Network Management

 View Only
last person joined: yesterday 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

CPPM Database cert

This thread has been viewed 32 times
  • 1.  CPPM Database cert

    Posted May 14, 2021 08:03 AM
    We've been using CPPM for some time now. Recently we noticed a message that the Database certificate had expired, so we obtained and installed a new one. However, now that the new cert is installed, we're no longer getting access to information like authentication tracking and there's 'database query error' message showing in the dashboard.

    Any idea of what we may have done wrong? We installed new server certs for RADIUS and HTTPS and haven't seen any issues with those - I can see in AirWave that users are authenticated and getting correct user roles. We used the same cert for all of these, but the DB one doesn't seem to be happy....

    ------------------------------
    Jon Koelker
    ------------------------------


  • 2.  RE: CPPM Database cert

    MVP GURU
    Posted May 14, 2021 08:50 AM
    Did you install database certificate across all of the nodes in the cluster?



    ------------------------------
    Dustin Burns
    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2021
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 3.  RE: CPPM Database cert

    Posted May 14, 2021 08:52 AM
    Hi, Dustin - we're a pretty small school district, so we only have one CPPM server - no cluster.

    ------------------------------
    Jon Koelker
    ------------------------------



  • 4.  RE: CPPM Database cert

    MVP GURU
    Posted May 14, 2021 08:59 AM
    Did you replace a self signed certificate with a publicly or internally signed certificate?

    Also, did you reboot the node after installing the certificate? If not, try rebooting. A change in DB certificate will only be applicable after a reboot of the node.

    ------------------------------
    Dustin Burns
    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2021
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 5.  RE: CPPM Database cert

    Posted May 14, 2021 09:04 AM
    We obtained our cert from Digicert. We didn't re-boot following the install. I wondered if that might be the issue. We plan on doing that after hours today. You think that should fix it?

    ------------------------------
    Jon Koelker
    ------------------------------



  • 6.  RE: CPPM Database cert
    Best Answer

    MVP GURU
    Posted May 14, 2021 09:11 AM
    It should. Also did you add the root and any intermediate certs to the trust store on CPPM for the authority you obtained the DB cert from?

    ------------------------------
    Dustin Burns
    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2021
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 7.  RE: CPPM Database cert

    Posted May 14, 2021 09:45 AM
    Hi, Dustin - I'm not sure of how that works. Our root CA cert and Intermediate cert (at least the ones that appear below the RADIUS and HTTPS server certs) are good to 2030, so we didn't replace them. And yes, Digicert does appear in the Trust List.

    ------------------------------
    Jon Koelker
    ------------------------------



  • 8.  RE: CPPM Database cert

    EMPLOYEE
    Posted May 14, 2021 10:13 AM
    Yes, as Dustin mentioned reboot is necessary after installing the DB cert. Also, event log will be the best place to check while installing as it will display message when the certificate is installed successfully or face any issue. Once you install it, give it sometime before reboot(monitor the event log).

    ------------------------------
    Vishnu Mannil
    Aruba ERT

    If my post addresses your query, give kudos :)
    ------------------------------



  • 9.  RE: CPPM Database cert

    Posted May 14, 2021 11:59 AM
    Thanks for the info, gentlemen - much appreciated. We'll be giving the server a re-start this evening and take a look at how it goes from there.

    ------------------------------
    Jon Koelker
    ------------------------------