WebSphere Application Server & Liberty

 View Only
Expand all | Collapse all

Self-signed cert auto renewal has been failed - Websphere Application Server version 9.0.5.19

  • 1.  Self-signed cert auto renewal has been failed - Websphere Application Server version 9.0.5.19

    Posted Tue August 20, 2024 01:17 PM

    Hi,

    I am looking out for some help related to auto renewal of self-signed certs in Websphere Application server version 9.0.5.19

    Auto renewal supposed to be happened yesterday i.e., August-18-2024 as per Next start date in Manage cert expiration settings. However, it was not happened and Next start date showing(September 15) now as below.


    I would really appreciate if someone can help me with your inputs on this.



    ------------------------------
    Ramya Ramya
    ------------------------------


  • 2.  RE: Self-signed cert auto renewal has been failed - Websphere Application Server version 9.0.5.19

    Posted 2 days ago

    Hello Ramya,

    the date which is listed in the "Next start date" field only tells you, when the next check will happen, if a certificate is about to expire soon.
    It does not necessarily mean, that a certificate will be renewed on that date. 

    The certificate will be replaced / renewed if it is to expire within the "Expiration replacement threshold" listed at the top of the page (default 60 days)

    You can have a look at the SystemOut.log of your DMgr (or standalone server, if no Network Deployment),  where you should see the following entry on Sunday 9:30 PM:

    CWPKI0037I: Expiration monitor reports the following information:
    CWPKI0719I: The default personal certificate in the "NodeDefaultKeyStore((cell):cellname:(node):nodename)" keystore is due to expire on Mar 30, 2025 and might be replaced after the Jan 29, 2025 threshold date.

    or you can check the personal certificates in

    SSL certificate and key management > Key stores and certificates > NodeDefaultKeyStore > Personal certificates

    and see when they will expire.

    Hope that helps...

    Cheers,
    Chris



    ------------------------------
    Christian Lohmann
    ------------------------------