Skip to main content
Skip table of contents

How to Renew the ICG Certificate

You can renew your IGEL Cloud Gateway (ICG) certificate using the ICG Keystore Update Wizard. The ICG Keystore Update Wizard simplifies the upload of a new keystore to the ICG server.


Prerequisites

  • UMS 5.09.100 or higher

  • An ICG keystore you wish to update

  • SSH root access to the host running the ICG; as of UMS 5.09.110, it is sufficient for the SSH user to have sudo privileges

Instructions

To update a keystore, proceed as follows:

  1. Start the UMS Console.

  1. Go to UMS Administration > Global Configuration > Certificate Management > Cloud Gateway.

  1. If your signed certificate has expired, create a new signed certificate:

    1. Select the appropriate root certificate, open the context menu and select Create signed certificate.

    2. Enter the required data and click OK.

  1. Select the signed certificate that is to be used. If you omit this step, an error message will be shown in the next step.

  1. Go to UMS Administration > UMS Network > IGEL Cloud Gateway.

  1. In the toolbar in the upper right, click Update Keystore
    The Keystore Update wizard opens.

  1. Select the keystore you want transfer to the ICG server, then click Next.

  1. Enter the SSH connection parameters.

  • SSH host: The host the ICG is running on (Default: localhost)

  • SSH port: SSH port (Default: 22)

The SSH user needs to have at least sudo privileges. For more on how to grant privilege, seeGiving a User sudo Privileges .

Root access to the SSH server is a security risk!

If you permit root login for SSH, it is recommended to disable root login when the ICG installation has finished.

  • SSH user: SSH user

  • Authentication method: Password or SSH key
    If you use Password as the Authentication method, enter the SSH password of an SSH user with sudo permissions (typically the same user that installed the ICG).
    If you use SSH Key as the Authentication method, enter the SSH Keypath and the Admin Password (the sudo password).

  1. Click Next to start the update process.
    The keystore is being updated.

  1. Click Finish.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.