Skip to main content

Configuring SSL Certificate in ObserveOps

Objective​

Replace the existing SSL certificate on the ObserveOps server (web UI on port 443) with a new certificate while preserving service continuity. The certificate files live at /motadata/motadata/ and must retain their exact file names: server-cert.pem, server-key.pem, and public-key.pem.

Prerequisites​

  • OpenSSL is installed on the machine used to prepare the files (your laptop, jump server, or any Linux machine). On Windows, use Git Bash or OpenSSL for Windows.
  • You have sudo or root access on the ObserveOps server.
  • A maintenance window of about 5 minutes is available for the service restart.
  • Your new certificate files are ready in one of these forms:
    • A certificate (.crt or .pem) and a private key (.key).
    • A single .pfx or .p12 bundle.
    • A certificate, private key, and intermediate/chain file from your CA.
  • The private key is unencrypted (no passphrase).
  • The certificate includes a SAN (Subject Alternative Name) for your domain.
note

File names must exactly match the current files on the server: server-cert.pem, server-key.pem, and public-key.pem. Do not change the names or extensions.

Procedure​

The workflow has two parts. Part A prepares the certificate files on any system with OpenSSL. Part B deploys them on the ObserveOps server.

Part A: Prepare the Files​

Perform Part A on any system that has OpenSSL. You do not need to run these commands on the ObserveOps server itself.

Step 1: Confirm the Files You Have​

A new certificate normally arrives as two files:

FileExample name
Certificateexample.crt
Private keyexample.key

If your CA also provided an intermediate or chain file, keep intermediate.crt ready.

If you received a single .pfx or .p12 bundle instead, extract the two files first:

openssl pkcs12 -in example.pfx -nokeys  -out example.crt
openssl pkcs12 -in example.pfx -nocerts -nodes -out example.key

Step 2: Convert the Certificate​

Check the first line of the certificate file:

head -1 example.crt

If the output shows -----BEGIN CERTIFICATE-----, the file is already in PEM format. Rename it:

mv example.crt server-cert.pem

If the output shows unreadable characters, the file is in DER format. Convert it:

openssl x509 -inform DER -in example.crt -outform PEM -out server-cert.pem

Confirm the result:

head -1 server-cert.pem

The output must show -----BEGIN CERTIFICATE-----.

Step 3: Convert the Private Key​

Check the first line of the key file:

head -1 example.key

If the output shows -----BEGIN PRIVATE KEY-----, rename it:

mv example.key server-key.pem

If the output shows -----BEGIN RSA PRIVATE KEY----- or -----BEGIN ENCRYPTED PRIVATE KEY-----, convert it:

openssl pkcs8 -topk8 -nocrypt -in example.key -out server-key.pem

Confirm the result:

head -1 server-key.pem

The output must show -----BEGIN PRIVATE KEY-----.

Step 4: Create the Public Key​

Generate the public key from the private key:

openssl rsa -in server-key.pem -outform PEM -pubout -out public-key.pem

If the command returns Not an RSA key (your certificate uses an ECC key), run this instead:

openssl pkey -in server-key.pem -pubout -out public-key.pem

Step 5: Add the Certificate Chain​

Perform this step only if your CA provided an intermediate file:

cat server-cert.pem intermediate.crt > temp.pem
mv temp.pem server-cert.pem

Step 6: Verify the Certificate and Key Match​

Run both commands:

openssl x509 -in server-cert.pem -noout -pubkey | openssl md5
openssl pkey -in server-key.pem -pubout | openssl md5

Both commands must print the same value.

note

If the two values differ, the certificate and key do not belong together. Stop here and check your source files before proceeding.

Step 7: Final File Check​

Confirm you now have these three files:

server-cert.pem
server-key.pem
public-key.pem

Part A is complete.

Part B: Deploy on the ObserveOps Server​

A maintenance window is required. The service will be down for about 5 minutes during this part.

Step 8: Log In to the Server​

ssh motadata@<server-ip>
sudo su -

Step 9: Back Up the Existing Files​

mkdir -p /motadata/backup
cd /motadata/motadata
cp -p server-cert.pem server-key.pem public-key.pem /motadata/backup/

Confirm the backup:

ls -la /motadata/backup/

Step 10: Replace the Files​

Copy the three new files into /motadata/motadata/, replacing the existing ones:

/motadata/motadata/server-cert.pem
/motadata/motadata/server-key.pem
/motadata/motadata/public-key.pem

Transfer them using WinSCP, FileZilla, scp, or any other method you normally use.

note

If you use an FTP or SFTP client, set the transfer mode to Binary, not ASCII.

Set the correct owner and permissions:

cd /motadata/motadata
chown motadata:root server-cert.pem server-key.pem public-key.pem
chmod 755 server-cert.pem server-key.pem public-key.pem

Confirm the new certificate is on disk:

openssl x509 -in /motadata/motadata/server-cert.pem -noout -subject -dates

Step 11: Stop the Motadata Service​

service motadata stop

Confirm the service has stopped:

service motadata status

Step 12: Start the Motadata Service​

service motadata start

Wait about 1 minute for the services to come up (allow up to 5 minutes on a busy server), then check the status:

service motadata status

The status must show active (running).

Confirm port 443 is listening again:

ss -tlnp | grep ':443'

Step 13: Verify the New Certificate​

Verify the certificate served on port 443:

echo | openssl s_client -connect 127.0.0.1:443 2>/dev/null | openssl x509 -noout -subject -dates

The subject and dates must show your new certificate.

Then open https://<your-domain> in a browser and confirm the padlock appears and login works.

Expected Outcomes​

  • The three files at /motadata/motadata/ (server-cert.pem, server-key.pem, public-key.pem) contain the new certificate data.
  • The Motadata service is running with the new certificate on port 443.
  • Browsers show the new certificate details with a valid padlock.

Rollback​

If verification fails, restore the previous certificate from the backup and restart the service:

cp -p /motadata/backup/server-cert.pem /motadata/motadata/
cp -p /motadata/backup/server-key.pem /motadata/motadata/
cp -p /motadata/backup/public-key.pem /motadata/motadata/

service motadata stop
service motadata start

Important Notes​

  • Do not modify any files inside /motadata/motadata/resources/.
  • Do not modify login-key.pem or login-pub.pem.
  • File names must exactly match server-cert.pem, server-key.pem, and public-key.pem.
  • The private key must be unencrypted so the service can start without prompting for a password.
  • Your certificate must include a SAN entry for your domain, otherwise browsers will reject it.