Replacing Expired Dashboard TLS Certificate


Product Name

CIS-CAT Pro Dashboard

Product Version

v3.0+

Date

Jan 10, 2024



Problem

The HTTPS certificate configured during the CIS-CAT Pro Dashboard installation has expired and needs to be renewed. This may present itself with a browser warning page when visiting the Dashboard web interface, along with error codes such as NET::ERR_CERT_DATE_INVALID:

Solution

A new certificate can either be generated (for the self-signed TLS option) or supplied to Dashboard (for an existing organizational certificate) by re-running the latest installer.

For Linux users: The general process outlined below using the Dashboard Installer GUI on Windows can be carried out on Linux installations via the CCPD_unix_Installer.sh setup script as well.

1

Launch the latest available Dashboard installer (CCPD_windows-x64_Installer.exe) on the server hosting the current deployment. A new copy of the installer can be obtained from CIS WorkBench if needed.

2

Select “Update application and/or configuration settings” (second option)

3

On the “HTTP/HTTPS Configuration” screen, choose either the first option (“Set up with HTTPS with a new self-signed certificate”) to create an updated self-signed cert valid for 90 days, or the second option to provide an existing organizational certificate in .pfx/.p12 or .jks format.

For more information on valid organizational certificate formats for use with CIS-CAT Pro Dashboard, please see the following KB article:
Dashboard v3 Certificate FAQs

4

Proceed through the remaining installation steps. The required services will be automatically restarted and the new certificate applied to the Dashboard application.

Verify the new configuration is in place by visiting the Dashboard web interface; you may have to clear your existing cookies / session tokens (or use Incognito / Private Browsing mode) to ensure the newest page content is properly retrieved.

Keywords; Dashboard v3 HTTPS TLS certificate expired

Content by Label


Copyright © 2023

Center for Internet Security®