The Nginx web server is used on all supported operating systems other than Astra Linux Special Edition.
To replace the SSL certificate of a cluster node with the Nginx web server:
/root
directory.cd /var/opt/kaspersky/ksmg/certs
cp -p webapi.crt webapi.crt.backup
cp -p webapi.key webapi.key.backup
cp -p dhparam.pem dhparam.pem.backup
cat /root/cert.pem > webapi.crt
cat /root/key.pem > webapi.key
openssl dhparam -out dhparam.pem 4096
Generating DH parameters may take 10 to 20 minutes. Wait for the operation to finish.
chown root:root webapi.crt
chmod 644 webapi.crt
chown kluser:root webapi.key
chmod 600 webapi.key
chown root:root dhparam.pem
chmod 644 dhparam.pem
systemctl restart nginx
systemctl status nginx
The service must have the running status.
/root
directory:rm -f /root/cert.pem /root/key.pem
The SSL certificate of the cluster node is replaced. If you want to replace certificates on multiple cluster nodes, you must follow the step-by-step instruction on each node.
Page top