6.5.25 Boomi

Configure API access, runtime restarts, and manual gateway or portal updates

Choose the template for the Boomi service that uses the certificate.

Template Use it for Manual steps
Boomi Runtime: Shared Web Server Certificate Self-hosted Atoms and Molecules Restart the runtimes if automatic restarts are disabled.
Boomi API Gateway Certificate An API Gateway Click Upgrade to Latest after each renewal.
Boomi Developer Portal Certificate A Developer Portal Click Upgrade to Latest after each renewal.

Each template creates or updates a Boomi certificate component through the Platform API over HTTPS. The agent needs access to Boomi’s API, not a direct connection to the runtimes or gateway.

Create the API token

Create a token under Settings > My User Settings > Platform API Tokens. If you haven’t used API tokens before, turn on the API Token feature there first. Enter the token’s owner in Boomi username (API token owner) and the token in Boomi Platform API token. Copy Boomi account ID from Settings > Account Information. If your account is on Boomi’s GB platform, set Platform API base URL to https://api.platform.gb.boomi.com.

The token’s user needs:

  • API Access and Build read/write, for every template
  • Runtime Management, for the Shared Web Server template
  • Environment Management, if the Shared Web Server template restarts runtimes

Certificate component

Set Certificate component name to the component CertKit should update. If it doesn’t exist, the first deployment creates it in Component folder ID (root by default). Renewals update the same component. Use a unique name for each certificate in the account.

Shared Web Server runtimes

List every runtime that serves the certificate in Runtime names (comma-separated), spelled as shown in Manage > Runtime Management. Runtimes you leave out keep the old certificate. Enter none to update only the component.

A runtime only serves the new certificate after it restarts. With Restart runtimes after the push set to true, CertKit restarts each one. A restart stops any work running on that runtime, so schedule the deployment for a quiet time. Set it to false to restart them yourself. The log lists which ones need it.

Only Atoms and Molecules you host yourself can use your own certificate. Boomi-hosted Clouds always use Boomi’s certificate.

API Gateway and Developer Portal

Boomi’s API does not expose the gateway or portal certificate binding, so you must update it in the console. Open API Management > Gateways, select the gateway, and open Location Settings. For the portal, use the Certificate field under Developer Portal Settings.

  • First run: select the new component in the Certificate field.
  • Every renewal after that: click Upgrade to Latest on the Certificate field. The old certificate stays in use until you do.

Enter the site’s name in Gateway public hostname or Developer Portal public hostname, for example api.example.com, without https:// or a port. CertKit stops before uploading if the certificate doesn’t cover that name. A wildcard like *.example.com covers api.example.com but not a.b.example.com. Enter none to skip this check.

Common problems

  • Boomi API ... failed (HTTP 401) or (HTTP 403): check the account ID, username, token, and the user’s privileges.
  • Found N certificate components named ...: rename or delete the extras so only one component has that name.
  • No runtime named '...' found in account: copy the name exactly from Runtime Management and check the account ID.
  • Found N runtimes named ...: give each runtime a unique name.
  • Cannot bind a certificate to '...': that runtime is a Boomi-hosted Cloud. Only self-hosted Atoms and Molecules can use your certificate.
  • No SSL listener port is enabled: turn on an SSL port under Listening Port Configuration in the runtime’s Shared Web Server settings.
  • Runtime still shows the old certificate: look for restart request FAILED in the log, which usually means the user lacks Environment Management. Otherwise, give the restart a minute to finish.
  • Certificate does not cover the gateway hostname or portal hostname: remove https:// and any port from the name, or use a certificate that covers it. Nothing was uploaded.
  • Gateway or portal still shows the old certificate: click Upgrade to Latest in Location Settings.
  • NO NEW COMPONENT VERSION WAS CREATED: the component already had this certificate. Nothing to do unless the gateway or portal isn’t using it yet.