WebSphere Application Server & Liberty

WebSphere Application Server & Liberty

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Certificate missmatch after update

    Posted 01/19/12 08:40 AM
    Hi I have following cluster architecture:

    dmgr -> node1
             -> node2
             -> http1
             -> http2

    Now the certificates were expiring and not automatically renewed (reason was that http1 did not have a certificate).

    So I renewed node1 and node2 certificate on the dmgr console. After that I have stopped node1 and node2 and made "synchNode.bat" on both of them. Its weird after a restart the errors because of expired certificate still shows up.

    On the file system the new key.p12 have been copied to the nodes during sync. I can see them in WAS_HOME/profiles/config/cells/wpcell/nodes/node1 resp node2.

    Where could the old previously used certificate come from?

    What is the purpose of WAS_HOME/profiles/etc/key.p12?

    Any idea? The servers are still running but the nodes might not be properly synchronized.



  • 2.  Certificate missmatch after update

    Posted 01/19/12 08:52 AM
    In the profile/temp and profile/wstemp I can not see key.p12 files. Is there may be an other location where such a key file could be cached?


  • 3.  Certificate missmatch after update

    Posted 01/19/12 02:11 PM
    Check this IBM document and verify if you did all the steps. I think, you missed exchanging the signers. 

    www-304.ibm.com/support/docview.wss?uid=... 


  • 4.  Certificate missmatch after update

    Posted 01/20/12 07:51 AM
    Hi ,

    I think you replaced old certificate correctly.

    Have you replaced  old certificate with new one. Please check in Security, SSL key management and manage endpoint security.

    Check here all nodes for inbound and outbound.  If you are mapped with old certificate or new certificate.

    If you are not mapped, please map here. Please restart it once.

    You are not created new certificate for  DMGr. You created new certificate for nodes and webserver. You are checking certificate for DMGr or Nodes.

    Try to access the application with that perticular node, we can see application is using which certificate.

    If you are checking for DMgr console certificate this is old.


    Please correct me,  if i am wrong.

    Please cross check.


    Thanks,
    Chinna.