01-23-2022 08:49 AM
failed registration between SSM-on prem and expressway with reason:
Failure reason: SSL: no alternative certificate subject name matches target host name 'CCSSMS.bfegy.com'
I have assigned a cert for SSM and uploaded it to EXP's trust CA.
but it shows that the certificate is "Not a CA" as below, I don't know if it is a problem or not.
I have opened the firewall ports HTTPS 443 between both.
the Expressway for smart licensing configuration is as below:
01-23-2022 11:43 PM - edited 01-23-2022 11:45 PM
As the error message already declares:
You only should upload CA certificate, that signed the cert of the SSM and not the cert of the server itself.
01-24-2022 03:19 AM
Have you tired with IP address ?
Sign the SSM certificate with an CA and upload the CA root to the Expressway C.
01-24-2022 03:35 AM - edited 01-24-2022 04:31 AM
I have already uploaded the root CA that signed the SSM cert to the expressway trust store.
i have tried with :
https://<<fqdn>>/Transportgateway/services/DeviceRequestHandler
https://<<fqdn>>/SmartTransport
https://<<iIP add>>Transportgateway/services/DeviceRequestHandler
https://<<IP add>>/SmartTransport
but the only works is:https://<<fqdn>>/SmartTransport and the others give invalid URL as the below :
01-24-2022 03:47 AM
It should be the following format: https://<<fqdn>>/SmartTransport. So it should be fine.
IP-address wouldn't work, since it isn't in the cert normally and therefore would give a cert error.
Have you delete the CSSM cert from the trust store?
Have you tried a reboot?
01-24-2022 04:01 AM
yes, i have done that, delete the cert of SSM from expressway trust store and leave only the ROOT
restart and try,, reboot and try ...and no hope
01-24-2022 04:05 AM
it still detects error as below:
Smart Licensing is ENABLED
Registration:
Status: REGISTERING - REGISTRATION IN PROGRESS
Export-Controlled Functionality: NOT ALLOWED
Initial Registration: FAILED on Jan 24 2022 13:54:05 EET
Failure reason: SSL: no alternative certificate subject name matches target host name 'CCSSMS.bfegy.com'
Next Registration Attempt: Jan 24 2022 14:13:28 EET
Although I have double-checked the cert and alternative certificate subject name:
01-24-2022 08:59 AM - edited 10-15-2022 11:01 PM
https://<<fqdn>>/SmartTransport is the correct url. Just to check the behavior of expressway, i requested to try with IP,
What version of expressway and SSM you use ? looks like you might need a TAC support.
08-24-2022 12:02 AM
Hello Abdelrahman,
How this issue was resolved cause i am having the same behavior.
Thank you
10-15-2022 11:00 PM
if you are using https://fqdn then make sure your certificate has the FQDN. if not try with https://IPaddress.
Also make sure you have ports opened
Register product instances to the SSM On-Prem. See Registering Product Instances to the On-Prem
in the Cisco SSM On-Prem User Guide and the documentation for your product.
• Cisco Products use the following API endpoints:
o HTTPS(443): tools.cisco.com. (Registration/Authorization)
o HTTP(80): www.cisco.com
• Smart Software Manager On-Prem uses the following API endpoints:
o User Interface: HTTPS (8443) Only
o Products: HTTP (80)/HTTPS(443)
o CSSM: HTTPS (443)
▪ Syncs:
api.cisco.com. (6.2 and prior)
swapi.cisco.com (6.3 and later)
▪ Account Registration: cloudsso.cisco.com
o cloudsso.cisco.com
10-13-2022 03:59 AM
You should open port 443 and 80 in your firewall
10-14-2022 09:01 AM
It does not use port 80. We’re using SL on our Expressways and do not have port 80 open in the firewall for the E to communicate with the on-prem SSM.
10-17-2022 01:56 AM
Port 80 needs to be open in version 14.0.6 of EXP (I have not testet with other versions). It dosen't make sense i know, but i have debugged on the error for a week and after we open port 80, it starts to work.
10-17-2022 04:50 AM
We use a newer version that that and we do not have port 80 open from the E’s to the on-prem SSM.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide