LINUXOR.SK ... open source notes ...

NetApp - API Services: Java keystore

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

NetApp Solution · Config document · referenced from Unified Manager and API Services

notePasswords and paths that were removed from the notes are placeholders. No certificate, request or key is reproduced here.

The keytool procedure that replaced the self-signed certificate of OnCommand API Services with one signed by the internal CA: new keystore, key pair, CSR, CA import, certificate import, and two corrections afterwards.

ItemValue
Runs inThe container api_container on dc1-a-vcocm002.adm.example.net, as root
Keystorekeystore.jks in <KEYSTORE_DIR>
Aliasdc1-a-vcocm002
Common namedc1-a-vcocm002.adm.example.net
KeyRSA 2048
Product versionOnCommand API Services 2.0.0, OpenJDK 1.8

The command set

bash
# --- 1. Put the delivered keystore aside ---------------------------------------
cd <KEYSTORE_DIR>
cp ./keystore.jks ./keystore.jks.old
rm ./keystore.jks

# --- 2. Tell the application the new passwords and the alias -------------------
# In keystore-config.properties:
#   apiserver.keystore.keypassword=<KEY_PASSWORD>
#   apiserver.keystore.storepassword=<KEYSTORE_PASSWORD>
#   apiserver.keystore.alias=dc1-a-vcocm002
vi /opt/netapp/api-server/api-tools/config/keystore-config.properties
# In the application server's XML configuration (a file ending in "-full.xml"),
# inside <system-properties>: the properties apiserver.keystore.keypassword
# and apiserver.keystore.storepassword with the same two values.
vi <APPLICATION_SERVER_CONFIG>-full.xml

# --- 3. New keystore and key pair ------------------------------------------------
# Interactive: keystore password, then the name fields. "First and last name"
# is the FQDN dc1-a-vcocm002.adm.example.net; organisation, locality and
# country as for the other certificates; unit and state left empty; then the
# key password.
keytool -genkey -alias dc1-a-vcocm002 -keyalg RSA -keystore keystore.jks -keysize 2048
keytool -list -v -keystore keystore.jks

# --- 4. Certificate signing request ----------------------------------------------
keytool -certreq -alias dc1-a-vcocm002 -file dc1-a-vcocm002.csr -keystore keystore.jks

# --- 5. CA certificates ------------------------------------------------------------
# Not needed for CAs that are already in the system-wide Java trust store
# ($JAVA_HOME/jre/lib/security/cacerts). Here only the second import was needed.
cd <KEYSTORE_DIR>
keytool -importcert -trustcacerts -file Internal_Root_CA.crt -alias internal-root-ca -keystore keystore.jks
keytool -importcert -trustcacerts -file Internal_CA.crt -alias internal-ca -keystore keystore.jks

# --- 6. The signed certificate, under the alias of the key ----------------------
cd <KEYSTORE_DIR>
keytool -importcert -trustcacerts -file dc1-a-vcocm002.cer -alias dc1-a-vcocm002 -keystore keystore.jks
/etc/init.d/apiserver restart

# --- 7. Correction: change the password of the private key ----------------------
# Interactive: keystore password, then the new key password twice.
cd <KEYSTORE_DIR>
keytool -keystore keystore.jks -alias dc1-a-vcocm002 -keypasswd

# --- 8. Correction: convert the keystore from JKS to PKCS12, in place -----------
cd <KEYSTORE_DIR>
cp ./keystore.jks ./keystore.jks.backup
keytool -importkeystore -srckeystore keystore.jks -destkeystore keystore.jks -deststoretype pkcs12

Section 8 follows the warning keytool printed in section 3: the JKS keystore uses a proprietary format, and migrating to PKCS12 is recommended, with exactly this command. The file keeps the name keystore.jks although it is PKCS12 afterwards. The notes do not record a restart of the API server after sections 7 and 8.

Checked against Active IQ Unified Manager 9.18

As builtToday
OnCommand API Services 2.0End of support. The last version, 2.2, reached end of availability on 2020-05-14 and end of version support on 2021-04-30
A separate REST front end for the monitoring systemThe REST APIs of Unified Manager and its API gateway, which passes ONTAP REST calls through with Unified Manager credentials

The keystore belonged to a product that no longer exists. The keytool commands themselves were not part of the research.

← solutionz