Browser error "NET::ERR_CERT_AUTHORITY_INVALID" when trying to use MTC-M with Self-Signed Certificates Stored in USS Files (TrustStore)
search cancel

Browser error "NET::ERR_CERT_AUTHORITY_INVALID" when trying to use MTC-M with Self-Signed Certificates Stored in USS Files (TrustStore)

book

Article ID: 264506

calendar_today

Updated On:

Products

Vantage Storage Resource Manager

Issue/Introduction

After upgrading to MTC-M 14.1.2 and setting up SSL access using self-signed certificates (USS Files - TrustStore), the following error is received in the Chrome browser when trying to connect to MTC-M: 

NET::ERR_CERT_AUTHORITY_INVALID

After receiving this error, clicking the 'Advanced' button allows the connection to be made; however, the connection is not secure (i.e., HTTP versus HTTPS).  

How can this be fixed? 

Environment

Release : 14.1

Cause

Self-signed certificates are not supported in MTC-M.  

Resolution

When the message "NET::ERR_CERT_AUTHORITY_INVALID" appears when trying to connect to the MTC-M HTTPS address, it is possible to still proceed to the target webpage (such as by clicking the 'Advanced' button).  This message is issued as a result of the browser not supporting Self-Signed Certificates.  Today it is not possible for Vantage to bypass this error (but in the past this was possible by importing such certificates and using them as being valid). The only way to avoid this situation is to use a certificate from a valid authority, and not use self-signed certificates.  To implement this change to avoid these issues it is recommended to store certificates in a SAF Keyring.  Further documentation on this setup using a SAF keyring can be found here.  ((Recommended) Enable HTTPS with Certificates Stored in SAF Keyring)

Additional Information

(