07-29-2011 08:10 AM
Hello
I've updated our internal application SSL certificates on our core WAEs group, for some reason it didn't push the updated ones down to the branch WAEs. The users are getting the expired cert error. The work around for now was to disable the SSL cert. Is there a procedure on how to update the SSL certs on your core WAEs? How can I check the branch WAE where the expired cert if being stored, it's not showing up when you issue a show
crypto certificates. I went and updated the existing ones with the new ones and the date had changed correctly.
WAEs - 4.2.1
CM - 4.4.1
Solved! Go to Solution.
08-03-2011 12:41 PM
Hi John,
I believe Ahmad is talking about this link, here is the corrected one:
As per the document, the certificates should be propogated to WAE and replace the expired one. Why it did not happen in your case, I believe requires some investigation. It may be that the CM-WAE connectivity is/was broken or may be the WAE is managed by CM but is configured in such a way that CM can not update config on WAE. This could happen if you are using Device Groups and if WAE is not part of that group.
Hope this helps.
Regards.
PS: If this answers your question, please mark this as Answered.
07-29-2011 08:23 AM
I would recommend you to go through the following document which should help you in troubleshooting the SSL AO:
Please let me know if you still need any help,
Ahmad
07-29-2011 08:36 AM
Yes, I had the SSL cert working before, it broke when I went and updated it. Why didn't it push it down to the WAE branches? Why is the branch WAE still storing the old certificate????
The links you posted, I can't open. Please confirm them.
08-03-2011 12:41 PM
Hi John,
I believe Ahmad is talking about this link, here is the corrected one:
As per the document, the certificates should be propogated to WAE and replace the expired one. Why it did not happen in your case, I believe requires some investigation. It may be that the CM-WAE connectivity is/was broken or may be the WAE is managed by CM but is configured in such a way that CM can not update config on WAE. This could happen if you are using Device Groups and if WAE is not part of that group.
Hope this helps.
Regards.
PS: If this answers your question, please mark this as Answered.
08-03-2011 12:53 PM
This was from the url you posted above. I was missing this important step!
"If you change the certificate or key for an existing SSL accelerated service, you must uncheck the
In service check box and click Submit to disable the service, then wait 5 minutes and check the
In service check box and click Submit to reenable the service. Alternatively, at the WAE, you can use the
no inservice SSL accelerated service configuration command, wait a few seconds, and then use the
inservice command. If you are changing the certificate or key for multiple SSL accelerated services, you can restart all accelerated services by disabling and then reenabling the SSL accelerator."
08-03-2011 02:09 PM
Thanks for the update, John. Good to know it is working now.
Regards.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide