12.1 Configuring SHA-2 Certificate

12.1.1 CA Server

  1. Apply patch on the OES server where CA is hosted in the tree.

  2. Restart the eDirectory service.

    rcndsd restart

  3. Delete the existing CA in tree and create a new CA with SHA-2 signing algorithm. For more information, see the TID on Configuring eDirectory to mint certificates with a SHA-2 signature (7016877).

  4. Restart the eDirectory service.

    Run the following command to recreate the eDirectory server certificates with SHA-2 algorithm.

    rcndsd restart

  5. Reboot the server.

    IMPORTANT:Ensure that eDirectory service is restarted before rebooting the server.

    All the OES services will now use the new eDirectory certificates.

12.1.2 Other Servers

  1. Apply patch on the OES server.

  2. Restart the eDirectory service.

    Run the following command to recreate the eDirectory server certificates with SHA-2 algorithm.

    rcndsd restart

  3. Reboot the server.

    IMPORTANT:Ensure that eDirectory service is restarted before rebooting the server.

    All the OES services will now use the new eDirectory certificates.

12.1.3 Servers Running on eDirectory 8.8.7 or OES 11 SP1 or Earlier

If there are OES servers (OES 11 SP1 or older versions) in the tree, it is recommended to delete the server certificates of that server and create a new certificate with SHA-2 signing algorithm same as CA. The CA will be hosted on OES 11 SP3 server in the tree.