11-14-2017 04:25 AM - edited 03-01-2019 01:21 PM
Hi all!
I have resign existing request for my UCS Manager and update certificate in KeyRing. But I don't know how to restart UCS WebServer to apply new cert. Can anyone help?
11-22-2017 07:31 AM
Hi,
Step 1 UCS-A# scope security
Step 2 UCS-A /security # scope keyring default
Step 3 UCS-A /security/keyring # set regenerate yes
Step 4 UCS-A /security/keyring # commit-buffer
this will regen your keyring and clear the fault
-Tyler
11-22-2017 07:50 AM
May be this correct for self-signed default certificate, but we use CA signed certs.
I had fixed this with:
Via UCSM GUI (use IE, Chrome will not work correctly while cert expired):
0. Get and Resign existing request with CA
1. Upload signed cert to keyring and refresh browser to confirm that now keyring status changed from Expired to Valid.
Go to SSH:
2. UCS-A# scope system
3. UCS-A# scope services
4. UCS-A# disable cimcwebsvc
5. UCS-A# disable http
6. UCS-A# commit-buffer
7. UCS-A# enable cimcwebsvc
8. UCS-A# enable http
9. UCS-A# commit-buffer
After this refresh page in your favorite browser.
10-18-2019 08:00 AM
Hello,
How to verify that the SSL certificate has been regenerated? Any show commands?
Thanks
10-18-2019 09:37 AM
scope security
show keyring detail
In the 'not after: ' section should be date in the future.
Kirk...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide