DX Unified Infrastructure Management

 View Only
  • 1.  Renew SSL Cert

    Posted May 03, 2021 11:30 AM
    In the process of renewing a SSL cert for our Operator Console.  I have reviewed and used the online doc

    https://techdocs.broadcom.com/us/en/ca-enterprise-software/it-operations-management/unified-infrastructure-management/20-3/installing/optional-post-installation-tasks/Configure-HTTPS-in-Admin-Console-or-OC-(Authority-Signed-SSL-Certificate).html

    But, is this the process we should use to renew a ssl?  The Instructions in the list above seem to talk about a generating a new cert.

    Thanks in advance for all responses.

    RJ


  • 2.  RE: Renew SSL Cert

    Broadcom Employee
    Posted May 03, 2021 04:08 PM
    See if this helps:

    https://knowledge.broadcom.com/external/article?articleId=121612


  • 3.  RE: Renew SSL Cert

    Posted May 04, 2021 10:51 AM
    Note: we found that we needed to provide the whole certificate chain in the file when loading the certificate file as described in the above article (from Greg)

    ------------------------------
    Knows a little about UIM/DXim, AE, Automic
    ------------------------------



  • 4.  RE: Renew SSL Cert

    Posted May 05, 2021 01:55 AM
    Isn't a renewal an actual generation of a new SSL certificate? It should be no difference from the installation of a new certificate from an existing one. The only difference would be with the import of the certificate chain into the existing trust store. If your certificate is signed with the same CA, you most probably won't have to make any changes to it.

    ------------------------------
    Senior Consultant
    SolvIT Networks
    ------------------------------



  • 5.  RE: Renew SSL Cert

    Posted May 05, 2021 08:26 AM
    Catalin

    You are right theoretically, but what we found is that the wasp seems to only look in the "wasp" alias of the keystore.  So even though you are only doing a renewal of an existing server certificate the whole certificate chain is stored under the wasp alias, thus even though the intermediate and root certs have not changed they still need to be added to the updated cert file and the whole chain loaded at the cert import step.

    Regards, Andrew


    ------------------------------
    Knows a little about UIM/DXim, AE, Automic
    ------------------------------



  • 6.  RE: Renew SSL Cert

    Posted May 06, 2021 11:44 AM
    Thanks to all who responded.  We got it done!