6.5.22 Absolute Secure Access
Install the agent on the Secure Access server itself
The Absolute Secure Access (NetMotion Mobility) Server template updates the certificate used by the Secure Access console and web services API. This is the certificate under Secure Access Management Tool > Web Server > Server Certificate. CertKit then restarts the Secure Access Web Server service (NmWebServer).
Console users are disconnected briefly during the restart. VPN connections are not affected. If the certificate is already installed, nothing is changed or restarted.
Requirements
- Install the CertKit agent on the Secure Access server itself.
- Run the agent as Local System or a local administrator, so it can change the web server’s files and restart the service.
- The Secure Access Web Server service must be running when the deployment starts.
- Java’s
keytool.exemust be available. The Java that comes with Secure Access is normally found automatically. - On a new server, create or import a server certificate once in the Management Tool before the first deployment.
Settings
CertKit detects the web server’s keystore and reads its password from the configuration. Leave the install directory and alias on auto unless detection fails.
- Secure Access server install directory: the folder that contains
webserver\conf\keystore, for exampleC:\Program Files\Secure Access Server. - Keystore alias: the name of the certificate entry the web server uses inside the keystore.
If you set the install directory yourself and the NmWebServer service doesn’t exist, CertKit updates the certificate but doesn’t restart anything. Restart the web server yourself.
Backups and rollback
Before each change, CertKit copies the keystore to keystore.certkit-backup-<timestamp> in the same folder. After the restart, it checks that the console serves the new certificate. If the update, restart, or check fails, it puts the old keystore back and restarts the service.
CertKit does not delete these backups. They contain private keys; restrict access and remove them according to your backup retention policy.
Common problems
- “Could not find the Secure Access server installation” or “does not contain webserver\conf\keystore”: set Secure Access server install directory to the folder that contains
webserver\conf\keystore. - “keytool.exe was not found”: install a Java runtime, or set a system-wide
JAVA_HOMEthe agent’s account can see. - “Service ‘NmWebServer’ is Stopped”: start the Secure Access Web Server service, check that the console loads, then deploy again.
- “Listing keystore … failed”: usually the keystore password is wrong. CertKit reads it from the web server’s XML settings files, or uses the old default
nmswebuiif none is set there. - “The keystore has several private key entries”: set Keystore alias to the one the web server uses. The error lists the aliases it found.
- “The keystore has no private key entry”: create the first server certificate in the Management Tool (Web Server tab > Server Certificate), or set Keystore alias.
- “The web server serves certificate …, not …”: the web server uses a different alias or keystore. The old keystore was put back. Set Keystore alias to the alias the web server uses.
- “could not complete a TLS handshake with localhost”: the certificate was updated but not checked. Open the console in a browser to confirm it.
- “Restart failed”: the old keystore was put back and the service restarted. Check the Windows event log for the Secure Access Web Server error.