Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Blog
  • Questions
  • Learning
    • E-learning Courses
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Tutorials
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • DataMiner Insights
      • Security
      • Integration Studio
      • System Architecture
      • DataMiner Releases & Updates
      • DataMiner Apps
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
  • Downloads
  • More
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
      • General Inquiries
      • DataMiner DevOps Support
      • Commercial Requests
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

How to allow HTTPS session in protocol driver to work with self signed certificates

Solved1.05K views12th July 2023HTTPS
1
Branimir Bajt56 10th October 2022 1 Comment

We have a use case with a self made DMA protocol driver (running on DMA 10.1 CU18 cluster) connected to a 3rd party HTTP REST API service which uses SSL 1.2 and self signed certificates (we'll have proper SSL certificates in the future, but test and validation service currently uses self made ones). DMA seems not to work in that kind of setup even if we insert/import certificate into Windows Certification store (on all DMA nodes in the DMA cluster); message reported is forced disconnect and/pr similar. Furthermore, we did not find a way to properly connect DMA using HTTPS if service is not hosted on port 443 (btw. service may be on port 8443 for example). We cannot find anything useful in the documentation. Is there a way we can test the REST API using HTTPS with self signed certificates and connect that particular DMA protocol driver to some other port than 443?

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 12th July 2023
Marieke Goethals [SLC] [DevOps Catalyst] commented 12th July 2023

As this question has been inactive for a long time, we will now close it. If you want further assistance, feel free to post a new question about this topic.

1 Answer

  • Active
  • Voted
  • Newest
  • Oldest
2
Gellynck Jens [SLC]2.71K Posted 10th October 2022 9 Comments

More information about implementing HTTPS in a protocol:

  • Implementing HTTP communications
  • More information about HTTPS

The important bit:

To poll an HTTPS server on a different port than 443, you have to specify the "https://" prefix in the address field of the server in the element wizard.

The <Request> tag should also allow you to specify a different port number:

It is also possible to specify an absolute URL (e.g. "http://google.com"), which possibly specifies another host (or IP address/port) than the one specified in the corresponding element connection.

If you have tried these and it still doesn't work, could you share the exact error message you are receiving and the relevant parts of the protocol?

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 12th July 2023
Branimir Bajt commented 11th October 2022

Thanks for info, I’ll try with specifying “https://” prefix in the address field of the server in the element wizard, hope this works as unfortunately we cannot use absolute URL’s.

Btw. is there any workaround for self signed certificates and how to tackle these?

Gellynck Jens [SLC] commented 11th October 2022

Self-Signed certificates should be supported. It’s required to import them in the trusted root certification authorities in the windows certificate store (on the dataminer agent hosting the element). This may require a dataminer restart before it can work.

Branimir Bajt commented 11th October 2022

Self signed certificate has been imported into windows cert store and DMA was restarted couple of times already. We can use IE or Firefox browser from that windows node to make a REST API call towards the service and all goes well but DMA element is in timeout when doing the same. Service runs on port 443 and is accessible. Element logging currently reports only element timeout, no other errors are visible in the logging. We’ve checked SLErrors and SLErrorsInProtocol log files as well. Same element seems to work fine if we remove SSL (port 443) and we reconfigure everything to work over HTTP (port 80). Basic authentication is used to access the REST API data, but this should not affect the SSL (transport layer).

Gellynck Jens [SLC] commented 12th October 2022

Can you confirm the certificate usage is set to “server”? Web servers offering a client certificate will be rejected. Certificates with a weak signature will also be rejected (e.g. MD5 or SHA1), could you share the signature algorithm used in your certificate?

Branimir Bajt commented 12th October 2022

Checking at the certificate, intended purpose(s) :
– All issuance policies
– All application policies

Signature algorithm: SHA256RSA
Signature hash: SHA256
Subject Type=CA
Path Length Constraint=None

Show 4 more comments
You are viewing 1 out of 1 answers, click here to view all answers.
Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas

Recent questions

Web Applications exception in Cube due to invalid certificate 0 Answers | 0 Votes
Redundancy Groups and Alarming – Duplicate Alarms 0 Answers | 0 Votes
Correlation Engine: “Test rule” doesn’t result in a hit, despite functional rule 1 Answer | 3 Votes

Question Tags

adl2099 (115) alarm (62) Alarm Console (82) alarms (100) alarm template (83) Automation (223) automation scipt (111) Automation script (167) backup (71) Cassandra (180) Connector (109) Correlation (69) Correlation rule (52) Cube (151) Dashboard (194) Dashboards (188) database (83) DataMiner Cube (57) DIS (81) DMS (71) DOM (140) driver (65) DVE (56) Elastic (83) Elasticsearch (115) elements (80) Failover (104) GQI (159) HTTP (76) IDP (74) LCA (152) low code app (166) low code apps (93) lowcodeapps (75) MySQL (53) protocol (203) QAction (83) security (88) SNMP (86) SRM (337) table (54) trending (87) upgrade (62) Visio (539) Visual Overview (345)
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin