<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trust Madness Part 2 -- Duplicate Certs in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/trust-madness-part-2-duplicate-certs/m-p/3583440#M13051</link>
    <description>We already have a Replicate Agent settings task that distributes the new certificate (as well as settings) every day.&lt;BR /&gt;&lt;BR /&gt;I can use the Configure and Repair agents to push the new certificate -- we've done this many times and it works too (well once you move your certs to C:\HP\SSLSHARE anyways).&lt;BR /&gt;&lt;BR /&gt;Every server has the new cert, but it also has the old cert.&lt;BR /&gt;&lt;BR /&gt;Removing the old cert will restore the trust, but I haven't been able to find any way to automate the removal of the old certs.</description>
    <pubDate>Fri, 15 Jul 2005 06:56:03 GMT</pubDate>
    <dc:creator>Kevin Kelling</dc:creator>
    <dc:date>2005-07-15T06:56:03Z</dc:date>
    <item>
      <title>Trust Madness Part 2 -- Duplicate Certs</title>
      <link>https://community.hpe.com/t5/server-management-systems/trust-madness-part-2-duplicate-certs/m-p/3583438#M13049</link>
      <description>OK..fixed the problem where SIM was distributing the wrong cert.&lt;BR /&gt;&lt;BR /&gt;Only a handful of our 400 servers are trusted however.&lt;BR /&gt;&lt;BR /&gt;I picked 2 test servers.  They each had 2 certificates for the hostname of the CMS/SIM server.  SIM correctly pushed the new cert but did not remove the old one.&lt;BR /&gt;&lt;BR /&gt;Once I removed the old certificte and rediscovered the system, the trust was present.  I repeated this for the other node with the same results.&lt;BR /&gt;&lt;BR /&gt;It appears that SIM will add certs but not take them away.  Herein lies the problem.  I need to find a way to remove the old cert on 400 servers -- so I can establish a trust with them -- or otherwise do it manually x400.&lt;BR /&gt;&lt;BR /&gt;Please tell me there is a way to automate this.  :^)&lt;BR /&gt;&lt;BR /&gt;Thanks.</description>
      <pubDate>Fri, 15 Jul 2005 05:44:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trust-madness-part-2-duplicate-certs/m-p/3583438#M13049</guid>
      <dc:creator>Kevin Kelling</dc:creator>
      <dc:date>2005-07-15T05:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Madness Part 2 -- Duplicate Certs</title>
      <link>https://community.hpe.com/t5/server-management-systems/trust-madness-part-2-duplicate-certs/m-p/3583439#M13050</link>
      <description>Hi Kevin,&lt;BR /&gt;&lt;BR /&gt;Since you have trusts established, did you try using "Configure-&amp;gt;Replicate Agents Settings...", and choose a "source" server where there is only 1 certificate, and replicate the "Trusted Certificate" setting??&lt;BR /&gt;This procedure, replaces what you have on target server, insted of adding it.&lt;BR /&gt;I think the source server has to have similar Agent versions, than target server.&lt;BR /&gt;&lt;BR /&gt;Hope this helps&lt;BR /&gt;&lt;BR /&gt;Alfredo</description>
      <pubDate>Fri, 15 Jul 2005 06:45:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trust-madness-part-2-duplicate-certs/m-p/3583439#M13050</guid>
      <dc:creator>Alfredo Soares</dc:creator>
      <dc:date>2005-07-15T06:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Madness Part 2 -- Duplicate Certs</title>
      <link>https://community.hpe.com/t5/server-management-systems/trust-madness-part-2-duplicate-certs/m-p/3583440#M13051</link>
      <description>We already have a Replicate Agent settings task that distributes the new certificate (as well as settings) every day.&lt;BR /&gt;&lt;BR /&gt;I can use the Configure and Repair agents to push the new certificate -- we've done this many times and it works too (well once you move your certs to C:\HP\SSLSHARE anyways).&lt;BR /&gt;&lt;BR /&gt;Every server has the new cert, but it also has the old cert.&lt;BR /&gt;&lt;BR /&gt;Removing the old cert will restore the trust, but I haven't been able to find any way to automate the removal of the old certs.</description>
      <pubDate>Fri, 15 Jul 2005 06:56:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trust-madness-part-2-duplicate-certs/m-p/3583440#M13051</guid>
      <dc:creator>Kevin Kelling</dc:creator>
      <dc:date>2005-07-15T06:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Madness Part 2 -- Duplicate Certs</title>
      <link>https://community.hpe.com/t5/server-management-systems/trust-madness-part-2-duplicate-certs/m-p/3583441#M13052</link>
      <description>Kevin, did you ever find a way to remove the old certs?</description>
      <pubDate>Thu, 04 Dec 2008 18:14:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/trust-madness-part-2-duplicate-certs/m-p/3583441#M13052</guid>
      <dc:creator>Tusc</dc:creator>
      <dc:date>2008-12-04T18:14:42Z</dc:date>
    </item>
  </channel>
</rss>

