Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 500-430 Exam - Topic 10 Question 19 Discussion

Instead of using the Enterprise Console Ul, how can an administrator import an existing keypair to manage the Controller SSL certificate?
A) Add the keypair to the keystore.jks using a third-party tool.
B) Re-run the Controller installer and specify the new keypair.
C) Upload a new keystore.jks file through the Controller Ul.
D) Upload the keypair from within the Controller UL.

Cisco 500-430 Exam - Topic 10 Question 19 Discussion

Actual exam question for Cisco's 500-430 exam
Question #: 19
Topic #: 10
[All 500-430 Questions]

Instead of using the Enterprise Console Ul, how can an administrator import an existing keypair to manage the Controller SSL certificate?

Show Suggested Answer Hide Answer
Suggested Answer: A

According to the Cisco AppDynamics Professional Implementer (CAPI) documents, the method to import an existing keypair to manage the Controller SSL certificate without using the Enterprise Console UI is to add the keypair to the keystore.jks using a third-party tool (A). The keystore.jks file is the default keystore for the Controller that contains the private keys and certificates for the secure communication on port 8181. If the administrator already has a custom keypair that is signed by a third-party Certificate Authority (CA) or an internal CA, they can use a third-party tool, such as KeyStore Explorer or OpenSSL, to import the keypair into the keystore.jks file. The administrator should also import the root or intermediate certificates of the CA into the cacerts.jks file, which is the default truststore for the Controller. The administrator should use the keytool utility, which is bundled with the Controller installation, to import the certificates into the cacerts.jks file.The administrator should also update the password for the keystore.jks and cacerts.jks files, and restart the Controller to apply the changes12.

The incorrect options are:

Re-run the Controller installer and specify the new keypair. (B) This is not a valid method because the Controller installer does not allow the administrator to specify a custom keypair for the Controller SSL certificate. The Controller installer only allows the administrator to specify the Controller host name, port, account name, access key, and database settings.The Controller installer does not modify the keystore.jks or cacerts.jks files, and does not import any custom keypair or certificate into the Controller keystore or truststore3.

Upload a new keystore.jks file through the Controller UI. This is not a valid method because the Controller UI does not provide any feature to upload a new keystore.jks file for the Controller SSL certificate. The Controller UI only allows the administrator to view and edit the Controller settings, such as the license, the security, the email, the analytics, and the EUM.The Controller UI does not access or modify the keystore.jks or cacerts.jks files, and does not import any custom keypair or certificate into the Controller keystore or truststore4.

Upload the keypair from within the Controller UI. (D) This is not a valid method because the Controller UI does not provide any feature to upload a custom keypair for the Controller SSL certificate. The Controller UI only allows the administrator to view and edit the Controller settings, such as the license, the security, the email, the analytics, and the EUM.The Controller UI does not access or modify the keystore.jks or cacerts.jks files, and does not import any custom keypair or certificate into the Controller keystore or truststore4.


1: Controller SSL and Certificates - AppDynamics

2: How do I resolve SSL certificate validation errors in the .NET Agent? - AppDynamics

3: Install the Controller - AppDynamics

4: Controller Settings - AppDynamics

Contribute your Thoughts:

0/2000 characters
Maurine
9 months ago
I agree, using a third-party tool is the way to go!
upvoted 0 times
...
Cassie
9 months ago
Wait, can you really do that from the Controller UI? Sounds off.
upvoted 0 times
...
Nathan
10 months ago
Uploading a new keystore.jks seems like the easiest route!
upvoted 0 times
...
Herminia
10 months ago
I think re-running the installer is a better option.
upvoted 0 times
...
Peter
10 months ago
You can definitely add the keypair to keystore.jks with a tool.
upvoted 0 times
...
Jeannetta
10 months ago
I vaguely recall that you can upload keypairs directly, but I can't remember if it was specifically through the Controller UI or another method.
upvoted 0 times
...
Melissia
11 months ago
I’m leaning towards option C, but I’m not completely confident. I remember discussing how to upload files through the UI in class.
upvoted 0 times
...
Daryl
11 months ago
I feel like we practiced a similar question where we had to re-run an installer to update configurations. Could that be the answer?
upvoted 0 times
...
Pa
11 months ago
I think I remember something about using a third-party tool for keystore management, but I'm not entirely sure if that's the right approach here.
upvoted 0 times
...
Devorah
11 months ago
I'm leaning towards A. Adding the keypair to the keystore.jks using a third-party tool seems like it would give me more control and flexibility over the process.
upvoted 0 times
...
Eura
11 months ago
Option D sounds like the easiest approach to me. Uploading the keypair directly through the Controller UI seems like the most intuitive way to handle this.
upvoted 0 times
...
Terrilyn
11 months ago
Hmm, I'm not sure about this one. I'm debating between A and D, but I'm a bit confused on the difference between adding the keypair to the keystore.jks and uploading the keypair directly through the UI.
upvoted 0 times
...
Lorrie
11 months ago
I think the answer is B. Re-running the installer and specifying the new keypair seems like the most straightforward way to import an existing keypair.
upvoted 0 times
...
Lili
11 months ago
Hmm, I'm a bit unsure about this one. The question is asking about specific characteristics for field technicians, so I'll need to think carefully about which of these options are most relevant.
upvoted 0 times
...
Nickolas
11 months ago
This looks like a pretty straightforward approval setup question. I think I can tackle this by breaking it down step-by-step.
upvoted 0 times
...
Brynn
2 years ago
Wow, they really make it hard to manage the SSL certificate, don't they? Option A is the way to go, but they should just let you upload the keypair directly.
upvoted 0 times
Harris
2 years ago
Yeah, it's a bit of a hassle. Option A seems like the best solution though.
upvoted 0 times
...
Barrie
2 years ago
I agree, it should be easier to manage the SSL certificate.
upvoted 0 times
...
...
Mabel
2 years ago
D looks interesting, but I'm not sure if the Controller UI has that functionality. I'd stick with the keystore.jks approach in A.
upvoted 0 times
Shawnta
2 years ago
C) Upload a new keystore.jks file through the Controller UI.
upvoted 0 times
...
Sarah
2 years ago
B) Re-run the Controller installer and specify the new keypair.
upvoted 0 times
...
Shasta
2 years ago
A) Add the keypair to the keystore.jks using a third-party tool.
upvoted 0 times
...
...
Dawne
2 years ago
I think option C is the most straightforward, just upload a new keystore.jks file through the Controller UI.
upvoted 0 times
...
Timothy
2 years ago
But wouldn't it be easier to just re-run the Controller installer like option B suggests?
upvoted 0 times
...
Gertude
2 years ago
I disagree, I believe the correct answer is D) Upload the keypair from within the Controller UL.
upvoted 0 times
...
Timothy
2 years ago
I think the answer is A) Add the keypair to the keystore.jks using a third-party tool.
upvoted 0 times
...
Rikki
2 years ago
I'm not sure about re-running the installer just to update the keypair. That seems overly complicated. I'd go with option A or C.
upvoted 0 times
Paulina
2 years ago
Uploading a new keystore.jks file through the Controller UI sounds like a simple solution.
upvoted 0 times
...
Paulina
2 years ago
I think adding the keypair to the keystore.jks using a third-party tool is the way to go.
upvoted 0 times
...
Paulina
2 years ago
I agree, re-running the installer seems like a hassle. Option A or C would be easier.
upvoted 0 times
...
Ula
2 years ago
I would go with option C as well. It seems like the most straightforward option.
upvoted 0 times
...
Delsie
2 years ago
Adding the keypair to the keystore.jks using a third-party tool could also work well.
upvoted 0 times
...
Krystal
2 years ago
Yeah, I would go with either option A or C. Both seem like easier solutions than re-running the installer.
upvoted 0 times
...
Alica
2 years ago
I think uploading a new keystore.jks file through the Controller UI would be the simplest solution.
upvoted 0 times
...
Noemi
2 years ago
I think option C is also a good choice. Uploading a new keystore.jks file through the Controller UI should be straightforward.
upvoted 0 times
...
Corrina
2 years ago
I agree, re-running the installer seems like too much work. Option A sounds easier.
upvoted 0 times
...
Oneida
2 years ago
I agree, re-running the installer seems like too much work. Option A sounds simpler.
upvoted 0 times
...
...
Shenika
2 years ago
Option A looks like the way to go. Importing the keypair directly into the keystore.jks sounds like the most straightforward approach.
upvoted 0 times
Valentine
2 years ago
It definitely sounds like the most straightforward approach.
upvoted 0 times
...
Josue
2 years ago
Yeah, adding the keypair to the keystore.jks seems like the easiest way to go.
upvoted 0 times
...
Jospeh
2 years ago
I agree, using a third-party tool for that task is efficient.
upvoted 0 times
...
Gwen
2 years ago
Yeah, adding the keypair to the keystore.jks seems like the easiest way.
upvoted 0 times
...
Myra
2 years ago
I think option A is the best choice.
upvoted 0 times
...
Madonna
2 years ago
I think option A is the best choice.
upvoted 0 times
...
...

Save Cancel