graph-studio
Replacing the Self-Signed Certificate
By default, Graph Studio installations include a self-signed certificate. Follow the instructions below if you want to replace the default certificate with a trusted one. The steps guide you through using OpenSSL to generate an SSL certificate and signing request and then uploading the signed certificate to Graph Studio.
Generate an SSL Certificate and Signing Request
If necessary, install OpenSSL.
Create a request configuration file. For example, create a file called certificate.cnf. Then add the following contents to the file. These contents include parameters for creating a multi-domain certificate:
# certificate.cnf
[req] default_bits = 2048 prompt = no default_md = rsa req_extensions = req_ext distinguished_name = dn
[ dn ] C =
ST = L = O = OU = emailAddress = CN = [ req_ext ] subjectAltName = @alt_names
[ alt_names ] DNS.1 =
DNS.2 = DNS.3 = Replace the placeholders in the file with the appropriate values. For example:
# certificate.cnf
[req] default_bits = 2048 prompt = no default_md = rsa req_extensions = req_ext distinguished_name = dn
[ dn ] C = US ST = MA L = Boston O = Cambridge Semantics OU = IT emailAddress = webmaster@cambridgesemantics.com CN = sample.cambridgesemantics.com
[ req_ext ] subjectAltName = @alt_names
[ alt_names ] DNS.1 = sample1.domain.com DNS.2 = 10.0.33.103 DNS.3 = sample3.domain.com
Run the following command to generate the signing request and private key using the configuration file:
openssl req -new -sha256 -nodes -out <csr_file_name>.csr -newkey rsa:2048 -keyout <key_name>.pem -config <config_file_name>.cnf
For example:
openssl req -new -sha256 -nodes -out anzo-csr.csr -newkey rsa:2048 -keyout anzo-key.pem -config certificate.cnf
Send the resulting CSR to a certificate authority for signing.
Upload the Trusted Certificate to Anzo
When you receive the signed certificate from the certificate authority, rename the certificate to anzo-crt.crt.
Then follow the steps below to create a PKCS12 key:
Run the following command to concatenate the signed certificate and private key file that you generated into an
anzo.pemfile:cat <key_name>.pem anzo-crt.crt > anzo.pem
For example:
cat anzo-key.pem anzo-crt.crt > anzo.pem
Run the following command to convert the resulting
anzo.pemfile to PKCS12, choose a name for the certificate, and set an export password:openssl pkcs12 -export -in anzo.pem -out anzo.pkcs12 -name "<destination_alias>"
If you have installed OpenSSL version 3 or later, include the
--legacyflag in the command (shown below):openssl pkcs12 -export -in anzo.pem -out anzo.pkcs12 -name "<destination_alias>" --legacy
Enter Export Password: Verifying - Enter Export Password:
Copy the
anzo.pkcs12certificate to your computer if necessary.In the Administration application, expand the Servers menu and click Server Certificates. Graph Studio displays the Server Certificates screen. For example:

Click Upload Server Key. Graph Studio displays the Upload Server Key dialog box.

Supply the required values:
- In the Destination Alias field, specify the destination alias that you chose when you created the PKCS12 certificate.
- In the Password field, specify the Export Password that you set when you created the PKCS12 certificate.
- Click the Choose File button and select the anzo.pkcs12 file.
- Click the Keystore type field and select PKCS12 from the drop-down list.
Click Upload to upload the certificate.
Finally, follow these steps to apply the new certificate to the Graph Studio server SSL ports:
In the Servers menu, click Server Settings.
On the Server Settings screen, expand Ports and click Edit. For example:

Click the Certificates drop-down list for each of the enabled SSL ports and select the new certificate. Then click Save.
Restart Graph Studio to apply the configuration change.
Source: https://docs.sw.siemens.com/documentation/external/PL20260212925461721/en-US/graph_studio/certificate-replace.htm · retrieved 2026-08-23