HPE OneView
1752565 Members
5340 Online
108788 Solutions
New Discussion

OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is expired

 
SOLVED
Go to solution
Todd_Bowden
Occasional Advisor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

John,

Im in total agreement with the person who started this thread.  OneView is so quirky, getting these obscure error messages.

I have tried to upload this .CRL file and stupid OneView says, I need a .CRL file2018-05-09_09-29-55.jpg

Todd_Bowden
Occasional Advisor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

Here is the fix, delete the CRL that it is complaining about, in this case "VeriSign Class 3 Public Primary Certification Authority - G5"

I found a Symantec website that you can copy and paste the key to put it back in.

https://knowledge.symantec.com/support/mpki-for-ssl-support/index?page=content&id=SO5624&actp=LIST&viewlocale=en_US

Just copy and paste the key, and BOOM, all is well.

 

Hope it helps

 

 

Dennis Handly
Acclaimed Contributor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

> I don't know how much clearer I can get

 

The problem isn't you, it's in the message.  :-)

CRLs don't "expire".  And the message doesn't say how to fix it, AFTER you get the CRL from the web.

Is your appliance connected to the Internet?

John Bigg
Esteemed Contributor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

Todd, I believe that the issue you saw with OneView reporting that a .crl file is needed even when a .crl file was selected is a known issue with certain versons of Firefox. Try using a different browser and you shouldn't see this and the crl file should work.

Lionel_Jullien
HPE Pro

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

The best is to use a PowerShell script using the OneView library so that you can automate all the process.

See https://github.com/jullienl/HPE-Synergy-OneView-demos/blob/master/Powershell/OneView/Update%20all%20existing%20OneView%20CRLs.ps1

This script updates all existing CRLs present in Oneview identified as expired.