Configure a CA-signed certificate for ArcGIS Server when accessed through ArcGIS Web Adaptor—ArcGIS Enterprise (2024)

When ArcGIS Web Adaptor has been configured to forward requests to your ArcGIS Server site, you need to enable HTTPS on the web server hosting ArcGIS Web Adaptor. To get started, follow the steps in the sections below.

  1. Create a new self-signed certificate.
  2. Request a CA to sign your certificate.
  3. Configure ArcGIS Server to use the certificate.
  4. Configure each machine in your deployment.
  5. Configure HTTPS on ArcGIS Web Adaptor.
  6. Access your site.

Create a new self-signed certificate

  1. Sign in to the ArcGIS Server Administrator Directory at https://gisserver.domain.com:6443/arcgis/admin.
  2. Browse to machines > [machine name] > sslcertificates.
  3. Click generate.
  4. Provide values for the parameters on this page:
    OptionDescription

    Alias

    A unique name that easily identifies the certificate.

    Key Algorithm

    Use RSA (the default) or DSA.

    Key Size

    Specifies the size in bits to use when generating the cryptographic keys used to create the certificate. The larger the key size, the harder it is to break the encryption; however, the time to decrypt encrypted data increases with key size. For DSA, the key size can be between 512 and 1,024. For RSA, the recommended key size is 2,048 or greater.

    Signature Algorithm

    Use the default (SHA1withRSA). If your organization has specific security restrictions, one of the following algorithms can be used for DSA:SHA256withRSA, SHA384withRSA, SHA512withRSA, SHA1withDSA.

    Common Name

    Use the domain name of your server name as the common name.

    If your server will be accessed on the Internet through the URL https://www.gisserver.com:6443/arcgis/, use www.gisserver.com as the common name.

    If your server will only be accessible on your local area network (LAN) through the URL https://gisserver.domain.com:6443/arcgis, use gisserver.domain.com as the common name.

    Organizational Unit

    The name of your organizational unit, for example, GIS Department.

    Organization

    The name of your organization, for example, Esri.

    City or Locality

    The name of the city or locality, for example, Redlands.

    State or Province

    The full name of your state or province, for example, California.

    Country Code

    The abbreviated code for your country, for example, US.

    Validity

    The total time in days during which this certificate will be valid, for example, 365.

    Subject Alternative Name

    The subject alternative name (SAN) is an optional parameter thatdefines alternatives to the common name (CN) specified in the certificate. There cannot be any spaces in the SAN parameter value.

    If this parameter is left empty, the fully qualified domain name of the local machine is used as the default value. The SAN field supports multiple values; however, it must include the fully qualified domain name of the website. For example, the URLs https://www.esri.com, https://esri,and https://10.60.1.16 can be usedto access the same site if the certificate is created using thefollowing SAN parameter value:

    DNS:www.esri.com,DNS:esri,IP:10.60.1.16

  5. Click Generate to generate the certificate.

Request a CA to sign your certificate

If ArcGIS Web Adaptor will be the only gateway to your site and your organization's IT security policy allows the use of self-signed certificates, you can skip this section. However, if users will occasionally bypass ArcGIS Web Adaptor and access ArcGIS Server directly or your IT policies disallow the use of self-signed certificates, it is recommended to request a CA to sign your certificate by following the steps below.

  1. Open the self-signed certificate you created in the previous section and click generateCSR. Copy the contents into a file, usually with a .csr extension.
  2. Submit the CSR to a CA of your choice. You can obtain a Distinguished Encoding Rules (DER) or Base64 encoded certificate. If the CA requests the type of web server the certificate is for, specify Other\Unknown or Java Application Server. After verifying your identity, the CA will send you a .crt or .cer file.
  3. Save the signed certificate you received from the CA to a location on your computer. In addition to the signed certificate, the CA will also issue a root certificate. Save the CA root certificate to your computer.
  4. Sign in to the ArcGIS Server Administrator Directory: https://gisserver.domain.com:6443/arcgis/admin.
  5. Click machines > [machine name] > sslcertificates > importRootOrIntermediate to import the root certificate provided by the CA. If the CA issued any additional intermediate certificates, import those as well.
  6. Browse to machines > [machine name] > sslcertificates.
  7. Click the name of the self-signed certificate that you submitted to the CA.
  8. Click importSignedCertificate and browse to the location where you saved the signed certificate you received from the CA.
  9. Click Submit. This replaces the self-signed certificate you created in the previous section with the CA-signed certificate.

Configure ArcGIS Server to use the certificate

To specify the certificate that ArcGIS Server should use, complete the following steps:

  1. Sign in to the ArcGIS Server Administrator Directory at https://gisserver.domain.com:6443/arcgis/admin.
  2. Browse to machines > [machine name].
  3. Click edit.
  4. Type the name of the certificate that you want to use in the Web server SSL Certificate field.
  5. Click Save Edits to apply your change. This automatically restarts your ArcGIS Server site.
  6. After your site has restarted, verify that you can access the URL https://gisserver.domain.com:6443/arcgis/admin. If you do not get a response from this URL, ArcGIS Server was unable to use the specified SSL certificate. Check your SSL certificate and configure ArcGIS Server to use a new or different certificate.
  7. On the current page, view the property Web server SSL Certificate to verify that the desired certificate will be used for HTTPS.

Configure each machine in your deployment

If you have a multiple-machine deployment of ArcGIS Server, you must configure each machine in your deployment to use the certificate. Repeat the steps in the previous section to configure the certificate with each of your ArcGIS Server machines.

Configure HTTPS on ArcGIS Web Adaptor

Enable HTTPS on the web server that is hosting ArcGIS Web Adaptor. For full instructions, consult the product documentation specific to your web server.

Access your site

You can securely access ArcGIS Server directly though HTTPS using port 6443 or the Web Adaptor URL. If you rename your ArcGIS Server site, you can continue to access ArcGIS Server using HTTPS; however, you must generate a new certificate and configure ArcGIS Server to use it. The URLs are formatted as follows:

ArcGIS Server Manager

Access Manager through the server: https://gisserver.domain.com:6443/arcgis/manager.

Access Manager through ArcGIS Web Adaptor (only applies if administrative access is enabled): https://webadaptorhost.domain.com/webadaptorname/manager.

ArcGIS Server Services Directory

Access Services Directory through the server: https://gisserver.domain.com:6443/arcgis/rest/services.

Access Services Directory through ArcGIS Web Adaptor: https://webadaptorhost.domain.com/webadaptorname/rest/services.

Feedback on this topic?

Configure a CA-signed certificate for ArcGIS Server  when accessed through ArcGIS Web Adaptor—ArcGIS Enterprise (2024)
Top Articles
How to crack Aptitude/Competitive exams and Why it is so important for career? – TATTI
Karol G Named Woman of the Year at Annual Billboard Latin Women in Music
Maxtrack Live
Kevin Cox Picks
7 Verification of Employment Letter Templates - HR University
Week 2 Defense (DEF) Streamers, Starters & Rankings: 2024 Fantasy Tiers, Rankings
Restaurer Triple Vitrage
Lamb Funeral Home Obituaries Columbus Ga
Kaydengodly
America Cuevas Desnuda
Kristine Leahy Spouse
Jonathan Freeman : "Double homicide in Rowan County leads to arrest" - Bgrnd Search
J Prince Steps Over Takeoff
Walgreens On Nacogdoches And O'connor
What Was D-Day Weegy
Housework 2 Jab
How Much Is Tj Maxx Starting Pay
Luna Lola: The Moon Wolf book by Park Kara
Google Flights Missoula
Mflwer
Marine Forecast Sandy Hook To Manasquan Inlet
Universal Stone Llc - Slab Warehouse & Fabrication
Laveen Modern Dentistry And Orthodontics Laveen Village Az
‘The Boogeyman’ Review: A Minor But Effectively Nerve-Jangling Stephen King Adaptation
Craigslist St. Cloud Minnesota
Ontdek Pearson support voor digitaal testen en scoren
Labcorp.leavepro.com
How do you get noble pursuit?
TJ Maxx‘s Top 12 Competitors: An Expert Analysis - Marketing Scoop
Craigslist Boerne Tx
Lawrence Ks Police Scanner
Craigslist Central Il
Mg Char Grill
Kokomo Mugshots Busted
Lowell Car Accident Lawyer Kiley Law Group
Uhaul Park Merced
آدرس جدید بند موویز
Jennifer Reimold Ex Husband Scott Porter
Agematch Com Member Login
Asian Grocery Williamsburg Va
42 Manufacturing jobs in Grayling
Daily Jail Count - Harrison County Sheriff's Office - Mississippi
8005607994
Walgreens Agrees to Pay $106.8M to Resolve Allegations It Billed the Government for Prescriptions Never Dispensed
Red Dead Redemption 2 Legendary Fish Locations Guide (“A Fisher of Fish”)
Todd Gutner Salary
Sea Guini Dress Code
Graduation Requirements
What your eye doctor knows about your health
Marion City Wide Garage Sale 2023
Shad Base Elevator
Latest Posts
Article information

Author: Lakeisha Bayer VM

Last Updated:

Views: 6588

Rating: 4.9 / 5 (69 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Lakeisha Bayer VM

Birthday: 1997-10-17

Address: Suite 835 34136 Adrian Mountains, Floydton, UT 81036

Phone: +3571527672278

Job: Manufacturing Agent

Hobby: Skimboarding, Photography, Roller skating, Knife making, Paintball, Embroidery, Gunsmithing

Introduction: My name is Lakeisha Bayer VM, I am a brainy, kind, enchanting, healthy, lovely, clean, witty person who loves writing and wants to share my knowledge and understanding with you.