Changing the UI (Console) Certificate for Audit Vault Server
Learn how to change the UI certificate for Audit Vault Server.
When you first access the Oracle Database Security Central console, you see a certificate warning or message. To avoid this type of message, you can upload a new UI certificate signed by a relevant certificate authority.
Note: If you’ve deployed DBSecCentral using RAC, these settings are inaccessible though the UI. See [Update the UI Console Certificate] (deploying-dbseccentral-high-availability-configuration-using-oracle-real-application-cluster.md#GUID-CCB74F83-6827-49AF-8284-B305B7B41175) for instructions on how to rotate certificates using AVCLI commands. {. :infoboxnote}
To change the UI certificate for the Audit Vault Server:
-
Log in to Oracle Database Security Central console as a super administrator. See Using Oracle Database Security Central Console for more information.
-
Select Settings.
-
Select Security in the left navigation menu.
-
Select Certificate on the main page.
-
Select Console Certificate.
-
Select Generate Certificate Request.
The Generate Certificate Request dialog is displayed with the Common Name for the certificate.
-
If you want to change the common name that is displayed, then select Change.
The certificate warnings are based on the common name used to identify Audit Vault Server. To suppress the warning when you access Oracle Database Security Central console using its IP address instead of the host name, also check Suppress warnings for IP based URL access.
-
Complete the form and enter content in the mandatory fields.
-
Select Submit and Download.
-
Save the
.csrfile and then submit this file to a certificate authority. Ensure that the certificate contains the following details. TheCOMMON NAMEfield is filled by default.COMMON NAMEISSUER COMMON NAME -
After the certificate authority issues a new certificate, upload it by returning to the Console Certificate sub, and then select Upload Certificate.
Note: You may need to install the public certificate of the Certificate Authority in your browser, particularly if you are using your own public key infrastructure.