Professional Documents
Culture Documents
Due to changes related to the way SSL certificates can be issued by publicly-trusted certificate
authorities a change may be required to your OPERA Environments. If you purchased an SSL certificate
from MICROS it is due to expire on or before October 31, 2015. OPERA relies on the SSL for secure
communication with the OPERA server and it is critical that your existing SSL certificate is replaced
before it expires.
Oracle has created an automated self-service installation app to streamline the implementation of a
new SSL certificate. The attached guide will walk you through the simple process of downloading the
app and step by step instructions to implement your new self-signed SSL certificate. There is no charge
for the app or the self-signed SSL certificate. An installation services fee will apply if you require Oracle
to implement your new SSL certificate for you. Please contact your Oracle Hospitality Sales Team for
further information.
Please read the F.A.Q below for more information and please feel free to contact your Oracle account
representative for more information.
---------------------------------------------------------------------------------------------------------------------------F.A.Q.
We use OPERA that is hosted in an Oracle data center, is there anything that we need to do here?
No. The events above only apply to OPERA servers located on-property or hosted in a non-Oracle data
center where the SSL certificate installed on the application server was purchased from MICROS.
What is an SSL certificate and why is it used with OPERA?
An SSL certificate is a special kind of encryption key that is loaded onto the server and enables
encryption of data transmitted in between your OPERA workstations and OPERA server. Many websites
use such a certificate and you can visually verify such a certificate is in use by reviewing the URL in
Internet Explorer. If you notice the URL begins with https://, then you can be sure an SSL certificate is in
place and the connection is secure. Later versions of Internet Explorer also include an image of a
padlock indicating security.
We did not purchase SSL certificates from MICROS, instead we provisioned our own from a Certificate
Authority. Do we still need to replace these certificates and use your automated utility program?
No. You can continue to use the certificates that you provision. As a reminder, you may want to
double-check the expiration of your certificates so that you renew/replace them in a timely manner.
Will the self-service app be installing the same Trustwave-issued certificates as before?
No. We will no longer be selling certificates from Trustwave or any other company. The self-service
installation app will install a self-signed certificate. This style of certificate is free of charge and it
requires installation on each OPERA workstation, which is not necessary with certificates that are
purchased from a certificate authority such as Trustwave.
The self-signed certificates sound like a great idea, is there anything different that needs to be done in
order to use OPERA?
There is no change in how OPERA is used after the installation process is complete. The attached guide
will walk you through the simple process of downloading and using the self-service installation app to
implement your new self-signed SSL certificate. Should a workstation be missed during installation
process it will still be possible to use OPERA from that workstation, however a warning message will be
displayed indicating that the certificate is not trusted. When this happens a user on the workstation will
simply need to run the self-service installation app as the workstation Administrator to install the
certificate as trusted. This procedure is also covered in the attached guide.
What OPERA servers in my environment are affected?
The self-service installation app should be run on each Application Server in your environment. If you
have just one server (e.g., a Single Server) please consider this to be the Application Server.
If I have an SSL certificate for my incoming OXI connection from a third-party system, should the SSL
Certificate be updated there?
For reasons of enhancing security for public-facing servers this solution is NOT recommended on
machines serving as the incoming point of connection for third-party systems connecting in from a
public network such as the internet. In these cases a separate solution will be recommended and details
regarding that will be sent under separate cover to those who are licensed for an affected interface.
If you have one of the following OXI interfaces, please reach out to your sales executive to schedule a
custom arrangement for your OXI machine:
Active PMS, Advantage Reserve, Book4Time, Cendyn, Click Squared, CompuREZ, Concept, Concierge
Assistant, Cvent, Daylight Sales & Catering, Delphi Sales & Catering, Digital Alchemy on Demand (Data 2
Gold), DigiValet, Duetto Profit Engine, FCS, FCS (PIAA), Force 10 Software LLC, Genares, Go Concierge,
GroupRevMax, Guestware, Hotel Booking Solutions, Hotel SalesPro, HotelCloud, HotSOS / REX (MTECH), IDISO, InnPoints, IntelliSpa, Interactive Sites, Katana, Libra OnDemand (HRM / DELPHI.FDC),
Make-Reservations.com, ManageMySpa, Metro, Mobius, Nanonation, NAVIS, Open Hospitality
OpenView IBE, Pegasus Generic XML, RainMaker, Resort Suite, ResPAK, Returnity, Revinate, Ryan
Solutions, SpaBooker, SpaSoft, SynXis, TAC, Target Net, TimeShareWare, Topaz, Travel Tripper,
TravelClick, TripCraft, Triton, UPS
Will this change mitigate the POODLE vulnerability on my OPERA Application Server?
No. The change to use self-signed certificates does not enhance the overall security-level of your OPERA
environment. This only replaces the certificate due to expire at the end of October with one that will
allow your system to continue operating. To address environmental security please speak to your sales
executive about moving into an Oracle cloud environment or reviewing upgrade options to a higher
version of OPERA.
What is the cost to replace the SSL Certificate?
Provided that you download and use the automated self-service app, there is no cost. If you choose to
have Oracle Hospitality perform the installation, please contact your sales executive to make
arrangements.
Click on I Agree after reading the terms of registering for the site.
_0,&526&205(*,65$7,21,16758&7,216
Please fill out the form with all of your information, please be sure to choose Access, SSL as your Primary contact at
MICROS.
3 | 0,&526&205(*,65$7,21,16758&7,216
You will also get a confirmation email which looks like this:
Please click the link within the email to confirm your email address.
4 | 0,&526&205(*,65$7,21,16758&7,216
When you first login, you will need to agree to the Terms of Use of the site:
If you have any issues with this process, please send an email to sslaccess_ww@oracle.com.
5 | 0,&526&205(*,65$7,21,16758&7,216
Use the links for Documentation and Installation Media (.exe) to assist in implementing the OPERA Self-Signed SSL solution.
Direct Links
Documentation http://downloads.micros.com/fidelio/OPERA/OHE/downloads/V5.0/Oracle_Opera_Self_Signed_SSL_Implementation.pdf
Installation Media (.exe) http://downloads.micros.com/fidelio/OPERA/OHE/downloads/V5.0/OPERA_Self_Signed_SSL_Installation.zip
If you have any issues with this process, please send an email to sslaccess_ww@oracle.com.
6 | 0,&526&205(*,65$7,21,16758&7,216
Worldwide Inquiries
Phone: +1.650.506.7000
Fax: +1.650.506.7200
&211(&7: ,7+86
EORJVRUDFOHFRPRUDFOH
IDFHERRNFRPRUDFOH
WZLWWHUFRPRUDFOH
Copyright 2015, Oracle and/or its affiliates. All rights reserved. This document is provided for information purposes only,
and the contents hereof are subject to change without notice. This document is not warranted to be error-free, nor subject to
any other warranties or conditions, whether expressed orally or implied in law, including implied warranties and conditions
of merchantability or fitness for a particular purpose. We specifically disclaim any liability with respect to this document, and
no contractual obligations are formed either directly or indirectly by this document. This document may not be reproduced
or transmitted in any form or by any means, electronic or mechanical, for any purpose, without our prior written permission.
RUDFOHFRP
Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective
owners.