To strengthen the security of your system, replace the self-signed certificate on your
Genetec™ Update Service (GUS) with one issued by a trusted certificate authority.
What you should know
- You must select a certificate from the local machine's Personal
store.
- The certificate must contain authentication for the server and the client.
- This process requires connecting directly to the machine on which the certificate is
stored.
Procedure
-
Stop the Genetec Update Service and Genetec Update Service Sidecar services.
-
Open File Explorer and navigate to C:\ProgramData\Genetec Update
Service\.
-
Edit the GenetecUpdaterServiceParameters.xml file as
follows:
- Remove the
<CertificateThumbprint>…</ CertificateThumbprint>
row.
- Set the
EnableCertificateGeneration value to
false.
In the Microsoft Management Console (MMC), delete the existing self-signed
certificate from the machine's Personal store.
-
From the Windows start menu, open the Run application.
-
In the Run dialog box, enter mmc.exe and
click OK.
The Console window opens.
-
Click .
-
In the Add or Remove Snap-ins dialog, select
Certificates and click Add.
-
In the Certificates snap-in dialog, select .
-
Click .
-
In the Console window, navigate to .
-
Delete the GUS certificate generated by the local machine.
Add your trusted certificate to GUS.
-
Start the Genetec Update Service and Genetec Update Service Sidecar services.
-
In a local browser, open the http://localhost:4594/Certificates
website.
-
On the Select your Genetec Update Service Certificate page, choose
your trusted certificate from the Certificates list.
-
Click Apply.
The page automatically redirects to the GUS web page at
https://localhost:4595.
-
Restart the Genetec Update Service Sidecar service to ensure the new certificate is
configured correctly.