Configuring SSL Certificate in ObserveOps
Objective
Replace the existing SSL certificate on the ObserveOps server (web UI on port 443) with a new certificate while preserving service continuity. The certificate files live at /motadata/motadata/ and must retain their exact file names: server-cert.pem, server-key.pem, and public-key.pem.
Prerequisites
- OpenSSL is installed on the machine used to prepare the files (your laptop, jump server, or any Linux machine). On Windows, use Git Bash or OpenSSL for Windows.
- You have sudo or root access on the ObserveOps server.
- A maintenance window of about 5 minutes is available for the service restart.
- Your new certificate files are ready in one of these forms:
- A certificate (
.crtor.pem) and a private key (.key). - A single
.pfxor.p12bundle. - A certificate, private key, and intermediate/chain file from your CA.
- A certificate (
- The private key is unencrypted (no passphrase).
- The certificate includes a SAN (Subject Alternative Name) for your domain.
File names must exactly match the current files on the server: server-cert.pem, server-key.pem, and public-key.pem. Do not change the names or extensions.
Procedure
The workflow has two parts. Part A prepares the certificate files on any system with OpenSSL. Part B deploys them on the ObserveOps server.
Part A: Prepare the Files
Perform Part A on any system that has OpenSSL. You do not need to run these commands on the ObserveOps server itself.
Step 1: Confirm the Files You Have
A new certificate normally arrives as two files:
| File | Example name |
|---|---|
| Certificate | example.crt |
| Private key | example.key |
If your CA also provided an intermediate or chain file, keep intermediate.crt ready.
If you received a single .pfx or .p12 bundle instead, extract the two files first:
openssl pkcs12 -in example.pfx -nokeys -out example.crt
openssl pkcs12 -in example.pfx -nocerts -nodes -out example.key
Step 2: Convert the Certificate
Check the first line of the certificate file:
head -1 example.crt
If the output shows -----BEGIN CERTIFICATE-----, the file is already in PEM format. Rename it:
mv example.crt server-cert.pem
If the output shows unreadable characters, the file is in DER format. Convert it:
openssl x509 -inform DER -in example.crt -outform PEM -out server-cert.pem
Confirm the result:
head -1 server-cert.pem
The output must show -----BEGIN CERTIFICATE-----.
Step 3: Convert the Private Key
Check the first line of the key file:
head -1 example.key
If the output shows -----BEGIN PRIVATE KEY-----, rename it:
mv example.key server-key.pem
If the output shows -----BEGIN RSA PRIVATE KEY----- or -----BEGIN ENCRYPTED PRIVATE KEY-----, convert it:
openssl pkcs8 -topk8 -nocrypt -in example.key -out server-key.pem
Confirm the result:
head -1 server-key.pem
The output must show -----BEGIN PRIVATE KEY-----.
Step 4: Create the Public Key
Generate the public key from the private key:
openssl rsa -in server-key.pem -outform PEM -pubout -out public-key.pem
If the command returns Not an RSA key (your certificate uses an ECC key), run this instead:
openssl pkey -in server-key.pem -pubout -out public-key.pem
Step 5: Add the Certificate Chain
Perform this step only if your CA provided an intermediate file:
cat server-cert.pem intermediate.crt > temp.pem
mv temp.pem server-cert.pem
Step 6: Verify the Certificate and Key Match
Run both commands:
openssl x509 -in server-cert.pem -noout -pubkey | openssl md5
openssl pkey -in server-key.pem -pubout | openssl md5
Both commands must print the same value.
If the two values differ, the certificate and key do not belong together. Stop here and check your source files before proceeding.
Step 7: Final File Check
Confirm you now have these three files:
server-cert.pem
server-key.pem
public-key.pem
Part A is complete.
Part B: Deploy on the ObserveOps Server
A maintenance window is required. The service will be down for about 5 minutes during this part.
Step 8: Log In to the Server
ssh motadata@<server-ip>
sudo su -
Step 9: Back Up the Existing Files
mkdir -p /motadata/backup
cd /motadata/motadata
cp -p server-cert.pem server-key.pem public-key.pem /motadata/backup/
Confirm the backup:
ls -la /motadata/backup/
Step 10: Replace the Files
Copy the three new files into /motadata/motadata/, replacing the existing ones:
/motadata/motadata/server-cert.pem
/motadata/motadata/server-key.pem
/motadata/motadata/public-key.pem
Transfer them using WinSCP, FileZilla, scp, or any other method you normally use.
If you use an FTP or SFTP client, set the transfer mode to Binary, not ASCII.
Set the correct owner and permissions:
cd /motadata/motadata
chown motadata:root server-cert.pem server-key.pem public-key.pem
chmod 755 server-cert.pem server-key.pem public-key.pem
Confirm the new certificate is on disk:
openssl x509 -in /motadata/motadata/server-cert.pem -noout -subject -dates
Step 11: Stop the Motadata Service
service motadata stop
Confirm the service has stopped:
service motadata status
Step 12: Start the Motadata Service
service motadata start
Wait about 1 minute for the services to come up (allow up to 5 minutes on a busy server), then check the status:
service motadata status
The status must show active (running).
Confirm port 443 is listening again:
ss -tlnp | grep ':443'
Step 13: Verify the New Certificate
Verify the certificate served on port 443:
echo | openssl s_client -connect 127.0.0.1:443 2>/dev/null | openssl x509 -noout -subject -dates
The subject and dates must show your new certificate.
Then open https://<your-domain> in a browser and confirm the padlock appears and login works.
Expected Outcomes
- The three files at
/motadata/motadata/(server-cert.pem,server-key.pem,public-key.pem) contain the new certificate data. - The Motadata service is running with the new certificate on port 443.
- Browsers show the new certificate details with a valid padlock.
Rollback
If verification fails, restore the previous certificate from the backup and restart the service:
cp -p /motadata/backup/server-cert.pem /motadata/motadata/
cp -p /motadata/backup/server-key.pem /motadata/motadata/
cp -p /motadata/backup/public-key.pem /motadata/motadata/
service motadata stop
service motadata start
Important Notes
- Do not modify any files inside
/motadata/motadata/resources/. - Do not modify
login-key.pemorlogin-pub.pem. - File names must exactly match
server-cert.pem,server-key.pem, andpublic-key.pem. - The private key must be unencrypted so the service can start without prompting for a password.
- Your certificate must include a SAN entry for your domain, otherwise browsers will reject it.