10-07-2021 12:01 PM
I have a HA CUC cluster. I recently noticed that our certificates on the cluster have already expired. I have not observed any adverse effects of the expired certificates.
These certificates are:
My questions are,
Solved! Go to Solution.
10-07-2021 10:47 PM - edited 10-08-2021 12:13 AM
It’s likely because you have not restarted the service that use that certificate. It keeps the certificate in memory and does not reload it until next restart.
10-07-2021 11:28 PM
My questions are,
Two days back I faced an issues with the DRF backup due to a expired certificate. If you didn't face an issues, doesn't mean that its not required. Proactive is better than reactive.
10-07-2021 12:37 PM
The recommendation is to always renew and keep all of your certificates valid. Please have a look at this document for the procedure for this. Cisco UC Certificates Renewal Guide
10-07-2021 03:07 PM
The odd thing is, DRF is continuing to backup CUC with no errors (with an expired ipsec.pem certificate). I didn't expect to find that.
10-07-2021 10:47 PM - edited 10-08-2021 12:13 AM
It’s likely because you have not restarted the service that use that certificate. It keeps the certificate in memory and does not reload it until next restart.
10-07-2021 11:28 PM
My questions are,
Two days back I faced an issues with the DRF backup due to a expired certificate. If you didn't face an issues, doesn't mean that its not required. Proactive is better than reactive.
10-08-2021 06:08 AM
Then I'll get this in front of our CCB to approve doing this asap.
Thank you for the information, everyone.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide