Replace the Default Server Certificate

To be able to start the Transfer Client and Gateway Administrator without seeing certificate warning messages, you can replace each of these self-signed certificates with a certificate from a well-known Certificate Authority (CA).

To replace self-signed certificates create a PKCS#12, or JKS keystore and migrate the file (.p12, .pfx, or .jks) to BCKFS. Server certificates must be stored in a FIPS compliant BCFKS keystore. Refer to the following procedures for details.

Install a Server Certificate in a PKCS#12 File

Install a Server Certificate in a Java Keystore