Repository navigation
Private key and X.509 certificate chain tips
If you serve the Glowroot UI over HTTPS and/or gRPC over HTTPS, you need:
- a PEM-encoded X.509 certificate chain, and
- a PEM-encoded PKCS#8 private key without a passphrase.
Examples below use ui-key.pem / ui-cert.pem. The same steps apply to grpc-key.pem / grpc-cert.pem. Shared names key.pem / cert.pem work when UI and gRPC share one certificate (Central Collector Installation, Agent Installation (for Central Collector)).
-
ASCII header
BEGIN PRIVATE KEY→ already PKCS#8 PEM → use asui-key.pem.-----BEGIN PRIVATE KEY----- ... -----END PRIVATE KEY----- -
ASCII header
BEGIN RSA PRIVATE KEY→ PKCS#1 PEM → convert to PKCS#8:openssl pkcs8 -in myprivatekey -topk8 -nocrypt -out ui-key.pem
See openssl pkcs8.
-
Binary (DER) private key:
openssl pkcs8 -inform DER -in myprivatekey -topk8 -nocrypt -out ui-key.pem
-
ASCII
BEGIN CERTIFICATE→ already PEM → use asui-cert.pem.-----BEGIN CERTIFICATE----- ... -----END CERTIFICATE----- -
Binary (DER) certificate:
openssl x509 -inform DER -in mycertificate -out ui-cert.pem
See openssl x509.
openssl req -new -x509 -nodes -days 365 -out ui-cert.pem -keyout ui-key.pemFor production, use certificates from your CA and ensure agents trust the chain (grpc-trusted-root-certs.pem or the JVM trust store) when using gRPC HTTPS.
Home · Releases · Discussions · Issues · Troubleshooting
Glowroot is licensed under the Apache License 2.0.
- Home
- Choosing Embedded vs Central
- What's new
- Health endpoints
- Troubleshooting Tips
- What Glowroot does not do
- Plugin coverage gaps
- How to read a Trace
- Re-engineering a slow call
- Releases
- Agent Installation (with Embedded Collector)
- Agent Upgrade
- Multiple JVMs and agent.id
- Where are my application server's JVM args?
- Plugins
- Instrumentation
- Plugin coverage gaps
- Batch application instrumentation
- Administration-Storage
- Administration-Web
- Agent Installation (for Central Collector)
- Central Collector Installation
- Central Collector with Docker
- Central Collector Upgrade
- Central Collector Cluster
- Cassandra Client Configuration
- Kubernetes
- Multiple JVMs and agent.id
- Agents and rollups
- Plugins
- Instrumentation
- Plugin coverage gaps
- Synthetic monitors
- Administration-Storage
- How to read a Trace
- Re-engineering a slow call
- Transaction tabs
- Transaction configuration
- Alerts and incidents
- Gauges and JMX
- Errors tab
- UI Defaults
- Advanced and config.json
- Ad-hoc reports
- Users and Roles