Skip to main content
OutSystems

Install a trusted root CA or self-signed certificate

To connect with HTTPS to a server, that server needs to have a valid SSL certificate. For this to work the certificate, or the authority that issued the certificate needs to be trusted by the server. Usually, certificates used in production environments are issued by Root Certificate Authorities, that are trusted by all major operating systems. But to reduce costs, non-productive environments and internal servers usually use self-signed certificates, or internal Root Certificate Authorities.

To make HTTPS requests to servers that use certificates that aren't already trusted by the operating system, the certificate or Root CA certificate needs to be manually installed in the server.

Note that:

  • This procedure is not available for OutSystems PaaS.
  • It is recommended that instead this procedure is only used when it is not possible to acquire a certificate issued by a Root Authority that is automatically trusted.

Get the certificate

To get the certificate you can either:

  1.  Ask the vendor for it. You can ask for the Root CA certificate, so you can authorize all the servers you need at once;
  2.  Use a web browser to get the certificate. Access a web page on the server with HTTPS. Then use the web browser options to export the certificate to a .cet file.

Install the certificate

On Microsoft Windows

  1. Open Microsoft Management Console (Start --> Run --> mmc.exe);
  2. Choose File --> Add/Remove Snap-in;
  3. In the Standalone tab, choose Add;
  4. Choose the Certificates snap-in, and click Add;
  5. In the wizard, choose the Computer Account, and then choose Local Computer. Press Finish to end the wizard;
  6. Close the Add/Remove Snap-in dialog;
  7. Navigate to Certificates (Local Computer)
  8. Choose a store to import:
    1. If you have the Root CA certificate for the company that issued the certificate, choose Trusted Root Certification Authorities;
    2. If you have the certificate for the server itself, choose Other People
  9. Right-click the store and choose All Tasks --> Import
  10. Follow the wizard and provide the certificate file you have;

On a Linux distribution

  1. Place the certificate in the machine.  The following commands will assume that it is located in /root/certificate.cer
  2. As root run:
    • source /etc/sysconfig/outsystems
    • $JAVA_HOME/bin/keytool -import -alias <give_it_a_name_here> -keystore $JAVA_HOME/jre/lib/security/cacerts -file /root/certificate.cer
  3. You will probably be asked for a password. If you haven't changed it, the password is "changeit".
  4. When the tool asks you if you want to trust this certificate, answer "yes".
  5. restart jboss using the command:
    • service jboss-outsystems restart