Enabling SSL connection between Experience Portal Postgres database and Usage Metering

Last Updated : Dec 08, 2020 |
Prolog information
Perform this procedure if you want to enable SSL connection between any of the following:
  • An Experience Portal local Postgres database and Usage Metering.
  • An Experience Portal external Postgres database and Usage Metering.
  1. Connect to the Postgres server by using PuTTY.
  2. Run the following command and note down the output of the command:
    ADDITIONAL INFORMATION:
    hostname
  3. Do the following to make the Postgres server a root certificate authority:
    1. Replace <root.yourdomain.com> in the following command with the output of the hostname command and run the following command to generate a root certificate signing request (CSR) and a public/private key file (root.key):
      ADDITIONAL INFORMATION: openssl req -new -nodes -text -out root.csr \
        -keyout root.key -subj "/CN=<root.yourdomain.com>"
    2. Run the following command to remove read, write, and execute permissions from the root.key file for all users except the file owner:
      ADDITIONAL INFORMATION:
      chmod og-rwx root.key
    3. Run the following command to generate a CA-signed root certificate by using the root.key and openssl.cnf files:
      ADDITIONAL INFORMATION: openssl x509 -req -in root.csr -text -days 3650 \
        -extfile /etc/ssl/openssl.cnf -extensions v3_ca \
        -signkey root.key -out root.crt
      The preceding command generates the root.crt file, which is a CA-signed root certificate file.
    4. If the command in the preceding step displays an error mentioning that the openssl.cnf file is not found, run the following command to find the file on the server:
      ADDITIONAL INFORMATION:
      find / -name "<filename>"
      Replace the file location in the command in the preceding step with the correct file location and run the command.
  4. Do the following to generate a server certificate that is signed by this root CA:
    1. Replace <dbhost.yourdomain.com> in the following command with the output of the hostname command and run the following command to generate a server certificate CSR and a public/private key file (server.key) for this CSR:
      ADDITIONAL INFORMATION: openssl req -new -nodes -text -out server.csr \
        -keyout server.key -subj "/CN=<dbhost.yourdomain.com>"
    2. Run the following command to remove read, write, and execute permissions from the server.key file for all users except the file owner:
      ADDITIONAL INFORMATION:
      chmod og-rwx server.key
    3. Run the following command to generate a server certificate that is signed by this root CA:
      ADDITIONAL INFORMATION: openssl x509 -req -in server.csr -text -days 365 \
        -CA root.crt -CAkey root.key -CAcreateserial \
        -out server.crt
      You can specify the number of days for certificate validity in the preceding command based on your corporate policy.
      The preceding command generates the server.crt file that is signed by this root CA.
  5. Copy the server.crt and server.key files to the var/lib/pgsql/data/ folder on the Postgres server.
  6. Run the following commands to allow the Postgres server access to the server.crt and server.key files:
    ADDITIONAL INFORMATION:
    chown postgres:postgres server.crt
    chown postgres:postgres server.key
  7. Do the following to enable SSL connection:
    1. Run the following command to edit the postgresql.conf file:
      ADDITIONAL INFORMATION:
      vi postgresql.conf
    2. Set the following parameters in the postgresql.conf file:
      ADDITIONAL INFORMATION:
      • ssl = on
      • ssl_crt_file = 'server.crt'
      • ssl_key_file = 'server.key'
    3. Save the postgresql.conf file.
    4. To apply the changes, restart the Postgres service by running the following command:
      ADDITIONAL INFORMATION:
      sudo service postgresql restart
  8. Copy the server.crt file to the Usage Metering Collector server.
  9. Install the server.crt file in the Usage Metering Collector.
    ADDITIONAL INFORMATION:
    For more information, see Installing an outbound certificate.
Next steps
After you perform this procedure, you must select the SSL check box when adding Experience Portal Manager to your Avaya OneCloud™ Subscription system to enable the SSL connection.