<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error accessing SDN UI after browser update in Software Defined Networking</title>
    <link>https://community.hpe.com/t5/software-defined-networking/error-accessing-sdn-ui-after-browser-update/m-p/6733864#M760</link>
    <description>&lt;P&gt;With the latest firefox and chrome browser updates, accessing the sdn ui fails with "&lt;SPAN&gt;ERR_SSL_VERSION_OR_CIPHER_MISMATCH".&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Searching online I gathered that the browsers no longer support DSA public keys. I'm told&lt;/P&gt;&lt;P&gt;regenerating the certificate should fix this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is how to regenerate the certificate for the VAN UI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2015 14:53:59 GMT</pubDate>
    <dc:creator>panluowei</dc:creator>
    <dc:date>2015-04-17T14:53:59Z</dc:date>
    <item>
      <title>Error accessing SDN UI after browser update</title>
      <link>https://community.hpe.com/t5/software-defined-networking/error-accessing-sdn-ui-after-browser-update/m-p/6733864#M760</link>
      <description>&lt;P&gt;With the latest firefox and chrome browser updates, accessing the sdn ui fails with "&lt;SPAN&gt;ERR_SSL_VERSION_OR_CIPHER_MISMATCH".&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Searching online I gathered that the browsers no longer support DSA public keys. I'm told&lt;/P&gt;&lt;P&gt;regenerating the certificate should fix this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is how to regenerate the certificate for the VAN UI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 14:53:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/software-defined-networking/error-accessing-sdn-ui-after-browser-update/m-p/6733864#M760</guid>
      <dc:creator>panluowei</dc:creator>
      <dc:date>2015-04-17T14:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Error accessing SDN UI after browser update</title>
      <link>https://community.hpe.com/t5/software-defined-networking/error-accessing-sdn-ui-after-browser-update/m-p/6733906#M761</link>
      <description>&lt;P&gt;The Certifacte signing requirements for a large portion of browsers has recentaly changed, and because of this the orignal self signed version for the SDN Controller conflicts with these browsers minimum requirements. Here is the procedure for manually generating a new self signed certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bold Italic text is commands&lt;/P&gt;&lt;P&gt;Bold is Important notes&lt;/P&gt;&lt;P&gt;I have indented sample output&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following needs to be done as root hence( I am assuming the account your are using does have sudo premissions for root)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;sudo service sdnc stop&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then the following needs to be done&amp;nbsp;as the user which&amp;nbsp;the sdn controller controller runs as(The user is the user sdn by default), since the truststore and keystore must be readable by that user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hint to become the user sdn us the following “&lt;STRONG&gt;&lt;EM&gt;sudo su – sdn”.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;cd /opt/sdn/admin&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;ls -l *store*&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;sdn@ubuntu:~/admin$ ls -l *store*&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;-rw-r----- 1 sdn sdn 1319 Mar 20 14:53 keystore&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;-rw-r----- 1 sdn sdn&amp;nbsp; 913 Mar 20 14:53 truststore&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note the permissions and ownership of the files&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here we generate a self-signed certificate with a validity period of 1780 days, after moving the old keystore and truststore away.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note you need to use the password “skyline” below unless you have changed it&lt;/STRONG&gt;. I have added it in for clarity in the commands below but it will not show when it is typed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Leave the password for the key the same as the keystore password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;mv keystore keystore.orig&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;mv truststore truststore.orig&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;keytool -genkey -alias serverKey -keyalg rsa -keysize 2048 -keystore keystore -validity &amp;nbsp;1780&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;sdn@ubuntu:~/admin$ keytool -genkey -alias serverKey -keyalg rsa -keysize 2048 -keystore keystore&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Enter keystore password: skyline&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Re-enter new password: skyline&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;What is your first and last name?&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; [Unknown]:&amp;nbsp; 192.168.181.135&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;What is the name of your organizational unit?&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; [Unknown]:&amp;nbsp; SDNCOE&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;What is the name of your organization?&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; [Unknown]:&amp;nbsp; HP&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;What is the name of your City or Locality?&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; [Unknown]:&amp;nbsp; Amstelveen&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;What is the name of your State or Province?&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; [Unknown]:&amp;nbsp; Noord-Holland&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;What is the two-letter country code for this unit?&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; [Unknown]:&amp;nbsp; NL&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Is CN=192.168.181.135, OU=SDNCOE, O=HP, L=Amstelveen, ST=Noord-Holland, C=NL correct?&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; [no]:&amp;nbsp; y&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Enter key password for &amp;lt;serverKey&amp;gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (RETURN if same as keystore password): Just press enter here&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;sdn@ubuntu:~/admin$&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;keytool -exportcert -keystore keystore -alias serverKey -file serverkey.cer&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;sdn@ubuntu:~/admin$ keytool -exportcert -keystore keystore -alias serverKey -file serverkey.cer&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Enter keystore password:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Certificate stored in file &amp;lt;serverkey.cer&amp;gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;sdn@ubuntu:~/admin$&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;ls -ltr&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;sdn@ubuntu:~/admin$ ls -ltr&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;total 15728&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;-rwxr-x--- 1 sdn sdn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 462 Jan 29 12:46 uninstall-dpkg&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;-rwxr-x--- 1 sdn sdn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 486 Jan 29 12:46 startup.sh&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;-rwxr-x--- 1 sdn sdn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1453 Jan 29 12:46 sdnpass&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;lt;SNIP&amp;gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;-rw-rw-r-- 1 sdn sdn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2257 Apr&amp;nbsp; 9 01:51 keystore&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;-rw-rw-r-- 1 sdn sdn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1088 Apr&amp;nbsp; 9 01:52 sdn-server.csr&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;-rw-rw-r-- 1 sdn sdn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 903 Apr&amp;nbsp; 9 02:06 serverkey.cer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;Note you need to use the password “skyline” below unless you have changed it&lt;/STRONG&gt;. I have added it in for clarity in the commands below but it will not show when it is typed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;keytool -importcert -trustcacerts -keystore truststore -file serverkey.cer -alias CARoot&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;sdn@ubuntu:~/admin$ keytool -importcert -trustcacerts -keystore truststore -file serverkey.cer -alias CARoot&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Enter keystore password: skyline&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Re-enter new password: skyline&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Owner: CN=192.168.181.135, OU=SDNCOE, O=HP, L=Amstelveen, ST=Noord-Holland, C=NL&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Issuer: CN=192.168.181.135, OU=SDNCOE, O=HP, L=Amstelveen, ST=Noord-Holland, C=NL&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Serial number: 54a39e23&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Valid from: Thu Apr 09 01:51:25 PDT 2015 until: Wed Jul 08 01:51:25 PDT 2015&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Certificate fingerprints:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MD5:&amp;nbsp; 44:02:D6:58:C5:2A:2D:B5:F3:64:9B:40:6D:9B:1D:10&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHA1: C7:59:89:31:9D:79:C9:D5:3A:22:D7:36:C7:43:2D:1B:88:5B:54:5E&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHA256: E9:5D:1E:06:02:25:17:3F:C4:D9:97:C4:28:27:E6:87:2F:BC:B4:C9:E1:47:17:57:FF:33:1B:23:86:41:A5:B0&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature algorithm name: SHA256withRSA&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version: 3&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Extensions:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;#1: ObjectId: 2.5.29.14 Criticality=false&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;SubjectKeyIdentifier [&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;KeyIdentifier [&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;0000: 82 FD 72 7D 83 60 88 C0&amp;nbsp;&amp;nbsp; DA 67 7D 6A 03 12 11 B7&amp;nbsp; ..r..`...g.j....&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;0010: 27 C7 EC D9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; '...&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;]&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;]&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Trust this certificate? [no]:&amp;nbsp; yes&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Certificate was added to keystore&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;sdn@ubuntu:~/admin$&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the user root hence, you might need to type “logout” here to switch to the account you usually log in which has sudo capbilities.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;sudo service sdnc start&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Gerhard Roets&lt;/P&gt;&lt;P&gt;HP SDN COE Team&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 16:58:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/software-defined-networking/error-accessing-sdn-ui-after-browser-update/m-p/6733906#M761</guid>
      <dc:creator>Gerhard Roets</dc:creator>
      <dc:date>2015-04-17T16:58:12Z</dc:date>
    </item>
  </channel>
</rss>

