Required Certificates and Their Location

Oracle recommends the use of certificates from well-known third-party CAs to SSL-enable Essbase in a production environment. You may use the default self-signed certificates for test purposes.

Note:

Essbase supports the use of wildcard certificates, which can secure multiple subdomains with one SSL certificate. Use of a wildcard certificate can reduce management time and cost.

Wildcard certificates cannot be used if host name check is enabled.

You require the following certificates:

Table 13. Required Certificates and Their Location

Component[1]KeystoreCertificate[2]
MaxLOracle Walletroot CA certificate
Administration Services ServerOracle Walletroot CA certificate
Provider ServicesOracle Walletroot CA certificate
EPM System DatabaseOracle Walletroot CA certificate
Essbase Studio ServerJava Keystoreroot CA certificate
Planning
  • Oracle Wallet

  • Java Keystore

root CA certificate
Financial ManagementJava Keystoreroot CA certificate
Essbase (Server and Agent)
  • Oracle Wallet

  • Java Keystore

  • root CA certificate

  • Signed certificate for Essbase Server and Agent

Shared Services Repository  

1 You require only one instance of the keystore to support multiple components that use similar keystore.

2 Multiple components can use a root certificate installed in a keystore.