Tech Kraft

Documentum, AWS, Java, Ruby on Rails, Linux, Windows, App Servers


How to Update SSL Certificates for Documentum

Why This Matters

SSL/TLS certificates on your Documentum environment (Content Server, D2, DA, or the JMS) expire on a schedule, usually 1-3 years depending on your certificate authority. When one lapses, client connections start failing with handshake errors, DFC connections refuse to bind, and users get locked out of D2 or Webtop until the certificate is renewed. This guide walks through updating an SSL certificate for a typical Documentum deployment running on a Java application server (JBoss/WildFly or WebLogic), which is the most common setup.

The exact commands vary a bit by app server and OS, but the underlying flow is the same everywhere: generate or renew the cert, get it into a keystore, point the app server (and DFC clients) at that keystore, and restart.

Prerequisites

  • Admin access to the Documentum Content Server host and the app server hosting D2/DA (JBoss, WildFly, or WebLogic)
  • The keytool utility (ships with the JDK Documentum uses) or OpenSSL, depending on your keystore format
  • Your new certificate files: the signed cert, any intermediate/root CA certs, and the private key (or a CSR ready to submit if you haven’t generated the cert yet)
  • The existing keystore password and alias name (check server.ini, dfc.properties, or your app server’s config for the current keystore path)
  • A maintenance window, since Content Server and the app server both need a restart to pick up the new certificate
  • A backup of the current keystore file before you touch anything

Step-by-Step: Updating the Certificate

1. Back up the existing keystore

cp $JAVA_HOME/keystore/documentum.keystore documentum.keystore.bak

2. Generate a new key pair and CSR (skip if you already have a signed cert)

keytool -genkeypair -alias documentum -keyalg RSA -keysize 2048 \
-keystore documentum.keystore -validity 730
keytool -certreq -alias documentum -keystore documentum.keystore \
-file documentum.csr

Submit documentum.csr to your CA and get back the signed certificate plus any intermediate/root certs.

3. Import the CA chain and the new certificate into the keystore

Import the root and intermediate certs first, then the signed cert, using the same alias you generated the key pair with:

keytool -importcert -alias root -keystore documentum.keystore -file root-ca.cer
keytool -importcert -alias intermediate -keystore documentum.keystore -file intermediate-ca.cer
keytool -importcert -alias documentum -keystore documentum.keystore -file new-cert.cer

4. Point the app server at the updated keystore

  • JBoss/WildFly: update the <ssl> element in standalone.xml (or your profile’s config) with the keystore path, password, and alias if they changed.
  • WebLogic: update the Keystores tab on the managed server, pointing Custom Identity and Trust to the new keystore file.

5. Update DFC clients

If DFC clients (D2, DA, custom apps) reference the keystore directly or via dfc.properties, update dfc.security.keystore.file and related properties to match.

6. Restart services

Restart the app server, then restart Documentum Content Server (dm_start_<repository> / dm_stop_<repository>) so DFC picks up the new trust chain.

Verifying the New Certificate

  • Confirm the keystore shows the new expiration date and correct alias:
keytool -list -v -keystore documentum.keystore -alias documentum
  • Check the certificate chain being served on the port Documentum uses for SSL:
openssl s_client -connect <hostname>:<port> -showcerts
  • Log into D2 or Webtop over HTTPS and confirm there’s no browser certificate warning
  • Test a DFC connection from a client machine to confirm the trust chain resolves without SSL handshake errors
  • Check dm_agent_exec and repository logs for any lingering SSL/TLS handshake failures after restart
SymptomLikely CauseFix
PKIX path building failedIntermediate/root CA missing from keystoreRe-import the full chain, not just the leaf cert
DFC connections drop after restartAlias mismatch between app server config and keystoreConfirm the alias in standalone.xml/WebLogic matches the keystore alias exactly
Browser still shows old certApp server or reverse proxy cache not restartedRestart the app server and any load balancer/reverse proxy in front of it
keytool error “keystore password was incorrect”Wrong password, or keystore type mismatch (JKS vs PKCS12)Verify keystore type with keytool -list -keystore <file> -storetype PKCS12
D2/DA login hangs or times outContent Server didn’t fully restart or repository didn’t come back upCheck dm_start_<repository> logs before touching the app server again


Leave a comment

About Me

Senior Software Engineer professional with over 16 years of success with multiple open source technologies and various Content Management platforms and solutions.

Proven technical abilities through numerous projects involving enterprise web application design and development, application installation, configuration and support, and workflow and collaboration system designs.

  • Ability to learn new technologies and platforms quickly and apply them to the task at hand.
  • Excellent analytical skills, and strong communication and collaboration abilities.
  • Technical emphasis in including but not limited to Java, Ruby on Rails, Documentum and Alfresco
    in both Linux and Windows based environments

Newsletter