HPE OneView
1751840 Members
5345 Online
108782 Solutions
New Discussion юеВ

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

 
SOLVED
Go to solution
David Claussen
Regular Advisor

OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is expired


OneView Appliance for vSphere, version 4.00.07.02-0334467.

 

Why is OneView so incredibly difficult to work with?

My latest problem is the following error:

screenshot.25.jpg

So I copied the URL for the cert and it downloaded fine. 

Now, I tried to get this new cert into my HPOneView appliance. Security/Manager Certificates/Add Certificates

screenshot.26.jpg

After an hour of searching, I can find no way to open the CRL files and get the base64 cert text and there is no option to inport a local file.

So I try Add certificate from an IP address or hostname:

screenshot.27.jpg

Entering the url provided by the initial alert FROM ONEVIEW yeilds the error:

screenshot.28.jpg

I tried multiple ports as well with no success.

Now I have been fighting with OneView for months now - configuration issues, update issues, alerting issues (IE - seven alerts for a server reboot - this is a total nightmare and there is no documentation anywhere for help) and now this cert thing.

Any help is appreciated, but this is strike 27 for this software and if I can't get this cert thing cleared up - OneView is gone and I'll go back to SIM.

 

 

14 REPLIES 14
Nikolape
Occasional Advisor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

I have the same problem with our Synergy frame, and could not agree more with previous post. Please, any help would be appreciated! 

The question is simple, how to import missing .crl file?

Thank you.

frenchy94
Regular Advisor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

this issue is well documented in release notes i think


---
L'absence de virus dans ce courrier ├йlectronique a ├йt├й v├йrifi├йe par le logiciel antivirus Avast.
https://www.avast.com/antivirus
Dennis Handly
Acclaimed Contributor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

I'm not sure why you want to get a CRL?  The Certificate Revocation List contains a list of certs that have been revoked.

I only see a Last Update and Next Update fields.

You need to create new certs to replace the expired ones.

 

> I tried to get this new cert into my HPOneView appliance. Security/Manager Certificates/Add Certificates

 

I'm not sure why it would need you to add a CRL?

 

>  I can find no way to open the CRL files and get the base64 cert text and there is no option to import a local file.

 

You can open the .CRL in Windows.  Or use:

openssl crl -inform der -in pca3-g5.crl -text -noout

So I would suggest you look for expiration dates for your certs and CA certs.

Unless it's related to you can't access the CRL?

https://github.com/HewlettPackard/POSH-HPOneView/issues/97

David Claussen
Regular Advisor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

It is not. There are references to CRL files in both the release douments and the user manual, but nowhere does it show how to istall/import a CRL file.

David Claussen
Regular Advisor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

As you can see in my inital post, the CRL file is what my OneView shows as expired - that is why I would assume that I need to replace it. 

Dennis Handly
Acclaimed Contributor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

> the CRL file is what my OneView shows as expired

 

Hmm, except the date fields in a CRL don't have "expired" in them, just "next update".

David Claussen
Regular Advisor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

I don't know how much clearer I can get than this screen shot directly from my HPOneView appliance:

screenshot.47.jpg

David Claussen
Regular Advisor
Solution

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

Well I give up. No help for the CRL issue, no help for the impossible alerting configuration and no help for the LDAP cert issues. Six months wasted on the software. It is too bad really, the appliance is good, but no support is a deal breaker. I will go back to HP SIM.  OV appliance powered off and deleted.

Funny, I'm sure that if I was using the paid version of OneView, help would be in abundance.

Thanks HP.

PS: HP SIM will be in production for a quite a while. I spoke to an HP tech about SIM's EOL and he said that because there are so many customers still using servers below G7 - they have to keep is going. True or false, who know this is HP.

John Bigg
Esteemed Contributor

Re: OneView Alert: CRL issued by VeriSign Class 3 Public Primary Certification Authority - G5 is exp

To upload a CRL file, go to Settings -> Manage certificates and then click on the little green pen icon on the certificate where the CRL is expired. You can then either drag and drop the CRL file you downloaded or browse to it in order to upload it.

Note that the CRL file takes effect immediately, although it can take up to an hour for the manage certificates page to show an OK state rather than CRL Expired.