Why This Matters
SSL/TLS certificates on your Documentum environment (Content Server, D2, DA, or the JMS) expire on a schedule, usually 1-3 years depending on your certificate authority. When one lapses, client connections start failing with handshake errors, DFC connections refuse to bind, and users get locked out of D2 or Webtop until the certificate is renewed. This guide walks through updating an SSL certificate for a typical Documentum deployment running on a Java application server (JBoss/WildFly or WebLogic), which is the most common setup.
The exact commands vary a bit by app server and OS, but the underlying flow is the same everywhere: generate or renew the cert, get it into a keystore, point the app server (and DFC clients) at that keystore, and restart.
Prerequisites
- Admin access to the Documentum Content Server host and the app server hosting D2/DA (JBoss, WildFly, or WebLogic)
- The
keytoolutility (ships with the JDK Documentum uses) or OpenSSL, depending on your keystore format - Your new certificate files: the signed cert, any intermediate/root CA certs, and the private key (or a CSR ready to submit if you haven’t generated the cert yet)
- The existing keystore password and alias name (check
server.ini,dfc.properties, or your app server’s config for the current keystore path) - A maintenance window, since Content Server and the app server both need a restart to pick up the new certificate
- A backup of the current keystore file before you touch anything
Step-by-Step: Updating the Certificate
1. Back up the existing keystore
cp $JAVA_HOME/keystore/documentum.keystore documentum.keystore.bak
2. Generate a new key pair and CSR (skip if you already have a signed cert)
keytool -genkeypair -alias documentum -keyalg RSA -keysize 2048 \ -keystore documentum.keystore -validity 730keytool -certreq -alias documentum -keystore documentum.keystore \ -file documentum.csr
Submit documentum.csr to your CA and get back the signed certificate plus any intermediate/root certs.
3. Import the CA chain and the new certificate into the keystore
Import the root and intermediate certs first, then the signed cert, using the same alias you generated the key pair with:
keytool -importcert -alias root -keystore documentum.keystore -file root-ca.cerkeytool -importcert -alias intermediate -keystore documentum.keystore -file intermediate-ca.cerkeytool -importcert -alias documentum -keystore documentum.keystore -file new-cert.cer
4. Point the app server at the updated keystore
- JBoss/WildFly: update the
<ssl>element instandalone.xml(or your profile’s config) with the keystore path, password, and alias if they changed. - WebLogic: update the Keystores tab on the managed server, pointing Custom Identity and Trust to the new keystore file.
5. Update DFC clients
If DFC clients (D2, DA, custom apps) reference the keystore directly or via dfc.properties, update dfc.security.keystore.file and related properties to match.
6. Restart services
Restart the app server, then restart Documentum Content Server (dm_start_<repository> / dm_stop_<repository>) so DFC picks up the new trust chain.
Verifying the New Certificate
- Confirm the keystore shows the new expiration date and correct alias:
keytool -list -v -keystore documentum.keystore -alias documentum
- Check the certificate chain being served on the port Documentum uses for SSL:
openssl s_client -connect <hostname>:<port> -showcerts
- Log into D2 or Webtop over HTTPS and confirm there’s no browser certificate warning
- Test a DFC connection from a client machine to confirm the trust chain resolves without SSL handshake errors
- Check
dm_agent_execand repository logs for any lingering SSL/TLS handshake failures after restart
| Symptom | Likely Cause | Fix |
|---|---|---|
PKIX path building failed | Intermediate/root CA missing from keystore | Re-import the full chain, not just the leaf cert |
| DFC connections drop after restart | Alias mismatch between app server config and keystore | Confirm the alias in standalone.xml/WebLogic matches the keystore alias exactly |
| Browser still shows old cert | App server or reverse proxy cache not restarted | Restart the app server and any load balancer/reverse proxy in front of it |
keytool error “keystore password was incorrect” | Wrong password, or keystore type mismatch (JKS vs PKCS12) | Verify keystore type with keytool -list -keystore <file> -storetype PKCS12 |
| D2/DA login hangs or times out | Content Server didn’t fully restart or repository didn’t come back up | Check dm_start_<repository> logs before touching the app server again |
Leave a comment