Customizing HTTPS on REST API

Hello,

Can someone please let me know if it’s possible to customize HTTPS connection on REST API on version prior to BigFix 10.0. I am running BigFix 9.5 and all my efforts to upload a Self Signed Certificate to BigFix and setting the client settings for BigFix server to use that has been failing.The link below has help for Ver 10 & 11 and not for version prior to that, so unsure if custom certificates are supported in older versions (please see link below)

Customizing HTTPS on REST API

In the screenshot below,

ssl.pvk and ssl.crt are the private key and cert file created for BigFix server using it’s IP address and Hostname, since the original certificate presented by BigFix server doesn’t provide the SAN causing the application sending REST API requests to the server to fail when server validation is enabled.

Question: Should I also Change the _BESRelay_HTTPServer_SSLPrivateKeyFilePath and _BESRelay_HTTPServer_SSLCertificateFilePath to point to the custom certificate? It is currently left at the default certificate. My understanding was _BESServer is for application connecting to BigFix using REST API, while BESRelay is for Hosts managed by BigFix to connect to the root server.

Thanks!

It should be possible: Customizing HTTPS on REST API

Recall that 9.5 is out of support…

Thanks @DanieleColi !

That helped to pass Certificate validation by pointing _BESRelay_HTTPServer_SSLPrivateKeyFilePath and _BESRelay_HTTPServer_SSLCertificateFilePath to the custom self signed certificates. While it worked for some APIs, it broke the rest

What worked
curl -u admin --insecure "https://:52311/api/computers"

What broke
curl -u admin --insecure "https://:52311/api/query?relevance=names%20of%20bes%20computers"

Cannot perform relevance query evaluation at this time because there is no reachable Web Reports instance collecting data from this Server.

Could it be because the BESRelay certificate and key filename settings are not pointing anymore to those in BESReportsData (SelfWRCertificate.pem and key) and the 2nd API Request needs to connect to BES Web Reports Server? My self signed certs replaced those. Again I am on Version 9.5. Thanks!

Search for that message on the Customer Support Knowledgbase..

1 Like

That was correct. Since you changed the SSL certificate, Web Reports could have problem talking to the Root Server: add it as a new datasource (and remove the old one).