Export and Import Certificates for Event Server Configuration

The following BeyondInsight certificates must be exported from the primary BeyondInsight server and then imported on the Event Server:

  • eEyeEmsCA: root certificate
  • EmsClientCert: client authentication certificate
  • eEyeEmsServer: server authentication certificate

Export the Certificate

To export the certificate using the Certificates snap-in, follow the steps below:

  1. Run mmc.exe.
  2. Select File > Add/Remove snap-in.
  3. Select Certificates, and then click Add.
  4. Select Computer Account, and then click Next.
  5. Select Local Computer, and then click Finish.
  6. Click OK.
  7. Expand Certificates.

An image of the Personal Certificates location in the Event Server configuration.

  1. Expand Personal, and then select Certificates.

 

An image of the eEyeEmsClient certificate export in the Event Server configuration.

  1. Right-click eEyeEmsClient > All Tasks > Export.
    • Click Next.
    • Select Yes, export the private key.
    • Select the check boxes: Include all certificates in the certification path if possible and Export all extended properties.
    • Enter a password. The password is needed when you import the certificate.
    • Click browse. Save the file with a .pfx extension, and then click Next.
    • Click Finish.
  2. Copy the exported file to a network share.

 

Import the EmsClientCert and eEyeEmsServer Certificates

You must import the EmsClientCert and eEyeEmsServer certificates on every Event Server you deploy. These certificates are imported to the Personal store.

To import the certificate using the Certificates snap-in, follow the steps below:

  1. Open the Certificates snap-in.
  2. Right-click the Personal folder, and then select All Tasks > Import.
  3. Click Next on the first page of the import wizard.
  4. Click Browse

An image of the selected file .pfx file extension in the Event Server configuration.

  1. On the Open dialog box, ensure that the file type is selected from the list. The certificate file has a .pfx extension.

 

  1. Find the file and click Open. Click Next.

An image of the EmsClientCert and eEyeEmsServer certificates import in the Event Server configuration.

  1. Enter the certificate password. This is the password that you created when you exported the certificate.

 

  1. Ensure the Include all extended properties check box is selected.
  2. Click Next.
  3. The certificate must be imported to the Personal store. Click Next.
  4. Click Finish.

Import the eEyeEmsCA Certificate

To import the eEyeEmsCA certificate to the Trusted Root store, follow the steps below:

  1. Open the Certificate Manager snap-in.
  2. Expand Trusted Root Certification Authorities.
  3. Right-click the Certificates folder, and then select All Tasks > Import.
  4. Click Next on the first page of the import wizard.
  5. Click Browse.
  6. On the Open dialog box, ensure that the file type is selected from the list. The certificate file has a .pfx extension.
  7. Enter the certificate password. This is the password that you created when you exported the certificate.
  8. Ensure the Include all extended properties check box is selected.
  9. Click Next.

An image of the eEyeEmsCA certificate import in the Event Server configuration.

  1. The certificate must be imported to the Trusted Root store. Click Next.

 

  1. Click Finish.

Confirm Certificates for BeyondInsight Server and Event Server

Confirm certificates on the BeyondInsight server and Event Server are the same by reviewing the information in the Thumbprint for the certificate.

An image of the certificate thumbprint confirmation in the Event Server configuration.

Double-click the certificate, and then select the Details tab.