Update SSL Certificate for TCM
SSL certificate for TCM has expired or needs to be updated
Apache Tomcat
SSL Certificate
Tyler Content Manager (TCM)
TCM Certificate
Existing SSL certificate set to expire soon or has already expired
Before starting, you will need to obtain a copy of the certificate as a .PFX along with the password
The Certificate Utility works best when the .PFX is placed on the desktop of the TCM server with a simple name such as cert20xx.pfx
The .PFX file name and the directory path cannot have any spaces
A common path is a non-OneDrive Desktop location
Certificate passwords must:
Be at least 8 digits long
Cannot contain any special characters
Connect to the TCM server with an administrative account such as tylerservice
Place copy of the new certificate in .PFX format on the desktop
Open File Explorer
Navigate to the Apache Certs directory (Ex: D:\ApacheCerts)
Clean up old files in this directory (previous .pfx files, files with a .old extension, etc.)
Rename the existing certificate file name and add .old to end of the file name
Ex: Cert.pem.old
Use the TCM Cert Utility to convert the .PFX certificate*
Navigate to D:\Tyler Installs\CertUtil
Right click CertUtility.exe > Run as administrator
Cert Path: Current location of .PFX
Click Browse
Select file
Click Open
Note: The current path of the .PFX file must not contain any spaces
Cert Destination: ApacheCerts folder
Ex: D:\ApacheCerts
Click Browse
Expand This PC
Expand applicable drive
Click ApacheCerts folder
Click OK
Cert Password: type in certificate password
Click Create PEM
Navigate back to D:\ApacheCerts and rename the new .pem to match the previous cert’s name if needed
For instance: SSLCert.pem
The certificate name can be verified in the server.xml file located in <DRV>:\Program Files\Apache Software Foundation\XXXX\Conf
Open Windows Services and restart the Apache service(s)
Please note: It may take a few minutes for Apache to fully start back up. If you receive a 503 error trying to access TCM, please wait a few more minutes and try again.
Open a browser and navigate to the TCM URL to verify that the certificate is now updated
Test launching the desktop client
If a PKIK error is received, please contact Tyler Systems Management Support or log a case via the Online Support Client Portal
*If you do not have the CertUtility installed on your TCM server, please contact Tyler Systems Management Support or log a case via the Online Support Client Portal
TCM Full Client certificate error using JLink - PKIX path building failed