How to generate or re-generate a certificate for Syracuse (Passphrase errors)
Description
Cause
  • The Syracuse Certification is missing, damaged, corrupted or incomplete.
  • This can also happen if you've changed the password for the "sagert" login or whichever login that's assigned to the Syracuse and X3 services. This password is encrypted and stored in various locations and should not be changed. If it is changed, X3 will run into unforeseen problems.
Resolution
[BCB:5:Third-party support:ECB]


A user is getting one or more of the following error messages when installing, patching, upgrading, updating, or launching X3; follow the resolution steps below. 

  Note:  This only applies for v7 and higher. 

 
     Error: "Passphrase for Syracuse server   has not been set. Please contact the administrator to set it." 
     Error: "Cannot read passphrase file" 
     Error: "Passphrase cannot be decrypted" 
     Error: "Cannot read passphrase file. Maybe it has been created under another operating system user: Error: Decryption error -2146893813" 
     Error: "Updating passphrase failed : Error # Passphrase updated failed ! ( )" 
     Error: "Passphrase has not been set" 
 

 How to generate or re-generate / regenerate a certificate for Syracuse?

Note: If "nothing" changed on the Syracuse server but between logging out and in again, users receives "Error: "Cannot read passphrase file. Maybe it has been created under another operating system user: Error: Decryption error -2146893813"", try rebooting the Syracuse server.

To generate a new certificate perform the following steps:

Login to Windows as the service account user and take note of the computer name

  1. Open a Windows command prompt (cmd.exe) using Run as administrator
  2. Type whoami

  1. Close the command prompt

Create a new certificate and private key

  1. Using Windows explorer, navigate to and click on certgen.bat located in a location like E:\Sage\Syracuse\syracuse\bin\cert_gen.
    Note: If there is an output and a private folder already in this location, delete these two folders.
    Note: Possible point of confusion: There is also a certgen.bat in the certs_tools folder. Either one will work, but you must make sure to use the same location in all steps and the associated output folder.
    Note: Recent versions of Syracuse have changed the install location main folder to SyracuseComponent. For example, C:\Sage\SyracuseComponent\syracuse\bin\cert_gen
  2. Fill out all necessary information for Country, State, City, Organization, Name, Days of validity (use 1000)
    Note: Recent versions of Syracuse may also prompt for an Optional email
  3. Enter a passphrase and confirm the passphrase
    Note: The cursor will not move with your typing

  1. Press ENTER

  1. Enter 1 and press ENTER
  2. Fill out the Name of server, press ENTER for the Server name for TCP Connections, press ENTER for the Enter days of validity, fill out the Enter passphrase for new private key, and the Confirm passphrase of private key, enter 8124 for Port of Syracuse server.
    Note: The cursor will not follow with your typing in the passphrase
    Note: Recent versions of Syracuse will also prompt for a passphrase of a private key of CA certificate

  1. Press ENTER
    Note: Ignore the error
  2. Press ENTER
  3. Type 10 and press ENTER

  1. Close the command prompt

Copy the generated files to the correct locations

  1. In Windows Explorer, go back to the location where you ran the certgen.bat.
  2. Open the output folder
  3. Copy 3 files (ca.cacrt, .crt (Security certificate), and the .key)

  1. Paste the three files into the ..\syracuse\certs\ folder.
    Note: You may need to create this folder

  1. Go back to your output folder and copy the .pem file

  1. Paste the .pem file into the keys folder of the runtime installation. For example, E:\Sage\SAGEX3V7\X3V7RUNTIME\runtime\keys.

  1. Close Windows explorer

Correct the passphrase by running the passphrase.cmd

  1. Open a Windows command prompt (cmd.exe) using Run as administrator

  1. In the Administrator: Command prompt navigate to the Syracuse sub folder, for example:
    1. Type cd e:\sage\syracuse\syracuse
    2. Type e:
    3. Type passphrase.cmd
      1. Note: There is a space after passphrase.cmd. Replace MYPASSPHRASE with your actual passphrase
    4. Press ENTER

  1. You will get a result:


Note: If you get an Error: "No data for local nanny", the Syracuse service is not started and you need to run (double-click) the init_host.cmd from Syracuse subfolder in the Syracuse installation directory before rerunning the passphrase.cmd

Result: You should now be able to launch Sage X3 and login successfully.

Steps to duplicate
Related Solutions

Error: "connect ECONNREFUSED"