Appliance Certificate Validation Status: CRITICAL - Certificate not installed
search cancel

Appliance Certificate Validation Status: CRITICAL - Certificate not installed

book

Article ID: 251035

calendar_today

Updated On:

Products

Reporter-VA

Issue/Introduction

When I look at new Reporter server system health I get this critical error:

 

xxxxxxxxxxxxx# health-monitoring view current

Health Monitoring current state of all metrics:

Last Check          | Metric Name
                    | State
--------------------+--------------------------------------------------------
2022-09-22 02:36:20 | Appliance Certificate Validation Status
                    | CRITICAL - Certificate not installed
--------------------+--------------------------------------------------------
2022-09-22 14:32:21 | CPU Utilization
                    | OK - 3.88%
--------------------+--------------------------------------------------------
2022-09-22 14:32:20 | License Server Communication Status
                    | OK
--------------------+--------------------------------------------------------
2022-09-22 14:32:22 | License Validation Status
                    | OK

 

Given there is no GUI except the more basic on in MC I am not clear on how to fix this problem.  Can you help?

Also I have successfully loaded some logs to Reporter, I can see them via the access-logs command, but Reporter has not done anything with them.  The Log Sources say they are unloaded (so is this what the problem is?) but the 'load' button doesn't do anything!  I'm using Chrome (launch console doesn't work in IE).  Please help

Environment

Release : 11.0.1.1

Component :

Resolution

Please be informed that the CRITICAL certificate error reported shows that the appliance certificate on the Reporter virtual appliance isn't installed.

To update the Virtual Appliance Certificate for Reporter, please refer to the resolution guidance/steps below.

Note: Ensure that the appliance can access abrca.bluecoat.com for appliance certificate downloads. To verify this, turn on PCAP of the reporter, ahead of running the solution command. For generating the PCAP on Reporter, please follow the guidance in the Tech. doc. with the URL below.

https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/reporter/11-0/Rptr_CLI/enable-mode-commands/c_pcap.html

abrca.bluecoat.com = 192.19.237.69

With Wireshark, check Statistics > Conversation > IPv4 to ensure that the appliance is able to communicate with abrca.bluecoat.com (192.19.237.69). It's important to also note the a successful DNS query/response, for abrca.bluecoat.com, is also a mandatory prerequisite, for communicating with abrca.bluecoat.com. Filter the DNS packets on Wireshark, to verify this. Another important note is to ensure the appliance knows how to (has a network route) talk to a DNS server.

With all of the above fully taken care of, and the PCAP started, proceed with running the solution command, to download and install the appliance certificate.

Resolution

To update the appliance certificate on a virtual appliance (VA), log into the Reporter CLI and enter the following command:

# licensing load username <username> password <password>
ok

where <username> and <password> are your Broadcom licensing portal credential

To ensure this works, after entering # licensing load username <username> password, hit the "enter" key on the keyboard, and in the next prompt, enter your password.

Ref. doc. https://knowledge.broadcom.com/external/article/207141/update-the-abrca-root-ca-certificate-on.html

If you do encounter any challenge and require further technical intervention, please note that sharing the evidences for the execution, including the raw exported PCAP file and your CLI commands execution, will be required on this ticket, for any further investigation.