cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
274
Views
0
Helpful
3
Replies
Highlighted
Beginner

Node certificate invalid - all switches inactive

Hi community,

 

I have at least one major issue, perhaps even two.

We have a small demo-lab, one APIC, two leaf switches, one spine. A critical fault (F3031) is raised with a description of "Node Certificate is invalid: Failed to parse the subject line as a valid ACI fabric certificate AND Invalid Serial Number AND Invalid Product ID". The fault is raised for the APIC.

For a time everything went fine, though. We had this fault but nothing really happened. Now I reset the fabric to factory defaults and started building it up from scratch. All nodes are discovered successfully, however they turn to an "inactive" state right after discovery. I have seen this happen in other environments for a short period, maybe up to a couple of minutes but in this case it's been hours now, since the devices have been discovered. I have a hunch this issue might be related to the invalid certificate.

Am I on the right track or are those problems not related? What can I do to get back a valid certificate?

 

Thank you and kind regards,

Nik

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Cisco Employee

Re: Node certificate invalid - all switches inactive

In 4.2 we introduced a new cli command "show discoveryissues" which can be run on leaf cli.

the cli basically runs a script in backend and perform multiple checks, certificate check is one of them.

 

If invalid certificate is the issue, please open a tac case.

 

 

 

View solution in original post

3 REPLIES 3
Highlighted
Cisco Employee

Re: Node certificate invalid - all switches inactive

In 4.2 we introduced a new cli command "show discoveryissues" which can be run on leaf cli.

the cli basically runs a script in backend and perform multiple checks, certificate check is one of them.

 

If invalid certificate is the issue, please open a tac case.

 

 

 

View solution in original post

Highlighted
Beginner

Re: Node certificate invalid - all switches inactive

Thank you Gaurav,

unfortunately the switches are still running 3.2(7f) so the command is not available.

I think I'll go with the TAC case. I'll update the discussion when we have a solution.

Highlighted
Beginner

Re: Node certificate invalid - all switches inactive

Thank you again for the input!
It took a while but it turned out the certificate did indeed have to be replaced. For some unknown reason the subject-line got corrupted and presented the values in a wrong order. I hope this is some very rare scenario but if someone is facing this issue there is no way around it without TAC and root access. 

CreatePlease to create content
Content for Community-Ad

Cisco COVID-19 Survey