#M2838</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/78188"&gt;@matKa&lt;/a&gt;&amp;nbsp;- Thank you for getting in touch! To get more eyes on this issue, I'd recommend posting it to our forums:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Deployment-Management/bd-p/qlik-sense-deployment" target="_blank" rel="noopener"&gt;Deployment and Management&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;When posting, please include additional details on the setup, for example, if your Reverse Proxy and the Qlik Sense Virtual Proxy have&amp;nbsp;&lt;EM&gt;different&amp;nbsp;&lt;/EM&gt;certificates and more detail on how the environment is constructed. A review of the Proxy logs (&lt;A href="https://help.qlik.com/en-US/sense-admin/May2021/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Deploy_QSEoW/Server-Logging-New-Log-File-Format-Storage.htm" target="_self"&gt;Log locations&lt;/A&gt;) will also give you an idea of what the issue may be.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 08:16:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1808589#M2838</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2021-05-18T08:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1902766#M5770</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/39663"&gt;@Andre_Sostizzo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I'm in this process and went to buy a custom SSL certificate, unfortunately I have been asked to *validate* CSR data and it looks the only way is a "file" authentication, hence they asked me to upload a specific file that should be reachable at "45.XX.YYY.Z/.well-known/pki-&lt;WBR /&gt;validation/fileauth.txt" and despite a lot of googling, I really don't know which #Qlik Sense Web Server folder to place it, to make it available.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Could you help me sorting this out? Thanks a lot, Brunello&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 07:17:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1902766#M5770</guid>
      <dc:creator>bmenicucci</dc:creator>
      <dc:date>2022-03-09T07:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1902772#M5771</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/18020"&gt;@bmenicucci&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Qlik Sense does not come with a web server that allows you to host a file in a custom folder structure like this. If you require a web server to host a file, we would need to recommend a third party web server, such as IIS.&lt;/P&gt;
&lt;P&gt;I would suggest connecting with the customer support of the org where you are attempting to purchase the certificate from, as they should be able to provide you with information on this.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 07:31:26 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1902772#M5771</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2022-03-09T07:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1902792#M5773</link>
      <description>Hi Sonja,&lt;BR /&gt;thank you for the quick answer.&lt;BR /&gt;May I ask you if it's possible to have an IIS web server and Qlik Sense one&lt;BR /&gt;together?&lt;BR /&gt;Any possibility to disrupt activities?&lt;BR /&gt;Thanks,&lt;BR /&gt;Brunello&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Mar 2022 07:54:10 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1902792#M5773</guid>
      <dc:creator>bmenicucci</dc:creator>
      <dc:date>2022-03-09T07:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1902809#M5774</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/18020"&gt;@bmenicucci&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We cannot recommend having it installed on the same server (while in production). You are likely to run into port conflicts. But if this validation is only required once, you can shut down the Qlik Sense services during a maintenance window, set up IIS, do your validation, and then uninstall/disable IIS to return to the normal Qlik Sense operation.&lt;/P&gt;
&lt;P&gt;But as I mentioned: This is something you'd want to check with the vendor you are trying to purchase the certificate from.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 08:11:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1902809#M5774</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2022-03-09T08:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1917562#M6098</link>
      <description>&lt;P&gt;Does anything have to be done to VIRTUAL PROXIES, after a new certificate is set up?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 16:08:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1917562#M6098</guid>
      <dc:creator>Ken_T</dc:creator>
      <dc:date>2022-04-12T16:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1917829#M6103</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/92536"&gt;@Ken_T&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only changes necessary when swapping to a 3rd party certificate are outlined in this guide. No modifications need to be done to the Virtual Proxy. All Virtual Proxies using the Proxy the cert is configured for will use this cert.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 06:53:12 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1917829#M6103</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2022-04-13T06:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1918038#M6108</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;we had to generate SP Metadata for all of our virtual proxies which had been individually configured with SAML authentication, after we updated our certificate. Had to send these new files to our team that handles SAML, and they had to do some updates with those files before our virtual proxies that had specific/different SAML set up started working again. This was on our QAP system where several virtual proxies are set up to have different SAML authentication.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 13:06:02 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1918038#M6108</guid>
      <dc:creator>Ken_T</dc:creator>
      <dc:date>2022-04-13T13:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1918041#M6109</link>
      <description>&lt;P&gt;ps, this article helped us get it all working !&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 13:07:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1918041#M6109</guid>
      <dc:creator>Ken_T</dc:creator>
      <dc:date>2022-04-13T13:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1918043#M6111</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/92536"&gt;@Ken_T&lt;/a&gt;&amp;nbsp;!&lt;BR /&gt;&lt;BR /&gt;I am glad the article helped!&amp;nbsp; And based on what you explained here: Yeah, alright, I only considered out of the box (going directly to the hub) in my reply and did not take into consideration possible customizations that rely on certificates. That's a very good point! Thank you for bringing it up and leaving the note here.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 13:09:33 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1918043#M6111</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2022-04-13T13:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to change the certificate used by the Qlik Sense Proxy to a custom third party certificate</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1921107#M6283</link>
      <description>&lt;P&gt;&lt;A href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597" target="_blank"&gt;@Sonja_Bauernfeind&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/39663"&gt;@Andre_Sostizzo&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp; -&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Our vulnerability Scanning Team scanning our servers with -&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Vulnerabilities - "Untrusted TLS/SSL server X.509 certificate". &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Vulnerability Proof - TLS/SSL certificate signed by unknown, untrusted CA: CN=&amp;lt;hostname&amp;gt;-CA -- [Path does not chain with any of the trust anchors]. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Port &amp;amp; Process Details as below -&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;TABLE class="wrapped confluenceTable" width="692px"&gt;&lt;COLGROUP&gt;&lt;COL /&gt;&lt;COL /&gt;&lt;COL /&gt;&lt;COL /&gt;&lt;COL /&gt;&lt;COL /&gt;&lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="126.094px" class="confluenceTd"&gt;Server Name&lt;/TD&gt;
&lt;TD width="42.7812px" class="confluenceTd"&gt;Port&lt;/TD&gt;
&lt;TD width="93px" class="confluenceTd"&gt;Process&lt;/TD&gt;
&lt;TD width="113.5px" class="confluenceTd"&gt;Process Description Name&lt;/TD&gt;
&lt;TD width="315.625px" class="confluenceTd"&gt;Location&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="126.094px" class="confluenceTd"&gt;
&lt;P&gt;&lt;BR /&gt;Scheduler Node&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="42.7812px" class="confluenceTd"&gt;443&lt;/TD&gt;
&lt;TD width="93px" class="confluenceTd"&gt;proxy.exe&lt;/TD&gt;
&lt;TD width="113.5px" class="confluenceTd"&gt;Qlik Sense Proxy Service&lt;/TD&gt;
&lt;TD width="315.625px" class="confluenceTd"&gt;C:\Program Files\Qlik\Sense\Proxy&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD rowspan="3" width="126.094px" class="confluenceTd"&gt;Proxy Node &lt;BR /&gt;Scheduler Node&amp;nbsp;&lt;BR /&gt;Engine Node 1&lt;BR /&gt;Engine Node 2&lt;/TD&gt;
&lt;TD width="42.7812px" class="confluenceTd"&gt;4242&lt;/TD&gt;
&lt;TD width="93px" class="confluenceTd"&gt;ntoskrnl.exe&lt;/TD&gt;
&lt;TD width="113.5px" class="confluenceTd"&gt;NT Kernel &amp;amp; System&lt;/TD&gt;
&lt;TD width="315.625px" class="confluenceTd"&gt;C:\Windows\System32&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="42.7812px" class="confluenceTd"&gt;5926&lt;/TD&gt;
&lt;TD width="93px" class="confluenceTd"&gt;dotnet.exe&lt;/TD&gt;
&lt;TD width="113.5px" class="confluenceTd"&gt;.NET Core Host&lt;/TD&gt;
&lt;TD width="315.625px" class="confluenceTd"&gt;C:\Program Files\Qlik\Sense\ServiceDispatcher\dotnet&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="42.7812px" class="confluenceTd"&gt;5927&lt;/TD&gt;
&lt;TD width="93px" class="confluenceTd"&gt;dotnet.exe&lt;/TD&gt;
&lt;TD width="113.5px" class="confluenceTd"&gt;.NET Core Host&lt;/TD&gt;
&lt;TD width="315.625px" class="confluenceTd"&gt;
&lt;P&gt;C:\Program&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Files\Qlik\Sense\ServiceDispatcher\dotnet&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;U&gt;&lt;STRONG&gt;Root Cause known&lt;/STRONG&gt;&lt;/U&gt; - Issue occurring due to self signed certificate installed on all nodes.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;U&gt;&lt;STRONG&gt;Background:&lt;/STRONG&gt; &lt;/U&gt;&amp;nbsp;&lt;/SPAN&gt;We recently got signed&lt;SPAN&gt;&amp;nbsp;Custom third party certificate (contains&amp;nbsp;&lt;SPAN&gt;all nodes SANs)&amp;nbsp; imported in Proxy Node. Architecture as below -&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;U style="font-family: inherit;"&gt;&lt;STRONG&gt;Question #1 - &lt;/STRONG&gt;&lt;/U&gt;Which Proxy choose Central or Proxy for updating Thumbprint?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;U style="font-family: inherit;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="QMC_Proxy.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/77608i11AA15C89E1E2D21/image-size/large?v=v2&amp;amp;px=999" role="button" title="QMC_Proxy.png" alt="QMC_Proxy.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;U style="font-family: inherit;"&gt;&lt;STRONG&gt;Question # 2&lt;/STRONG&gt;&lt;/U&gt;&lt;SPAN&gt;&amp;nbsp;- Once we complete the Step 4 in this article, will post&amp;nbsp;&lt;STRONG&gt;Sense Proxy restart&lt;/STRONG&gt;&amp;nbsp;distribute the &lt;STRONG&gt;new certificate to Central/Scheduler Node, other Engine nodes&lt;/STRONG&gt; and&amp;nbsp;Windows API calls will correctly bind the new certificate to its SSL ports on same ?.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;U style="font-family: inherit;"&gt;&lt;STRONG&gt;Question # 3&amp;nbsp;-&lt;/STRONG&gt;&lt;/U&gt;if this document doesn't applies to this problem, &lt;STRONG&gt;can you please provide details Steps of replacing Self Signed Certificate with Custom 3rd party certificate - goal here is to replace existing self signed cert with 3rd party cert on all required nodes?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;U style="font-family: inherit;"&gt;&lt;STRONG&gt;Architecture&lt;/STRONG&gt;&lt;STRONG style="font-family: inherit;"&gt;&amp;nbsp;Here -&lt;/STRONG&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Architecture_Diagram.png" style="width: 682px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/77607i8199448F023C4600/image-dimensions/682x426?v=v2" width="682" height="426" role="button" title="Architecture_Diagram.png" alt="Architecture_Diagram.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 22:03:37 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/How-to-change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/tac-p/1921107#M6283</guid>
      <dc:creator>gdrabla</dc:creator>
      <dc:date>2022-04-21T22:03:37Z</dc:date>
    </item>
  </channel>
</rss>

