SSL Certificate Update for - FAQs


Hi @cperellis We are using newrelic Java agent version - 3.31.0 for our APM, I ran the connection test using curl, Are we good?

curl -v
Connected to () port 443 (#0)

  • Initializing NSS with certpath: sql:/etc/pki/nssdb
  • CAfile: /etc/pki/tls/certs/ca-bundle.crt
    CApath: none
  • SSL connection using TLS_RSA_WITH_RC4_128_SHA
  • Server certificate:
  •   subject: CN=*,O="New Relic, Inc.",L=San Francisco,ST=California,C=US
  •   start date: Jan 19 00:00:00 2018 GMT
  •   expire date: Apr 16 12:00:00 2021 GMT
  •   common name: *
  •   issuer: CN=GeoTrust RSA CA 2018,,O=DigiCert Inc,C=US

GET / HTTP/1.1
User-Agent: curl/7.29.0
Accept: /

< HTTP/1.1 200 OK
< Connection: Keep-Alive
< Content-Length: 66
tls_version: TLSv1.2
cipher: RC4-SHA


Hi there - yes, there is no SSL error. Please see comments above related to Java agent and JVM certificate store for more information.


Thanks! @cperellis for the clarification.


Hi @cperellis. We have a number of Ruby agents with version < that cannot be readily updated due to outdated Ruby/Rails versions which are tangled in some legacy applications. That said, all of these machines already recognize Digicert via their system store. Is there some work around that you know of to get the agents to recognize the new certificate without having to update?

Thanks in advance.


Hi there @aaron.b - We think we may need to do some investigating with you so we’ve opened a ticket for you to work on directly with Cara and our team. Please be on the lookout for an email.

If we come up with anything that is useful to other Ruby users, we will share back here!


This update has been made.

If you are experiencing any issues check out the thread above for agent specific information.

We are encouraging conversation in this thread:

Please let us know what questions you have for us regarding this update in the thread linked above so we can keep this thread focused on FAQs.