Certificates for the WebOffice SOE

The WebOffice Server Object Extension (SOE) of the VertiGIS WebOffice Output Service (SynOutputService) runs inside ArcGIS Server. To query the ArcGIS Server administrator directory and to validate geodata uploads (tool Upload Data), the SOE calls the administrator endpoint of its own ArcGIS Server. This connection is made by ArcGIS Server itself – the certificate is therefore checked against the Java truststore of ArcGIS Server, not against the WebOffice truststore.

 

Who connects to whom?

•WebOffice application server → ArcGIS Server (SOE service): checked against the WebOffice truststore. Problems here are logged as CERTIFICATE ERROR [WebOffice application server] and are resolved with the TLS certificate tool in SynAdmin.

•WebOffice SOE inside ArcGIS Server → administrator endpoint of its own ArcGIS Server: checked against the Java truststore of ArcGIS Server. Problems here are logged as CERTIFICATE ERROR [WebOffice SOE on ArcGIS Server] and are the subject of this chapter.

Which certificate ArcGIS Server is presented with depends on the administrator URL used:

•Through the ArcGIS Web Adaptor (e.g. https://server.company.com/arcgis): the certificate of the web server hosting the Web Adaptor (e.g. IIS).

•Directly on ArcGIS Server (e.g. https://server.company.com:6443/arcgis): the certificate of ArcGIS Server itself.

If an internal server URL is configured for the ArcGIS Publisher, the SOE uses it.

 

Recognizing it in the log

A typical message in the WebOffice Logging looks like this:

CERTIFICATE ERROR [WebOffice SOE on ArcGIS Server] :: The WebOffice SOE (service 'https://server.company.com/arcgis/SynOutputService/MapServer') cannot connect to the administrator endpoint of its own ArcGIS Server 'https://server.company.com/arcgis' :: ArcGIS Server does not trust the certificate presented at this endpoint ...

 

•The message names the SOE service, the administrator endpoint called, the cause and which function is unavailable until the problem is resolved.

•It is logged as a warning only once per endpoint and cause after each WebOffice start, further occurrences only at DEBUG level.

•The certificate check in SynAdmin usually shows no error for the same URL, because it checks the WebOffice truststore, not the one of ArcGIS Server.

 

Importing the certificate into the Java truststore of ArcGIS Server

1.Determine the certificate: the one presented at the URL named in the message, preferably the issuing (root or intermediate) CA certificate. Export it e.g. from the browser as a .cer file (Base64).

2.On every machine of the ArcGIS Server site, import the certificate into the truststore of the ArcGIS Server Java using its keytool (the path of the Java runtime depends on the ArcGIS Server version, see below; the default truststore password is changeit unless it was changed).

3.Restart ArcGIS Server so that the changed truststore is loaded.

4.Restart WebOffice (or re-initialize the project) and check the log: the message must no longer appear.

The Java runtimes of ArcGIS Server are located in the ArcGIS Server installation directory (e.g. C:\Program Files\ArcGIS\Server or D:\ArcGIS\Server) under framework\runtime. Depending on the version, one or more jre folders exist there:

•ArcGIS Server 10.9.1: jre

•ArcGIS Server 11.4 / 11.5: jre and jre17

•ArcGIS Server 12.0 / 12.1: jre17 and jre21 (from 12.0 on, the folder name always contains the Java version)

Import the certificate into all existing jre folders, each with the keytool of the respective Java runtime. The truststore is located in lib\security\cacerts, the keytool in bin\keytool.exe. Example for ArcGIS Server 10.9.1 in the default installation (adjust the installation directory and jre folder to your environment):

"C:\Program Files\ArcGIS\Server\framework\runtime\jre\bin\keytool.exe" -importcert -alias company-ca -file C:\temp\company-ca.cer -keystore "C:\Program Files\ArcGIS\Server\framework\runtime\jre\lib\security\cacerts" -storepass changeit

icon_comment

An ArcGIS Server update may replace the Java truststore. After an update, check whether the certificate is still present and import it again if necessary.

 

Expired certificate

If the log reports an expired certificate, importing does not help. The certificate must be renewed where it is installed: on ArcGIS Server or on the web server hosting the ArcGIS Web Adaptor.

 

icon_cross-reference

•Certificates of the WebOffice application server: Import of SSL/TLS Certificates and Import SSL Certificates in SynAdmin.

•Other causes of problems with the Upload Data tool: Upload Data.