#DC1 listener: { "keyStoreAlias":"REPLICATION_KEYSTORE", "keyAlias":"replicationalias", "trustStoreAlias":"REPLICATION_TRUSTSTORE", "listener": { "nodeName": "662908ae-855a-41d8-84d9-a4e47380198b", "host": "sync-api-mgt-dc1.dc1.ocp.somedns", "port": 4440 }, "insecureTrustManager": true } #DC1 ring: { "ring": [ { "nodeName": "ad193d47-3c51-4059-8e54-060062bcec84", "host": "sync-api-mgt-dc2.dc2.ocp.somedns", "port": 443 } ] } #DC2 listener: { "keyStoreAlias":"REPLICATION_KEYSTORE", "keyAlias":"replicationalias", "trustStoreAlias":"REPLICATION_TRUSTSTORE", "listener": { "nodeName": "ad193d47-3c51-4059-8e54-060062bcec84", "host": "sync-api-mgt-dc2.dc2.ocp.somedns", "port": 4440 }, "insecureTrustManager": true } #DC2 ring: { "ring": [ { "nodeName": "662908ae-855a-41d8-84d9-a4e47380198b", "host": "sync-api-mgt-dc1.dc1.ocp.somedns", "port": 443 } ] } ====================================================== Keystore/Truststore via custom CA creation ====================================================== #DC1 keytool -genkey -alias replicationalias -keyalg RSA -keystore dc1-replication.jks -keysize 2048 openssl req -new -x509 -keyout ca-key -out ca-cert keytool -keystore dc1-replication.jks -alias replicationalias -certreq -file cert-file openssl x509 -req -CA ca-cert -CAkey ca-key -in cert-file -out cert-signed -days 3650 -CAcreateserial -passin pass:somepass keytool -keystore dc1-replication.jks -alias CARoot -import -file ca-cert keytool -keystore dc1-replication.jks -alias replicationalias -import -file cert-signed #DC2 keytool -genkey -alias replicationalias -keyalg RSA -keystore dc2-replication.jks -keysize 2048 keytool -keystore dc2-replication.jks -alias replicationalias -certreq -file cert-file openssl x509 -req -CA ca-cert -CAkey ca-key -in cert-file -out cert-signed -days 3650 -CAcreateserial -passin pass:somepass keytool -keystore dc2-replication.jks -alias CARoot -import -file ca-cert keytool -keystore dc2-replication.jks -alias replicationalias -import -file cert-signed #Truststore for both keytool -keystore truststore.jks -alias replicationalias -import -file ca-cert