Avaya Support Forums  

Go Back   Avaya Support Forums > Avaya Networking Products

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 09-03-2014, 10:14 AM
bdholmes bdholmes is offline
Hot Shot
 
Join Date: Aug 2014
Location: Columbia TN
Posts: 16
bdholmes has 12 reputation points
Question Certificates on Ignition server

Our security dept renewed or Root and Signing CA certificates. When I try to load the new certificates into our Ignition server it says the name cannot match an existing certificate and refuses to load.

Don't I need the old and new since most of our objects were signed with the old. Or can I just delete the old and load the new?

Many of our objects were not signed with the new certificates yet.

Or will the ignition server only look at the name on the certificate for trust? None of the other information on the certificate matters? date, serial # etc..

Trying to understand how this is going to work.
__________________
Brian Holmes

Network Architect
Fiat Chrysler Automobiles
Reply With Quote
  #2  
Old 09-03-2014, 04:04 PM
bdholmes bdholmes is offline
Hot Shot
 
Join Date: Aug 2014
Location: Columbia TN
Posts: 16
bdholmes has 12 reputation points
Angry

This is actually broken in v9.0.1. One cannot load two certificates with the same name, even if the public key is different. I will have to try and get a bug fix from Avaya for this as our public certificate is expiring soon, so we simply renewed it with the same name.

The problem is the Ignition server will only allow us to load the old or the new and not both. So if I load the new, all old clients become untrusted...and if I load the old, any client signed by the new will be untrusted.

In a pickle here.
__________________
Brian Holmes

Network Architect
Fiat Chrysler Automobiles
Reply With Quote
  #3  
Old 10-03-2014, 08:51 AM
rshaynes rshaynes is offline
Whiz
.
 
Join Date: Mar 2010
Location: Eastern Time Zone, United States
Posts: 27
rshaynes has 12 reputation points
Default Duplicate Certificate Import Concern

Brian,

Thank you for reporting this issue via the forums. We would appreciate that if you believe you have identified potential product related issues that you raise a services support request with Avaya Support Services @ https://support.avaya.com.

In the interim I will review your findings and discuss with our development teams regarding this issue.
Reply With Quote
Reply

Tags
certificate, eap-tls, ide, ignition

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 02:56 PM.

This Forum is provided solely for the use and convenience of Avaya customers and partners. Use of the Forum is subject to the Terms and Use and Privacy Statement found at www.avaya.com. No other use is permitted. The Forum including all content posted is “AS IS” and Avaya expressly disclaims all warranties and/or guarantees as to its accuracy, reliability, usefulness, quality or non-infringement of intellectual property. Avaya reserves the right to remove any content posted on the Forum at any time and for whatever reason.

Avaya will not be liable for any content posted on this Forum, including, without limitation, any errors or omissions or for any losses or damages of any kind incurred as a result of use or reliance on any content, regardless of its origin.

You expressly understand and agree that you assume all risks associated with use or reliance on this content.