Regenerating the server SSL certificates
========================================

If the PEM backend database server certificates are near expiring, plan
to regenerate the certificates and key files.

..  Important::
   PEM performs these steps by default when the certificates are nearing expiry. These instructions are provided for completeness in case you need to manually regenerate the PEM certificates and keys.

To replace the SSL certificates:

1. Stop all running PEM agents, first on the server host and then on any
   monitored host. - On Linux:

.. code:: shell

        # Running as root
        systemctl stop pemagent

- On Windows: Use the Services applet to stop the PEM agent. The PEM
  agent service is named Postgres Enterprise Manager Agent. In the
  Services dialog box, select the service name, and select **Stop the
  service**.

1. Back up the existing SSL certificates and keys:

.. code:: shell

      cd /var/lib/edb/as<x>/data
      mkdir certs
      mv server.* root.* ca_* certs/

1. Use the ``openssl`` command to generate the ``ca_key.key`` file:

.. code:: shell

      openssl genrsa -out ca_key.key 4096 

1. Move the ``ca_key.key`` file to the data directory of the backend
   server, and change the permissions:

.. code:: shell

      mv ca_key.key /var/lib/edb/as<x>/data
      chmod 600 /var/lib/edb/as<x>/data/ca_key.key

1. Use ``ca_key.key`` to generate the ``ca_certificate.crt`` file:

.. code:: shell

      openssl req -x509 -nodes -days 3650 -newkey rsa:4096 -keyout ca_key.key -out ca_certificate.crt

1. Change the permissions of the ``ca_certificate.crt`` file:

.. code:: shell

      chmod 600 /var/lib/edb/as<x>/data/ca_certificate.crt

1. Reuse the ``ca_certificate.crt`` file as the ``root.crt`` file:

.. code:: shell

      cp /var/lib/edb/as<x>/data/ca_certificate.crt /var/lib/edb/as<x>/data/root.crt

1. Change the owner and permissions on the ``root.crt`` file:

.. code:: shell

      chown enterprisedb /var/lib/edb/as<x>/data/root.crt
      chmod 600 /var/lib/edb/as<x>/data/root.crt

1. Use the ``openssl_rsa_generate_crl()`` function to create the
   certificate revocation list ``root.crl`` :

.. code:: shell

      psql -U enterprisedb -d pem --no-psqlrc -t -A -c
      "SELECT openssl_rsa_generate_crl(/var/lib/edb/as<x>/data/ca_certificate.crt, /var/lib/edb/as<x>/data/ca_key.key)" > /var/lib/edb/as<x>/data/root.crl

1. Change the ownership and permissions of the ``root.crl`` file:

.. code:: shell

      chown enterprisedb /var/lib/edb/as<x>/data/root.crl
      chmod 600 /var/lib/edb/as<x>/data/root.crl

1. Use the ``openssl`` command to generate the ``server.key`` file:

.. code:: shell

      openssl genrsa -out server.key 4096 

1. Move ``server.key`` to the data directory of the backend server, and
   change the ownership and permissions:

.. code:: shell

      mv server.key /var/lib/edb/as<x>/data
      chown enterprisedb /var/lib/edb/as<x>/data/server.key
      chmod 600 /var/lib/edb/as<x>/data/server.key

1. Use the ``openssl req`` command to create the CSR:

.. code:: shell

      openssl req -new -key server.key -out server.csr -subj /C=IN/ST=MH/L=Pune/O=EDB/CN=PEM

Where ``-subj`` is provided as per your requirements. You define ``CN``
as the hostname/domain name of the PEM server host.

1. Use the ``openssl x509`` command to sign the CSR and generate a
   server certificate. Move ``server.crt`` to the data directory of the
   backend database server:

.. code:: shell

      openssl x509 -req -days 365 -in server.csr -CA ca_certificate.crt -CAkey ca_key.key -CAcreateserial -out server.crt
      mv server.crt /var/lib/edb/as<x>/data

Where ``-req`` indicates the input is a CSR. The ``-CA`` and ``-CAkey``
options specify the root certificate and private key to use for signing
the CSR.

1. Change the owner and the permissions on the ``server.crt`` file:

.. code:: shell

      chown enterprisedb /var/lib/edb/as<x>/data/server.crt
      chmod 600 /var/lib/edb/as<x>/data/server.crt

1. Restart the PEM server:

.. code:: shell

      systemctl restart edb-as-<x>

Restarting the backend database server restarts the PEM server.

1. Regenerate each PEM agent’s SSL certificates. For more information,
   see :ref:`Regenerating the agent SSL certificates <Regenerating the agent SSL certificates>`  .
