How to Create and Install an SSL Digital Certificate

There are several ways to create a Digital Certificate for SSL communications.

  • Use the LoadRunner Certificate Manager. If you used the Certificate Manager to create a CA certificate, you can generate the corresponding SSL certificate from the Certificate Manager as well.
  • Use the gen_cert Utility. If you use the gen_ca_cert utility to create a new CA certificate, you may want to follow that by using the gen_cert utility to create the SSL certificate.
  • Automatically Generate the Certificate on the Controller. You use the Authentication Settings dialog box to associate a certificate with a scenario in the Controller. While setting this, you can instruct the dialog box to automatically generate an SSL digital certificate for you.
  • Use the Network and Security Manager Command Line. If you are using the Network and Security Manager command line options to automate your certificate setup process, there is also a command for creating a new digital certificate.

After you choose the method you want to use to create the digital certificate, follow the relevant instructions below.

Use the LoadRunner Certificate Manager

  1. Run the Certificate Manager from <LoadRunner installation folder>\bin\LRcertificateMngr.exe.

    If you have not previously created certificates with this application, it displays the default LoadRunner certificates.

  2. In the Certificate Manager, click Change.

  3. If you already have a CA certificate, select it. Otherwise, click New to create a new CA certificate. After creating it, select it in the list.

  4. Click Next, and then click New to create a new SSL certificate. When finished, select the newly created SSL certificate.

  5. Click Next and then Finish.

    This installs the SSL certificate and corresponding CA certificate on the current LoadRunner machine.

  6. To install this SSL certificate on other LoadRunner computers, click Export to save the generated certificate. Then install it on other LoadRunner computers using the gen_ca command with the -install option as described at the end of the procedure below.
Back to top

Use the gen_cert Utility

Note: If working on Windows, use the gen_cert.exe utility. If you are working on a Linux platform, use the gen_cert utility.

Authentication Settings Dialog Box

To create a digital certificate using the gen_cert utility, perform the following steps:

  1. Run the gen_cert utility from the <LoadRunner root folder>\bin folder.

  2. Run the gen_cert command with at least one of the following options:

    • -country_name

    • -organization_name

    • -organization_unit_name

    • -eMail

    • -common_name

    • It is important to note the following:

    • The CA Certificate and the CA Private Key files are necessary for the creation of the certificate. By default, it is assumed that they are in the current folder, and are named cacert.cer and capvk.cer respectively. In any other case, use the -CA_cert_file_name and -CA_pk_file_name options to give the correct files and locations.

    • The certificate file is created in the folder from which the utility was run. By default, the file name is cert.cer. To provide a different name, use the -cert_file_name option.

    • You can also run the gen_cert utility with the -install option to install the certificate that you create.
Back to top

Automatically Generate the Certificate on the Controller

Select the Generate a certificate automatically option in the Authentication Settings Dialog Box

Back to top

Use the Network and Security Manager Command Line

Use the -generate_new_cert option command to create a digital certificate. For details, see Network and Security Manager - Command Line Tool.

Back to top