If the ASE certificate is changed after the deployment of PingIntelligence policy and it doesn't match with the certificate present in the ase.pem certificate file, you might encounter SSL related issues.
To resolve these issues:
- Undeploy the PingIntelligence policy by following either of the two options as applicable:
To obtain the correct certificate to match what's in the
ase.pem file, run the following command.
# openssl s_client -showcerts -connect <ASE IP address>:<port no> </dev/null 2>/dev/null | openssl x509 -outform PEM > ase.pem
- Paste the correct certificate in the /opt/pingidentity/pi/apigee/certs/ase.pem file.
Redeploy the PingIntelligence policy by following either of the two options as
- Deploy PingIntelligence policy for Flow Hook with self-signed certificate
- Deploy PingIntelligence policy for Flow Call Out with self-signed certificate
Make sure that the ase_ssl parameter in /pingidentity/pi/apigee/config/apigee.properties file is set to