Introduction
This article explains how to install third-party digital certificates on your BPA Platform server.
What is a Digital Certificate?
A digital certificate is an electronic document containing a cryptographic key to validate the identity of a network device. When communicating with external systems, BPA Platform uses these certificates to authenticate itself and to ensure the correct encryption key is used when communicating. Without the certificate, the connection cannot be made as the trust is not established.
What Tools Require Certificates?
At the time of writing, the following tools require certificates from external systems to be installed on the BPA Platform server:
| ► | File Management |
| ► | Microsoft Exchange Connector — For the Exchange server you are connecting to |
| ► | Web Service Connector — For the web service you are connecting to |
Installing the Digital Certificate
The following procedure creates a store for those certificate required specifically for BPA Platform. If you have already created a dedicated certificate store for BPA Platform, follow the procedure under How to Register Third-Party Certificates with BPA Platform instead.
Note: This procedure assumes you have the digital certificate from your external system. If not, consult your System Administrator. It also uses Windows Server 2019 menu names and options — adjust as necessary for the operating system you are using.
To install the digital certificate, do the following:
- Copy the digital certificate to the machine hosting the BPA Platform server.
- From the same machine, launch the Microsoft Management Console — click the Windows Start key and type mmc <enter>.
- Go to File > Add / Remove Snap-in.

- From the Available snap-ins pane, highlight Certificates and click Add.
- Select Service Account and click Next.
- Ensure Local computer is enabled then click Next.

- From the list of service accounts, select BPA Platform Server.
- Click Finish.
- You are returned to the Add or Remove Snap-ins window. Click OK to close.
- A Certificates - Service (BPA Platform Server) on Local Computer node now appears under Console Root. Expand Certificates > TCServer\Trusted Root Certification Authorities > Certificates.
- Right-click Certificates and select All Tasks > Import.
- Because we already specified that certificates in this store are for the local computer already, all options are pre-set and cannot be changed. Click Next.
- Click Browse and locate and open the digital certificate.
- Click Next.
- Ensure Place all certificates in the following store is enabled and the Certificate store is TCServer\Trusted Root Certification Authorities.
- Click Next.
- Confirm the details and click Finish.
- Click OK when the import was successful.
- Click File > Save.
- Enter a meaningful name for your console file. Save it to the default location.
The certificate is now ready to be used by BPA Platform.
Adding Certificates to the BPA Platform Store
If there are additional certificates required by BPA Platform, you add them to the same TCServer certificate store. You do this as follows:
- Launch the Microsoft Management Console.
- Open the console file you saved previously (click File > Open).
- Follow steps 10 to 19 (above) to import the new certificate.
Why Can't I Just Install the Certificate into the Default Store?
This procedure assigns the certificates for the sole use of the BPA Platform Server service. This is the recommended procedure to use to ensure the communication is kept between BPA Platform and the external system, rather than any other application that runs on the same machine.