6.5.24 Oracle WebLogic
Use the same keystore path, password, and alias WebLogic already uses
The Oracle WebLogic Server template replaces the identity keystore and restarts SSL to load the new certificate. It does not restart the WebLogic server process.
It needs WebLogic 12c or later and a CertKit agent on Windows.
Match your WebLogic settings
CertKit replaces the JKS identity keystore. Configure it with the path, password, and private key alias that WebLogic uses.
In the WebLogic console, open Environment > Servers > (your server) > Configuration and copy these values:
| CertKit field | WebLogic setting |
|---|---|
| JKS Destination | Custom Identity Keystore (Keystores tab) |
| Keystore Password | Custom Identity Keystore Passphrase (Keystores tab) |
| Entry Alias | Private Key Alias (SSL tab) |
CertKit uses one password for the keystore and the key inside it. WebLogic’s Private Key Passphrase must equal Keystore Password. If they differ today, change Private Key Passphrase in WebLogic before the first deployment.
The Keystores setting must be Custom Identity and Java Standard Trust or Custom Identity and Custom Trust. Trust keystores are not changed.
Admin server connection
CertKit uses the WebLogic Scripting Tool (WLST) to connect to the admin server and restart SSL.
- Oracle home: the Oracle Middleware home, the folder that contains
oracle_common. Not the domain folder. - Admin server URL: use the plain
t3://address if you have one, nott3s://. The reload restarts WebLogic’s secure connections, which can cut off at3ssession. - WebLogic admin username and WebLogic admin password: an account that can sign in to the admin server and restart SSL.
- Server names (comma separated): every server that uses this keystore, spelled exactly as in Environment > Servers.
Servers on more than one machine
Each managed server reads its local keystore. Install an agent on each host and deploy to the path configured in WebLogic. Multiple agents can list the same servers.
Node Manager’s own keystore settings (nodemanager.properties) are not changed.
Common problems
- “WLST was not found”: fix Oracle home. It’s the folder that contains
oracle_common. - “WLST exited with code …”: find the failing step in the deployment output. A connection error usually means a wrong URL, username, or password. An error mentioning
/ServerRuntimes/means a server name is misspelled or that server isn’t running. - The SSL restart fails with a keystore or key error: the password or alias doesn’t match WebLogic. Check that Private Key Passphrase equals Keystore Password.
- One server still shows the old certificate: that server’s machine has no agent, or its deployment writes to a different path.