SSL certificate expired on new appliance OS port 9443 after reminting

So the certificate is ok after reminting on https://ourdomain.xx:7443 on our three new Appliance servers and removed our old windows servers.

but from what I read online it should have updated the VA cert as well at https://ourdomain.xx:9443 but it did not. I have to keep typing in thisisunsafe to access the page. Even before the remint I had to do this.

Trying to find how to either use the same cert or swap it out manually on the file system.

Anyone with thoughts? So far managing the Suse appliance has been a pain. As well as trying to increase var storage. We are on 23.4 and when I get this sorted I will attempt the 24 release.

  • 0  

    I would open a Service Request to see what is happening.  Normally the Certificates are one and the same.  Perhaps try Rebooting the entire VM and see if that helps.  Maybe the Appliance Console Web Service did not reload and is still using the old cert.  However, if you had the issue in the past, there is likely something amiss with your configuration files.  Maybe at one point things were edited to disassociate the certs, but I would not want to guess what was done.  Many, many years ago, the certs were indeed maintained separately, but that has not been the case for many years.

    --

    For VAStorage, it should not be that difficult since it's not the Boot OS.  You simply need to ensure there are not any current Snapshots and then use either the Appliance GUI or Native VM Tools to expand the disk depending on the VM Solution you are using.

    --

    I do recommend Enabling SSH permanently and then using WInSCP and Putty to access the appliance as need be.  These industry standard tools make daily work much simpler.  When doing so accessing the Appliance Console using Port 9443 should be quite uncommon.

    --

    If you found this post useful, give it a “Like” or click on "Verify Answer" under the "More" button

    Be sure to "Like" My (and a few others) Cool Solutions below! 

    https://community.microfocus.com/members/craigdwilson/bookmarks

  • 0 in reply to   

    I use putty and winscp daily for other tasks. Usually only turn on SSH when needed. If you thing its ok to leave them on and autostarted then I might.

    Af far as changed settings for the appliance I dought it. I just switched from windows server to appliances. I have not touched anything exept ssh to see whats happening. I have rebooted many times.

    What is the best way to go about opening a Service Request as I have never done one before. You have suggested this to me in the past but I always ended up figuring things out on my own so this would be my first support request since I started with ZEN in 15 years.

  • 0   in reply to 

    I just looked and saw you were a school.....So an SR may be a bit tougher as they are not automatically included with the licensing for education.  I don't want to suggest any hacks, because I'm not really sure why/how it's acting that way and I would hate to make matters worse.  

    Yes...Most Folks I know tend to leave SSH enabled.  It is a standard protocol for managing LInux Servers.....which is what is under the Black Box hood of the Appliance.  However,  there are some who disable it and mostly use vCenter for Management but those are the minority.

    --

    If you found this post useful, give it a “Like” or click on "Verify Answer" under the "More" button

    Be sure to "Like" My (and a few others) Cool Solutions below! 

    https://community.microfocus.com/members/craigdwilson/bookmarks

  • 0  

    Hi, As   mentioned, appliance web-console and ZCC uses the same certs. I would like to take a look at a few files.. (I may need a few more.. But we can start with these for now.)

    /opt/novell/jetty9/etc/jetty-ssl-context.xml

    /var/opt/novell/jetty/logs/jetty.stderrout.out

    /etc/opt/microfocus/zenworks/security/serverConfig.xml

    If possible,you can send these to me in private. Or you can share it with Craig.. I'll get it from him.

  • 0 in reply to   

    I sent you a private message. The files are availabe individually or all zipped.

  • Verified Answer

    +1   in reply to 

    Hi, Can you try running the following commands on the appliance and attempt a login?

    microfocus-zenworks-configure -c UnifyTrustStoreForApplianceConfigureAction

    systemctl restart vabase-jetty.service

    systemctl restart vabase-datamodel.service (Mostly not required.. But, just for the sake of it..)

  • 0 in reply to   

    You rock SIR!!!!!!

    I will save that in case the next remit years from now does the same thing!!!!!!!

  • 0 in reply to   

    Thanks to you as well of course Grinning