cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
552
Views
0
Helpful
2
Replies

Upgrade to 20.15 broke web certificate

dijix1990
VIP Alumni
VIP Alumni

For my test environment I upgraded sdwan controllers from 20.12.3 to 20.15.1 for testing sd-routing, after upgrading I found that web certificate flew off. I tryied to regenerate CSR and found that it got errrors with SAN DNS (vmanage returns an error that you cannot use SAN like name sdwan-test or 192.168.100.100). Before I added SAN DNS like - "sdwan-test.lab.ru sdwan-test 192.168.100.100" now I can use only sdwan-test.lab.ru. So I regenerate CSR and tried to import new certificate and I got another error 

dijix1990_2-1725603273156.png

 

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

is this self-signed ? and signed by same root CA as before.

you have DNS entries for sdwan-test.lab.ru

If the root ca changed you need to get root ca added.

I used in Lab with latest and works for me.

https://www.cisco.com/c/en/us/support/docs/routers/sd-wan/215103-how-to-generate-self-signed-web-certific.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I use Enterprise CA

Root doesn't changed, of course I have dns and I signed it the same root CA and root CA exists on the vmanage. For 20.12.3 it worked and after updating my Web certificate replaced self-signed, and certificates certifying controllers remained the same - enterprise