How to add our own certificate for CMX server which is currently using a self-signed certificate?

Categories:
Solution Number:
HOW18
Last Modified:
2026-08-25
Description
We see that CMX Server on APM agent using a self-signed certificate. How can we add our own certificate so we do not use the self-signed certificate?
Solution
By default, the CMX Server will generate it's own self-signed TLS certificate and private key.
These files are located in the below location
/Panorama/hedzup/mn/security directory.  

The certificate file is cmx-server.crt while the private key file is cmx-server.key.

Alternatively, if a user wishes they could supply their own certificate and key files.
To configure their certificate and private key,  the file below file below must be updated to add the path to the certificate and private key files under the section called 'comms'.  
/Panorama/hedzup/mn/userdata/plugins/cmx/metadata/configuration-basic.json

The following snippet show's the configuration change,  using the customer's certificate and key files:

"comms": {
    "port": 7074,
    "secure": true,
    "sslPrivateKeyFile": "/etc/ssl/private/my_private_key_file.key",
    "sslCertificateFile": "/etc/ssl/certs/my_cert_file.crt"
},


**Please open a technical support case if you have a question or an issue
Environment
APM Agent
NOTICE: Riverbed® product names have changed. Please refer to the Product List for a complete list of product names.
Can't find an answer? Create a case