You can configure the Orchestrator configuration server to use a different SSL certificate, for example if your company security policy requires you to use their SSL certificates.

Make sure that you have generated or installed an SSL certificate signed by a CA.


Log in to the appliance Linux console as root and navigate to the jetty.xml file.

The default location is:



In the jetty.xml file, find the following entry:

<Call name="addConnector"> 
    <New class=""> 
      <Set name="Port">8283</Set> 
      <Set name="maxIdleTime">30000</Set> 
      <Set name="handshakeTimeout">2000</Set> 
      <Set name="keystore"><SystemProperty name="jetty.home" default="." />/etc/jssecacerts</Set> 
      <Set name="password">dunesdunes</Set> 
      <Set name="keyPassword">dunesdunes</Set> 
      <Set name="truststore"><SystemProperty name="jetty.home" default="." />/etc/jssecacerts</Set> 
      <Set name="trustPassword">dunesdunes</Set>

Change the keystore, truststore, password, keyPassword and trustPassword values to refer to your <your_keystore_filename> file and password.


Save the jetty.xml file.


Restore the default vco user credentials by running the following command:

chown vco.vco /opt/vmo/configuration/jetty/etc/jetty.xml
chmod 600 /opt/vmo/configuration/jetty/etc/jetty.xml

The vco user must be the owner of the jetty.xml file. Otherwise you cannot start the Orchestrator configuration service.


Restart the Orchestrator configuration server.

You successfully changed the SSL certificate for the Orchestrator configuration interface.