GroundRunners enable chain commands to interact with on-premises systems or remote data sources not otherwise accessible over the internet.
To use a custom certificate, an IT professional or someone who is familiar with your organization's network settings must import the certificate to your system's certificate store. Instructions for this are below.
Requirements
- An IT professional is recommended when using a custom certificate. Workiva Support will not be able to assist with this installation.
- A supported operating system is required.
A Java Runtime Environment (JRE) is not installed with the GroundRunner during the initial GroundRunner installation. After setup is completed and the GroundRunner is running, it will automatically download a JRE as needed to run commands that depend on Java. No installation or admin intervention is required, and the retrieved JRE will not affect existing JRE installations if they exist on the host. See the Workiva Support article Install and manage GroundRunners for more information on GroundRunner requirements.
Import the custom certificate
When using a self-signed certificate or one not issued by a Certificate Authority, your GroundRunners must use your system's certificate store.
To import a certificate:
- Contact your IT admin to obtain a copy of the certificate used to secure your site, or export it from your browser.
- Import the certificate into the system's certificate keystore. Valid locations are listed below.
Valid locations
Earlier GroundRunner versions accepted custom certificates listed in the cacerts file in the JRE/JDK installation directory. Current GroundRunner versions (9.21.1 and later) require custom certificates to be stored in one of the following locations:
Valid locations
Windows-ROOTWindows-ROOT-LOCALMACHINEWindows-ROOT-CURRENTUSERWindows-MYWindows-MY-CURRENTUSERWindows-MY-LOCALMACHINE
Troubleshooting
The GroundRunner won't start if any of the paths provided in your config file:
- Do not exist.
- Are missing a
binsubdirectory.