- Community Home
- >
- Software
- >
- HPE OneView
- >
- HP-Oneview 4.0 upgrade Issues
Categories
Company
Local Language
Forums
Discussions
Knowledge Base
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-09-2018 12:33 PM
02-09-2018 12:33 PM
Re: HP-Oneview 4.0 upgrade Issues
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-12-2018 06:03 PM
02-12-2018 06:03 PM
Re: HP-Oneview 4.0 upgrade Issues
I just upgraded from 4.00.05 to 4.00.07 and my certificate issues are still present.
Only an issue on 1 enclosure. Other enclosures are fine. Firmware levels etc between the enclosures and blades are identical.
Have tried all the suggestions prior to the update, even after updating, and get the same. Nothing seems to fix this ILO certificate error on 1 enclosure.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-05-2018 05:30 AM
03-05-2018 05:30 AM
Re: HP-Oneview 4.0 upgrade Issues
I also have that error:
"Self-signed certificate with alias name HP Infrastructure Management Certificate Authority-internalroot Basic Constraint is not valid"
"Resolution: Provide a certificate with Basic Constraint set to SubjectType=CA. Try again."
Comming from 3.x -> 4.00.05 to 4.00.07
How can I solve it. I'm not seeing the certificate in question anywhere.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-05-2018 05:34 AM
03-05-2018 05:34 AM
Re: HP-Oneview 4.0 upgrade Issues
I have upgraded from 4.00.05 to version 4.00.07 with no issues. and its fixed the original issue with the certificates :)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-05-2018 01:08 PM
03-05-2018 01:08 PM
Re: HP-Oneview 4.0 upgrade Issues
I can confirm that the certificate alerts are gone after the upgrade to 4.0.07...
I still had the error on the SCMB certificate with SHA1, but that one is solved now with the 2 CLI instructions from Chris Lynch, mentioned in another thread...
If my post was useful, clik on my KUDOS! "White Star" !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-18-2018 03:08 AM
05-18-2018 03:08 AM
Re: HP-Oneview 4.0 upgrade Issues
Kick of this topic., as I'm facing 3 issues with another Oneview environment (on another location) from 3.x to 4.00.07.02. Had a lot of expired ILO certificates (15), this issue is resolved by reset the ilo to factory defaults, re-add the ip-address etc again and update the certificates in the store in OV.
1. a lot of 'leaf certificate with alias name 'xxx' is expired. I can't remove these alerts myself, they are locked in 'Active Alerts'
2. CA certificate with alias name xx is expired. Can i see somewhere if this CA Certificate is still being used by some device?
3. Alert 'The appliance certificate does not have 'Client Authentication' in its Enhanced Key Usage field which is required for OneView to communicate to an iLO that has two-factor authentication mode enabled.' Where can I change this or resolve this behavior?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-18-2018 06:11 AM
05-18-2018 06:11 AM
Re: HP-Oneview 4.0 upgrade Issues
I just installed version 4.00.09 and after thast the certificate problem was gone.
Now i just have to figure out how to get a leaf certificate, but the critical error is gone.
Kenneth
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-18-2018 07:07 AM
05-18-2018 07:07 AM
Re: HP-Oneview 4.0 upgrade Issues
Glad to hear the 4.00.09 patch helped fix the critical error. The leaf certificate is the iLO cert. As long as it is being managed, and no further errors about the certificate have been reported, the cert should already be trusted within the appliance certificate store.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-18-2018 07:13 AM
05-18-2018 07:13 AM
Re: HP-Oneview 4.0 upgrade Issues
@Jkersten1982 wrote:Kick of this topic., as I'm facing 3 issues with another Oneview environment (on another location) from 3.x to 4.00.07.02. Had a lot of expired ILO certificates (15), this issue is resolved by reset the ilo to factory defaults, re-add the ip-address etc again and update the certificates in the store in OV.
1. a lot of 'leaf certificate with alias name 'xxx' is expired. I can't remove these alerts myself, they are locked in 'Active Alerts'
2. CA certificate with alias name xx is expired. Can i see somewhere if this CA Certificate is still being used by some device?
3. Alert 'The appliance certificate does not have 'Client Authentication' in its Enhanced Key Usage field which is required for OneView to communicate to an iLO that has two-factor authentication mode enabled.' Where can I change this or resolve this behavior?
- The 4.00.09 update will help fix this issue.
- Unfortunately, not today.
- You need to validate in your Cert Authority template that it will create a certificate with both "Server Authentication" and "Client Authentication" Ehanced Key Usage proerties when issuing the certificate. If you are using Microsoft Certificate Authority, these ehance key usage properties are standard in the Web Server template.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-18-2018 07:15 AM
05-18-2018 07:15 AM
Re: HP-Oneview 4.0 upgrade Issues
Hmm didn't notice .09 was released; will try to upgrade the OV to this version this weekend or next week, and let's see what happends than. Still working to fix the issue(s), out of the blue, there are some servers complaining now about; the following. Strange thing is, the certificate is valid, so I don't expect these messages at all.
Unable to establish trusted communication with the server. The iLO certificate does not have any IP address or host name specified.
The certificate has a hostname, so i have to figure out why this error is happening and howto resolve this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-18-2018 07:18 AM
05-18-2018 07:18 AM
Re: HP-Oneview 4.0 upgrade Issues
@ChrisLynch wrote:
- The 4.00.09 update will help fix this issue.
- Unfortunately, not today.
- You need to validate in your Cert Authority template that it will create a certificate with both "Server Authentication" and "Client Authentication" Ehanced Key Usage proerties when issuing the certificate. If you are using Microsoft Certificate Authority, these ehance key usage properties are standard in the Web Server template.
Thanks! Will give it a try later. Maybe my issues what I'm facing now is also resolved when upgrading to 4.00.09. Will let you know.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-22-2018 02:37 AM
05-22-2018 02:37 AM
Re: HP-Oneview 4.0 upgrade Issues
This morning, I have deployed update 4.00.09 to resolve 2 issues.
After the upgrade the 2 errors are still displayed in Oneview:
1. 'Leaf certificate' with alias name <hash> is expired
2. 'Unable to establish trusted communication with the server. ILO certificate does not have any IP address or host specified'
Is there something what we can do to remove the alerts?
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-22-2018 06:30 AM
05-22-2018 06:30 AM
Re: HP-Oneview 4.0 upgrade Issues
I found this interiesting document here https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00041655en_us&docLocale=en_US, my issue is that the date validation from to is reversed.
I tried to follow a link in the file, but it took me to an HPE site where this file does not exist.
this is the link https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c03743622
is there a solution to this?
Kenneth
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-23-2018 03:11 AM
05-23-2018 03:11 AM
Re: HP-Oneview 4.0 upgrade Issues
That document was superseded by https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00042194en_us
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-23-2018 10:49 PM
05-23-2018 10:49 PM
Re: HP-Oneview 4.0 upgrade Issues
@Jkersten1982 I was able to fix the Certificate problem, all it took was to reset the ILO to default and then set it up again with the correct ip and so on, then the certificate was renewed with correct from - to date and all went green again :)
hope this will help you to solve your issue.
Kenneth
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-24-2018 03:21 AM
05-24-2018 03:21 AM
Re: HP-Oneview 4.0 upgrade Issues
@KSM1 yeah I know, I have corrected it for the Gen8 machines. for Gen7 machines I can't get it fixed. Certificate has a correct date (start 2018/end 2033), but the error still remains.
And second, the error starting with 'Leaf certificate' is still displayed as a critical alerts. I still can't remove the error myself.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2019 02:42 PM
01-09-2019 02:42 PM
Re: HP-Oneview 4.0 upgrade Issues
Currently on OneView 4.10 and this issue still exist it seems, 3 iLO connections reporting SSL certs
Valid From Jan 30 23:00:00 2013 GMT
Valid Until Dec 26 17:31:44 2001 GMT
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2019 09:30 PM
01-09-2019 09:30 PM
Re: HP-Oneview 4.0 upgrade Issues
Hi @YYCSysAdmin
I work for HPE.
Can you help us with any further information you can share on this?
The incorrect valid from / valid until dates in certificates on some of the iLOs - are you having trouble in fixing the firmware and certificates on the 3 iLOs?
Or, are you stating that
1. the locked alerts are still there in OneView 4.10 and not getting cleared even though the certificates got fixed?
2. OneView 4.10 is alerting about the specific bad certificates (whereas it should not be)
Regards,
Bhaskar
I am an HPE employee

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2019 07:22 AM
01-10-2019 07:22 AM
Re: HP-Oneview 4.0 upgrade Issues
Hello,
The iLO are gen 4, using firmware 2.60 May 23 2018, on blade nodes ProLiant BL460c Gen8. We are using OneView 4.10 currently. The alerts are showing for 3 nodes and the expiration date is showing as Dec 2001
Issued By
C = US, ST = TX, L = Houston, O = Hewlett-Packard Company, OU = ISS, CN = iLO Default Issuer (Do not trust)
Valid From
Jan 30 23:00:00 2013 GMT
Valid Until
Dec 26 17:31:44 2001 GMT
Serial Number
52:6a:a1:3c
I will be doing a host rename on the iLO and a power cycle for it to generate new certificates, unless there is a better method that does not require me to power cycle the blade node?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2019 07:26 AM
01-10-2019 07:26 AM
Re: HP-Oneview 4.0 upgrade Issues
A power cycle of the server is never required just to change or update the iLO SSL Cert, let alone the iLO configuration. If you want to automate this process, or do multiple iLOs without needing to go to their respective web management UI's, you can use this PowerShell script.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2019 09:17 AM
01-10-2019 09:17 AM
Re: HP-Oneview 4.0 upgrade Issues
Thank you Chris,
I was going by what a couple of other people had posted their solution was to the issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2019 10:50 AM
01-10-2019 10:50 AM
Re: HP-Oneview 4.0 upgrade Issues
Question, as I am running into an issue. I am trying to test this in our lab but receiving an error
"The certificate is not truested due to these X509CertChain flags: NotTimeValid" -
I checked the GitHub page but do not see a support thread related to this script. The MS links did provide possible ignore flags but I am unsure where to put them into the script to ingnore the NotValidTime error.
I would like to test this out in our lab first if possible.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2019 11:33 AM
01-10-2019 11:33 AM
Re: HP-Oneview 4.0 upgrade Issues
Replace Line 166:
[System.Net.ServicePointManager]::CertificatePolicy = New-Object TrustAllCertsPolicy
with
[System.Net.ServicePointManager]::CertificatePolicy = { $true }
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2019 02:48 PM
01-10-2019 02:48 PM
Re: HP-Oneview 4.0 upgrade Issues
Thank you very much!
My next inquiry, can i specify this to only do a single iLO vs all nodes in OneView? Or does it prompt once run?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2019 02:51 PM
01-10-2019 02:51 PM
Re: HP-Oneview 4.0 upgrade Issues
Line 170 is where you would change to something like:
$servers = Get-HPOVServer -Name ServerName
or for wildcard search
$servers = Get-HPOVServer -Name ServerName*
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]