How to query the tree to locate SSL Certificates that have expired or are close to expiring.
This document (3814248) is provided subject to the disclaimer at the end of this document.
Environment
eDirectory 8.7.3
Situation
SSL Certificate is expired
Can't identify which SSL Certificates are expired or soon to expire.
How to query the tree to locate SSL Certificates that have expired or are close to expiring.
Resolution
2nd part of the fix is an updated pki.nlm version 2.77. This is included with edir8736 update. It is located in the /security/secupd directory. It is possible to just install the secupd piece which has it's own secupd.ips file seperate from the nds installation. (although it is recommended to update edirectory as well) Once you have installed this through nwconfig, reboot the server.
Additional Information
dn: cn=SSL CertificateIP - FS1,ou=servers,o=novell
changetype: add
nDSPKINotAfter: 200611121824
nDSPKINotBefore: 200411121824
Once it is determined which certificates are expired or soon to
expire, there are multiple ways to remedy the situation. On Netware
pkidiag can be used. More information on using this tool can be
found in tid 10095905.
iManager 2.5 or later can also be used and may be the more convenient option. Through Novell Certificate Server | Create Default Certificates task, a list of servers can be defined with the option to overwrite the chosen server's default certificates. This is also useful as it gives a summary screen breaking down by server the success or failure of each certificate creation attempt. In order to see the Create Default Certificates task the latest pki.npm will need to be installed. So the minimal version that will need to be applied is 3.1.20060109. This can be obtained at http://download.novell.com. Search for Novell iManager in the drop down box and then search for pkis on this page.
Default Certificates would be the following:
| IP AG | ||
| SSL CertificateIP - | ||
| DNS AG | ||
SSL CertificateDNS - Additional steps may be required for for applications that import edirectory certificates into a file file format or keystore. |
Formerly known as TID# 10097442
Document
| Document ID: | 3814248 |
| Creation Date: | 02-26-2007 |
| Modified Date: | 12-24-2008 |
Disclaimer
The Origin of this information may be internal or external to Novell. Novell makes all reasonable efforts to verify this information. However, the information provided in this document is for your information only. Novell makes no explicit or implied claims to the validity of this information.
Any trademarks referenced in this document are the property of their respective owners. Consult your product manuals for complete trademark information.