Symantec Access Management

 View Only
  • 1.  Partnership federation keeps old information of a renewed certificate

    Posted Jun 19, 2019 09:22 AM
    Hello,

    Does anyone have ever seen this happening?
    I just updated a certificate that will expire soon (jun, 24).
    However, when I check the partnership and the entity (which use this certificate), both keeps showing the expiration date of the previous version of it.
    Please note that I also deactivated the federation before updating the certificate and even like this the information is never updated.
    I wonder if this is only a "presentation bug" or a cached information that was not recycled by WamUi.

    Regards


  • 2.  RE: Partnership federation keeps old information of a renewed certificate

    Broadcom Employee
    Posted Jun 20, 2019 03:36 AM
    Hi Marcos,

    You can use the secondary certificate to modify the certificate and
    avoid down time. Also, you should pay attention on how to manage the
    alias.

    Refer to the following KD to know how to proceed :

    What is the recommended approach to renew a Federation signing certificate that is about to expire?
    https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=108733

    Token Signing Certificate Expiry
    https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=98292

    Certificates Uploaded to Policy Store don't show up in WAMUI
    https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=9642

    I hope this helps,

    Best Regards,
    Patrick


  • 3.  RE: Partnership federation keeps old information of a renewed certificate

    Posted Jun 20, 2019 08:29 AM
    ​Hello Patrick,

    Thanks for spearing a time to answer my question.
    Actually, I did exactly what is described in you first article (https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=108733) - this is how I usually update a certificate. That was the first time that I saw something like that happening.

    Finally, I managed to find out that it was nothing but a WamUi bug .. even when I recycle the cache information from it, it kept showing the obsolete information.
    But when I check the certificate information via smkeytool, it shows me the new certificate expiration date.

    Thank you once again.

    Regards,
    Marcos


  • 4.  RE: Partnership federation keeps old information of a renewed certificate
    Best Answer

    Broadcom Employee
    Posted Jun 20, 2019 03:36 AM
    Hi Marcos,

    You can use the secondary certificate to modify the certificate and
    avoid down time. Also, you should pay attention on how to manage the
    alias.

    Refer to the following KD to know how to proceed :

    What is the recommended approach to renew a Federation signing certificate that is about to expire?
    https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=108733

    Token Signing Certificate Expiry
    https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=98292

    Certificates Uploaded to Policy Store don't show up in WAMUI
    https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=9642

    I hope this helps,

    Best Regards,
    Patrick