ASM REST API giving ssl host mismatch after recent ASM patching
search cancel

ASM REST API giving ssl host mismatch after recent ASM patching

book

Article ID: 235578

calendar_today

Updated On:

Products

CA App Synthetic Monitor

Issue/Introduction

We monitor the APi endpoint https://api.asm.ca.com/1.6

 

We noticed after the ASM release, we are getting SSL errors on this page:

 

MismatchCert (Hostname mismatch) Blocked by SSL_HOST_MISMATCH

The destination api.asm.ca.com is not reachable.
Contact your IT administrator with the following error:

mode='CLIENT', lname='st-gateway-proxy', <***redact***>, sni='api.asm.ca.com', fd='238085', Hostname 'api.asm.ca.com' didn't match certificate info, issuer='/C=US/O=DigiCert Inc/CN=DigiCert SHA2 Secure Server CA', subject='/C=US/ST=California/L=San Jose/O=Broadcom Inc/OU=saas.broadcom.com/CN=*.asm.saas.broadcom.com', notbefore='Jun 5 00:00:00 2020 GMT', notafter='Jun 6 12:00:00 2022 GMT', serial='0B73FED5222CC2FE135A73A797224BA8', altnames='DNS:asm.saas.broadcom.com, DNS:*.asm.saas.broadcom.com'

Environment

Release : SAAS

Component : CA APP SYNTHETIC MONITOR (WATCHMOUSE)

Resolution

Reason why the https://api.asm.ca.com/1.6 is not working anymore was due to a planned maintenance (link is below).  If you are not already subscribed, I would strongly recommend going to https://asm.status.broadcom.com and clicking on the red subscribe button at the top right hand side.

Also all master account email addresses in ASM were emailed the planned maintenance as well.  However subaccounts do not receive it, so best practice for subaccounts to also subscribe to the above mentioned.

 

https://asm.status.broadcom.com/incidents/2kvhc708rv5c

Impact
During the maintenance window, the User Interface (UI), API and scheduling of checks will not be available. Redirection from the old domains *.asm.ca.com will also stop working after the maintenance. Only the current domains *.asm.saas.broadcom.com will be functional.