Unable to Commit Changes after Installing New Certificate

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Unable to Commit Changes after Installing New Certificate

L2 Linker

I was asked to assist with a new wildcard certificate that was uploaded to the firewall yesterday, update the SSL/TLS Service Profile and confirmed settings for GP.  Commit failed so began reviewing configuration. The 2 reasons listed for the failure were:

 

client useridd phase 1 failure
client gp_broker phase 1 failure

 

Double checking and the wildcard certificate was set active for the Authentication Override between the GP Portal and Gateway; reverted to the old certificate and the that error cleared.  

 

While looking into the other commit error was for found that the SSL/TLS profile had been used in the user-id settings for the server monitor section.  

 

I was able to create a new SSL/TLS profile using the new correct certificate and confirmed that is now working for the GP login page, but would like to get the other 2 errors corrected so I can remove the expired certificates.

 

What I did notice is that if I select TLS 1.3 as the maximum version for in the SSL/TLS profile, the new profile isn't listed as an option in the User-ID Syslog Service Profile drop down.  

 

Both old and new certificates are from the same CA.  The only real difference I see between the 2 certificates is that the old certificate had the following SANs:

 

*.mydomain.org

mydomain.org

 

While the new only has *.mydomain.org.

0 REPLIES 0
  • 17 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!