This article describes the steps required to configure SSL for IBM Cognos in a standard FlexNet Manager for Engineering Applications installation where the administration/reporting components and Cognos are hosted on separate servers. Completing these steps ensures secure communication between the Cognos server and other components.
Prepare the environment
- Ensure SSL has been configured for both the Admin and Reporting modules before starting this procedure. For reference, see Configure a CA Certificate for FlexNet Manager for Engineering Applications Admin and Reporting services
- Create a folder named:
<Cognos Install Directory>\Flexera\SSL\ - A backup of several files will be taken during the configuration steps. Follow the instructions below to identify and back them up when prompted.
Configure SSL for Cognos
- Stop the IBM Cognos service.
- Export the current Cognos configuration:
• Run<Cognos Install Directory>\Flexera\fnmea\analytics\bin64\cogstartup.batas Administrator to start the Cognos Configurator.
• In the Cognos Configurator, select File > Export As and save the file to<Cognos Install Directory>\Flexera\analytics\configuration\export.xml.
• Close the Cognos Configurator. - Back up the following folders into a zip file named
cognos_config_original_keys.zip:
•<Cognos Install Directory>\Flexera\fnmea\analytics\configuration
•<Cognos Install Directory>\Flexera\fnmea\analytics\temp - Delete these files:
•<Cognos Install Directory>\Flexera\fnmea\analytics\configuration\cogstartup.xml
•<Cognos Install Directory>\Flexera\fnmea\analytics\configuration\caSerial
•<Cognos Install Directory>\Flexera\fnmea\analytics\configuration\certs\CAMCrypto.status
•<Cognos Install Directory>\Flexera\fnmea\analytics\configuration\certs\CAMKeystore
•<Cognos Install Directory>\Flexera\fnmea\analytics\configuration\certs\CAMKeystore.lock
•<Cognos Install Directory>\Flexera\fnmea\analytics\temp\cam\freshness - Delete the folder:
•<Cognos Install Directory>\Flexera\fnmea\analytics\configuration\csk - Rename
<Cognos Install Directory>\Flexera\fnmea\analytics\configuration\export.xmltocogstartup.xml. - Open Command Prompt as Administrator and run:
cd <Cognos Install Directory>\Flexera\fnmea\analytics\binand
ThirdPartyCertificateTool.bat -c -e -p NoPassWordSet -a RSA -r "<Cognos Install Directory>\Flexera\SSL\cognos.csr" -d "CN={Cognos Server FQDN},OU=IT,O=test,L=test,ST=test,C=com" -H "{Cognos Server FQDN}"NOTE : Send
cognos.csrto your certificate management team for signing. - After receiving the signed certificates, open and save the server certificate with Base-64 encoded X.509:
• Double-click<Cognos Install Directory>\Flexera\SSL\cognos.cer.
• In the Details tab, select Copy to File and follow the Certificate Export Wizard prompts to save the root certificate as:- Base-64 encoded X.509 (.CER)
- File Path:
<Cognos Install Directory>\Flexera\SSL\cognos.cer
- Extract and import the root CA certificate:
• Double-click<Cognos Install Directory>\Flexera\SSL\cognos.cer.
• In the Certification Path tab, select the root certificate.
• Click the View Certificate button to open the root certificate.
• In the Details tab, select Copy to File and follow the Certificate Export Wizard prompts to save the root certificate as:- Base-64 encoded X.509 (.CER)
- File Path:
<Cognos Install Directory>\Flexera\SSL\cognos_root.cer
- Extract the intermediate CA certificate following the same process and save the intermediate certificate as:
• Double-click<Cognos Install Directory>\Flexera\SSL\cognos.cer.
• In the Certification Path tab, select the root certificate.
• Click the View Certificate button to open the intermediate certificate.
• In the Details tab, select Copy to File and follow the Certificate Export Wizard prompts to save the root certificate as:- Base-64 encoded X.509 (.CER)
- File Path:
<Cognos Install Directory>\Flexera\SSL\cognos_intermediate.cer
- Create the certificate chain file:
• Copy the contents of<Cognos Install Directory>\Flexera\SSL\cognos_intermediate.cerand<Cognos Install Directory>\Flexera\SSL\cognos_root.cer( in that order ) into a new Notepad file.
• Save the contents to a new file called<Cognos Install Directory>\Flexera\SSL\cognos_chain.cerwith ANSI encoding. - Open a command prompt as an Administrator and run each of the following commands in order to import the certificates into the Cognos Server keystore:
cd <Cognos Install Directory>\Flexera\fnmea\analytics\analytics\binThirdPartyCertificateTool.bat -i -T -r <Cognos Install Directory>\Flexera\SSL\cognos_root.cer -p NoPassWordSetThirdPartyCertificateTool.bat -i -T -r <Cognos Install Directory>\Flexera\SSL\cognos_intermediate.cer -p NoPassWordSetThirdPartyCertificateTool.bat -i -e -r <Cognos Install Directory>\Flexera\SSL\cognos.cer -<Cognos Install Directory>\flexera\SSL\cognos_chain.cer -p NoPassWordSet - Start the Cognos Configurator:
•<Cognos Install Directory>\Flexera\fnmea\analytics\bin64\cogstartup.bat - Modify these settings in the GUI:
Path Property Value Local Configuration > Environment Gateway URI Update URLs to https:// External dispatcher URI Internal dispatcher URI Dispatcher URI for external applications Content Manager URIs Local Configuration > Security > Cryptography Common symmetric key store password NoPassWordSet Local Configuration > Security > Cryptography > Cognos Key store password NoPassWordSet Use third party CA True Certificate Authority Password NoPassWordSet - Save the changes.
- Select Actions > Restart to restart the Cognos service.
- Close the Cognos Configurator.
- Import
cognos_root.cerinto the Admin and Reporting server truststore using:.\jvm\bin\keytool.exe -keystore ".\jvm\lib\security\cacerts" -storepass "changeit" -import -alias cognos_root -file "<Install Directory>\FLEXnet\certs\cognos_root.cer" -trustcacerts -noprompt - In the FNMEA web UI navigate to Admin > System Configuration > Reporting and update the 'Cognos server host' to include https://.
After completing these steps, the FNMEA environment communicates over SSL using a third-party CA-signed certificate.
Related Articles
Configure a CA Certificate for FlexNet Manager for Engineering Applications Admin and Reporting services 196Number of Views Configure SSL for FlexNet Manager for Engineering Applications Cognos on a single server 62Number of Views FlexNet Manager for Engineering Applications 2021 R1 Vulnerabilities, Open SSL & JavaService Libraries Statement 13Number of Views Configure the connection to a new database after installing Flexnet Manager for Engineering Applications 16Number of Views Change the RAM/heap size for FlexNet Manager for Engineering Applications 41Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago