35.3. Configuring the Certificate Server Component
- To configure Certificate Server (CS) manually, open the
/etc/pki/pki-tomcat/server.xmlfile. Set all occurrences of thesslVersionRangeStreamandsslVersionRangeDatagramparameters to the following values:sslVersionRangeStream="tls1_2:tls1_2" sslVersionRangeDatagram="tls1_2:tls1_2"
sslVersionRangeStream="tls1_2:tls1_2" sslVersionRangeDatagram="tls1_2:tls1_2"Copy to Clipboard Copied! Toggle word wrap Toggle overflow Alternatively, use the following command to replace the values for you:sed -i 's/tls1_[01]:tls1_2/tls1_2:tls1_2/g' /etc/pki/pki-tomcat/server.xml
# sed -i 's/tls1_[01]:tls1_2/tls1_2:tls1_2/g' /etc/pki/pki-tomcat/server.xmlCopy to Clipboard Copied! Toggle word wrap Toggle overflow - Restart CS:
systemctl restart pki-tomcatd@pki-tomcat.service
# systemctl restart pki-tomcatd@pki-tomcat.serviceCopy to Clipboard Copied! Toggle word wrap Toggle overflow