Note: The information in this article has changed. After additional testing, it was discovered that manually updating the trust package and appliance certificate was not sufficient. Content Analysis requires a software upgrade to do proper certificate validation during subscription downloads.
The Appliance Birth Registration Certificate Authority (ABRCA) root CA certificate is the ultimate root of trust for all appliance certificates that Symantec products use. Symantec has created a new ABRCA root CA certificate to replace the one expiring in December 2021. The new certificate will have an expiration date of December 31, 2037.
The continued operation of your Content Analysis appliances requires that you complete the following actions in a timely manner. To ensure the uninterrupted operation of your appliances, request a new appliance certificate and perform a software update as soon as possible to allow for adequate testing and troubleshooting before the certificate expires.
IMPORTANT: Plan to update your Content Analysis appliances as soon as possible to allow time for testing and troubleshooting. If you fail to update the appliances in a timely manner, they might experience failures as described in "Consequences of an Expired Appliance Certificate" below. In this case, upgrade to a supported Content Analysis release by November 2021 and update the appliance certificate as described in the following Resolution.
Note: To update Content Analysis applications on Integrated Secure Gateway (ISG), refer to Integrated Secure Gateway Birth Registration Certificate Authority (ABRCA) Root CA Certificate Update for instructions.
Monitor this KB article for any updates.
If the appliance certificate expires, certain appliance-to-back-end communications flows that use the appliance certificate for authentication might stop working correctly, including:
Other issues, yet to be identified, might also occur. To prevent these issues from occurring, perform the applicable steps described below as soon as possible.
If you fail to update your Content Analysis appliances before the root CA expires in December 2021, the appliances might experience failures as described above. To renew the certificate, follow the steps described in the Resolution section below.
To upgrade the ABRCA root certificate on the Content Analysis appliance:
Upgrade to a supported Content Analysis release ; see the following table.
IMPORTANT: All Content Analysis appliances must be updated to a supported version. Any previous versions will not be supported after November 2021.
Supported Release | Release Date |
Content Analysis 2.4.2.1 and later on S200 hardware appliances Note: Content Analysis 2.4.2.0 was previously released with the updated ABRCA root CA certificate. Version 2.4.2.0 is no longer available and is superseded by version 2.4.2.1. If you are currently running Content Analysis 2.4.2.0 or any earlier release, please upgrade to version 2.4.2.1. |
June 11, 2021 |
Content Analysis 3.1.2.4 and later on hardware appliances and virtual appliances Note: Content Analysis 3.1.2.2 was previously released with the updated ABRCA root CA certificate. For a better experience, please upgrade to version 3.1.2.4 instead. |
July 1, 2021 |
Note: If you are currently running Content Analysis 3.0 with an expired license, you must perform additional steps before upgrading to version 3.1. See Upgrade Steps for Content Analysis 3.0.
For upgrade instructions, refer to KB169313. You can download the software package from the Broadcom download portal.
Refer to the appropriate instructions to update the appliance certificate:
Note: Ensure that the appliance can access abrca.bluecoat.com for appliance certificate downloads.
To update the appliance certificate on a hardware appliance, log into the Content Analysis CLI and enter the following command:
CAS# request-appliance-certificate
ok
If the appliance is in a closed environment, see Update the Appliance Certificate in a Closed Environment.
Note: Ensure that the appliance can access abrca.bluecoat.com for appliance certificate downloads.
To update the appliance certificate on a virtual appliance (VA), log into the Content Analysis CLI and enter the following command:
CAS(config)# licensing load username <username> password <password>
ok
where <username> and <password> are your Broadcom licensing portal credentials.
If the appliance is in a closed environment, see Update the Appliance Certificate in a Closed Environment.
In a closed environment, you must manually download the license file and host it on a file server that the appliance can access, or install it inline.
To update the appliance certificate in a closed environment:
CAS(config)# licensing load url <url> passphrase <passphrase>
where <url> is the location of the file and <passphrase> is the passphrase you specified on the Support Portal.
Open the license file and copy its contents. Paste the contents using the following command.CAS(config)# licensing inline license-key passphrase <passphrase>
where <passphrase> is the passphrase you specified on the Support Portal.
After upgrading, verify that an appropriate trust package is installed. Use the following command in the Content Analysis CLI:
CAS# show ssl ca-certificate ABRCA_root
In the command output, look for the date beside 'valid-until'. The date should be December 31, 2037 or later.
If you are running a Content Analysis virtual appliance, confirm the application is using the new license file after the application has started.
To do this, in the Content Analysis CLI, view the bluecoat-appliance certificate details:
# show ssl keyring bluecoat-appliance
In the output, check the CN= value from the Certificate issuer. The certificate should contain the string "Virtual Appliance Birth Certificate Intermediate CA".
If you are currently running Content Analysis 3.0 with an expired license, additional steps are required before an upgrade to version 3.1 (if your license is not expired or if you upgraded version 3.0 successfully, these steps are not required).
To upgrade version 3.0 with an expired license, perform an appropriate workaround before updating the appliance certificate:
Perform these steps if a Content Analysis 2.x release is available in the list of currently installed systems for your appliance. This procedure requires a factory reset.
Before proceeding, make note of the VA serial number.
Note: You require a valid appliance certificate to perform these steps.
Note: After December 2021, this procedure will not work for virtual appliances.