Uploading a Certificate to the Logger:
Upload a valid server SSL (Secure Sockets Layer) certificate file for the ArcSight Manager that you are establishing as a Logger destination for forwarding events and alerts.
If your Manager does not have FIPS 140-2 mode enabled, you can obtain a certificate file for your Manager in these ways:
Use the keytoolgui utility to export a Manager’s certificate as described in the “Using Keytoolgui to Export Certificate” procedure in the ArcSight ESM Administrator’s Guide. For detailed information about keystore, truststore, their locations on the Manager, ArcSight Console, and the SmartConnectors, see the ArcSight ESM Administrator’s Guide.
Once you have exported a certificate for your Manager, copy it to the machine from which you connect to your Logger.
If your Manager has FIPS 140-2 mode enabled, run this command to export the Manager’s certificate from the Manager’s <ARCSIGHT_HOME>/bin directory:
arcsight runcertutil -L -n managerkey -r -d <ARCSIGHT_HOME>/config/jetty/nssdb -o <absolute_path_to_manager.cert>
This command generates the manager.cert file, the Manager’s certificate, in the location that you specified in the above command.
Note: By default, the manager.cert file will be exported to your <ARCSIGHT_HOME> directory if you do not specify the absolute path to the manager.cert file destination.
To upload a certificate file for an ESM Destination:
Click Add. An screen will be displayed.
This name is used to easily identify a certificate file. For example, arcsight_esm_manager1_cert.
.cer, .crt, and .pem.