Skip to content

Private key and X.509 certificate chain tips

Nicholas Antinori edited this page Jul 31, 2026 · 4 revisions

If you serve the Glowroot UI over HTTPS and/or gRPC over HTTPS, you need:

  • a PEM-encoded X.509 certificate chain, and
  • a PEM-encoded PKCS#8 private key without a passphrase.

Examples below use ui-key.pem / ui-cert.pem. The same steps apply to grpc-key.pem / grpc-cert.pem. Shared names key.pem / cert.pem work when UI and gRPC share one certificate (Central Collector Installation, Agent Installation (for Central Collector)).

Private key

  • ASCII header BEGIN PRIVATE KEY → already PKCS#8 PEM → use as ui-key.pem.

    -----BEGIN PRIVATE KEY-----
    ...
    -----END PRIVATE KEY-----
    
  • ASCII header BEGIN RSA PRIVATE KEY → PKCS#1 PEM → convert to PKCS#8:

    openssl pkcs8 -in myprivatekey -topk8 -nocrypt -out ui-key.pem

    See openssl pkcs8.

  • Binary (DER) private key:

    openssl pkcs8 -inform DER -in myprivatekey -topk8 -nocrypt -out ui-key.pem

X.509 certificate chain

  • ASCII BEGIN CERTIFICATE → already PEM → use as ui-cert.pem.

    -----BEGIN CERTIFICATE-----
    ...
    -----END CERTIFICATE-----
    
  • Binary (DER) certificate:

    openssl x509 -inform DER -in mycertificate -out ui-cert.pem

    See openssl x509.

Quick self-signed (lab only)

openssl req -new -x509 -nodes -days 365 -out ui-cert.pem -keyout ui-key.pem

For production, use certificates from your CA and ensure agents trust the chain (grpc-trusted-root-certs.pem or the JVM trust store) when using gRPC HTTPS.

Clone this wiki locally