SES: Sip Enablement Services Alarm; SES,S,94,MAJ
Doc ID |
|
SOLN202865 |
Version: |
|
14.0 |
Status: |
|
Published |
Published date: |
|
19 Mar 2019 |
Created Date: |
|
25 May 2012 |
Details
SES 5.x
SES,S,94,MAJ
Checked PKI certificate:
[root@SESA01 ~]# openssl x509 -in /etc/opt/ecs/certs/server/server.crt -nout -enddate
notAfter=Jan 3 03:53:06 2032 GMT
Checked SIPcertificate:
[root@SESA01 ~]# openssl x509 -in /etc/opt/ecs/certs/CA/sip_product_root.crt -noout -enddate
notAfter=Jul 23 00:33:17 2011 GMT
Problem Clarification
SES,S,94,MIN avCCSCertExpired: SIP certificate serversip.crt is expired.
(Prior to expiration SES 93 MIN alarm will be seen warning of pending expiration.)
Cause
Avaya uses industry-standard digital Public Key Infrastructure (PKI) security certificates in many of its products to provide authentication and data encryption for communication links within its user solutions. As an industry-standard security measure, PKI certificates expire after a period of time.
On July 23, 2011, the certificates in certain releases of Avaya Aura™ Communication Manager, Avaya Aura™ SIP Enablement Services, Avaya Aura™ Conferencing, IP Softphone, IP Agent, Avaya one-X® Desktop, SIP Phone, and earlier versions of Avaya Aura™ Communication Manager Branch Edition (Distributed Office), expired. Certain critical functions within these products (see 'Impact of Expired Certificates' below) possibly experienced service outages if the PKI certificates were not updated prior to their expiration date.
The product releases listed in this bulletin are affected if their SIP connectivity to other applications uses Transport Layer Security (TLS) for encryption. No other SIP-capable products in Avaya's portfolio are impacted by the PKI certificates that expired on July 23.
Be advised that, due to the durability of many SIP connections (e.g. Communication Manager to SIP Enablement Services, Communication Manager to Modular Messaging or Voice Portal, etc.), it is very possible that some systems with expired certificates have not yet exhibited issues. The PKI certificate is only needed when a SIP connection needs to be re-established after being dropped deliberately or inadvertently. All SIP-enabled products at the release levels indicated below that use TLS for secure SIP communication, must receive an updated certificate. If nothing has been done to date, action should be taken immediately.
e.g. stat
Watchdog 9/ 9 UP
TraceLogger 3/ 3 UP
SME 7/ 7 UP
INADSAlarmAgen 1/ 1 UP
GMM 4/ 4 UP
SNMPManager 1/ 1 UP
ImLogger 3/ 3 UP
SipServer 2/44 PARTIALLY UP
CCSTrapAgent 1/ 1 UP
mon 1/ 1 UP
Solution
As of December 8, 2017 the built-in SIP Enablement Server TLS certificates have expired. Follow PSN020331U to either disable TLS and use TCP, or install a System Manager or 3rd Party Certificate.
Solution 1: (information available in PSN003381u or see PSN020331u)
Install new certificates using the patch script available at: http://support.avaya.com/PKI/install_certs.tar.gz root permission on the system is required to perform this task.
Patch install instructions
Service-interrupting? Potentially yes, reboot must occur. Should perform on standby, complete, interchange and then on secondary server.
1. Login to SES server as root.
2. Run the certificate verification commands below.
If both certificates have expiration dates well past 7/23/2011, no action is necessary on this SES server.
Typical output from these commands is shown below.
a. cp install_certs.tar.gz /root
b. cd /root. md5sum install_certs.tar.gz
3. Verify the md5sum command returns: 22bc327d52ef6567bbe67878c0b2a096
4. tar xvzf install_certs.tar.gz
5. ./install_certs.sh ( reboot will occur from script automatically )
6. Output: Certificate Authority /var/home/ftp/pub/sip_product_root.crt is now installed and will now be loaded upon system restart!
Solution 2:
Upgrade to SES software version 5.2.1.
Additional Relevant Phrases
SES: Sip Enablement Services Alarm; SES,S,94,MAJ
Certificate Nearing Expiration:
SES CORESIDENT CERTIFICATE EXPIRED
(Alarm Name) : SES,S,94 , (Alarm String) : 06/05:05,EOF,ACT|1000263683 06/05:05,EOF,ACT|SES,S,131,MAJ;SES,S,131,MAJ;SES,S,94,MAJ; ,MAJ;
sip
Avaya -- Proprietary. Use pursuant to the terms of your signed agreement or Avaya policy
|