To resolve these issues:

  1. Undeploy the PingIntelligence policy by following either of the two options as applicable:
  2. To obtain the correct certificate to match what's in the ase.pem file, run the following command.
    # openssl s_client -showcerts -connect <ASE IP address>:<port no> </dev/null 2>/dev/null | openssl x509 -outform PEM > ase.pem
  3. Paste the correct certificate in the /opt/pingidentity/pi/apigee/certs/ase.pem file.
  4. Redeploy the PingIntelligence policy by following either of the two options as applicable:
    Note:

    Make sure that the ase_ssl parameter in /pingidentity/pi/apigee/config/apigee.properties file is set to true.