Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Replacing the Default Certificate in JSA Generates Invalid PEM Errors

Replacing the default certificate in JSA causes the ConfigurationServer.PEM file to change, affecting all WinCollect agents in the deployment. To fix this issue, you must replace the ConfigurationServer.PEM file on the Windows host.

WinCollect agents receive rejection messages because the incorrect certificate is passed when the agents attempt to communicate with the updated JSA appliance. The following error message appears in the logs:

The IP address of the agent that is attempting to communicate is displayed. The WinCollect agent also sends LEEF Syslog messages to inform the administrator of the communication issue due to the invalid certificate. To fix this issue, you must replace the ConfigurationServer.PEM file on the Windows host.

Note:

This action must be completed by a Windows administrator or a user that has privileges to delete files from the remote Windows host.

  1. Open a remote desktop connection to the WinCollect Agent that is unable to communicate.

  2. Click Start > Run.

  3. Type services.msc, then click OK.

  4. Stop the WinCollect service.

  5. On the Windows host, navigate to the WinCollect configuration folder.

    By default, the folder path is: C:\ProgramFiles\IBM\WinCollect\config

  6. Delete ConfigurationServer.PEM.

  7. From the Services window, start the WinCollect service.