Certificate renewal command overview

Last Updated : May 17, 2022 |

From System Manager Release 10.1.0.1 onwards, you can use the newly added command to renew the System Manager Identity (Server) certificates. The System Manager Certificate Authority (CA), the System Manager subordinate CA (SubCA), or a third-party CA (EJBCA) can sign the System Manager Identity certificates.

Run the certificate renewal command to issue new System Manager CA issued Identity certificates for all System Manager services. The new System Manager CA issued Identity certificates are valid for 730 days or from the time the command runs till the System Manager CA expiry date, whichever is lesser.

You must run the command with the -FORCE argument in any of the following scenarios:
  • If the System Manager services are secured using the third-party CA issued Identity certificates.

  • If there is a problem with the System Manager certificates causing the System Manager web console to be down.

If you run the certificate renewal command with -FORCE argument, the -FORCE argument replaces the third-party CA issued and System Manager issued certificates with the System Manager CA issued certificates.

Use the certificate renewal command only if certificate management is not possible through Services > Inventory > Manage Elements on the primary System Manager. The best practice is to perform all the certificate management operations from the System Manager web console.

In System Manager configured with Geographic Redundancy, if the primary and secondary System Manager certificates expire, you must first renew the certificates on the primary System Manager. Before you renew the certificates on the secondary System Manager, ensure that the primary System Manager web console is up and running and you can log in. If there are expired certificates on the secondary System Manager, you cannot issue the secondary System Manager certificates from the primary System Manager web console.

You can find the certificate renewal command logs at the following location: /var/log/Avaya/ folder

Important:

If your System Manager Certificate Authority expires, the command does not work. If the System Manager Certificate Authority expires or is nearing expiry, see the procedure in PSN005555u on the Avaya Support site.

You can run the certificate renewal command with the -FORCE argument or without any arguments.