07-14-2020 04:25 AM
Hi there,
can someone help me how to renew Cluster Certificate on cluster. and what will impact if it fails.
07-14-2020 06:23 AM
First off the Manual info is here to start.
Check out what your current certificate is using a wildcard or each ESA has its own cert common name.
Certificates are used in 4 locations for cluster mode. You need to take note of the 'Name' used in all of them.
1) Go to Network -> Listeners
2) Click on the name of your listener
3) Select the certificate in the "Certificate" drop down
4) Submit this page
5) Repeat steps 1-4 for any other listeners
6) Commit the changes
1) Go to Mail Policies -> Destination Controls -> Edit Global Settings
2) Select the certificate in the "Certificate" drop down
3) Submit this page
4) Commit the changes
1) Go to Network -> IP Interfaces
2) Click on the name of your IP Interface
3) Select the certificate in the "HTTPS Certificate" drop down
4) Submit this page
5) Repeat steps 1-4 for any other applicable interfaces
6) Commit the changes
1) Go to System Administration -> LDAP -> Edit Settings
2) Select the certificate in the "Certificate" drop down
3) Submit this page
4) Commit the changes
When you import the new one and commit it to the cluster, use a name other than the one above for initial staging. Make sure each machine has the same name being used.
1. You can then rename the names of the old with the new. Quick swap.
2. Or use the current new name of the cert, and go change the settings to use the new name cert (from the top of this reply).
When you think you have one complete utilize this site to check certificates: http://www.checktls.com/perl/TestReceiver.pl
-Hope this helps
07-14-2020 02:37 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide