Skip to main content

Backing up certificates

To be able to recover from a system crash, you should create a backup of the certificates on the central node of your Qlik Sense site.

  1. Open a command prompt, and launch the Microsoft Management Console (mmc) as the user that runs the Qlik Sense services.
  2. Select File>Add/Remove Snap-in.
  3. Double-click Certificates.
  4. The Add or Remove Snap-ins window. "Certificates" is selected.

  5. Select Computer account and click Next.
  6. The Certificates snap-in window. "Computer account" is selected.

  7. Select Local computer and click Finish.
  8. The Select Computer window. "Local computer" is selected.

  9. Double-click Certificates.
  10. The Add or Remove Snap-ins window. "Certificates" is selected.

  11. Select My user account and click Finish.
  12. The Certificates snap-in window. "My user account" is selected.

  13. Click OK.
  14. The Add or Remove Snap-ins window. "OK" is selected.

  15. Expand Certificates (Local Computer) in the left panel.
  16. The Console1 window. The Certificates (Local Computer) folder is expanded.

  17. Expand the Trusted Root Certification Authorities folder and select the Certificates folder.
  18. Right-click the certificate that is Certificate Authority (CA) for all nodes in the Qlik Sense site and select All Tasks>Export. The CA is named <computer_that_issued_the_certificate>-CA by default.
  19. The Console1 window. The Certificates (Local Computer > Trusted Root Certification Authorities > Certificates folder is expanded. A certificate has been right-clicked, and All Tasks > Export is selected.

  20. Click Next.
  21. The Certificate Export Wizard window. "Next" is selected.

  22. Select Yes, export the private key and click Next.
  23. The Export Private Key screen. "Yes, export the private key" is selected.

  24. Select Personal Information Exchange.
  25. Tick the Export all extended properties box and then click Next.
  26. The Export File Format screen. "Personal Information Exchange" is selected, and the "Export all extended properties" box is ticked.

  27. Enter and confirm a password. Then click Next.
  28. The password is needed when importing the certificate.

    The Password screen. A password has been entered in two places.

  29. Enter a file name for the .pfx file and click Next.
  30. Tip: It is recommended to include the server name in the file name to avoid confusion with other certificate files.

    The File to Export screen.

  31. Click Finish.
  32. The .pfx file that contains the CA for all nodes in the Qlik Sense site is stored in the selected location.

  33. Export certificates:
    1. Starting at step 11, repeat the procedure and export the server certificate (that is, the SSL certificate), which is located under Certificates (Local Computer)>Personal>Certificates. The server certificate a) has the same name as the Domain Name System (DNS) name of the machine, and b) is signed by the CA for all nodes in the site.

    2. Starting at step 11, repeat the procedure and export the client certificate (that is, the ID of the client), which is located under Certificates - Current User>Personal>Certificates. The client certificate is named QlikClient and is signed by the CA for all nodes in the site.

    3. Starting at step 11, repeat the procedure and export the QlikServiceCluster certificate, which is located under Certificates (Local Computer)>Personal>Certificates.

  34. Close the MMC console.
  35. No changes need to be saved.