Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

SSL issues

APC UPS Data Center & Enterprise Solutions Forum

Schneider, APC support forum to share knowledge about installation and configuration for Data Center and Business Power UPSs, Accessories, Software, Services.

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • APC UPS, Critical Power, Cooling and Racks
  • APC UPS Data Center & Enterprise Solutions Forum
  • SSL issues
Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Mute
  • Printer Friendly Page
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Experts
User Count
BillP
Administrator BillP Administrator
5060
voidstar_apc
Janeway voidstar_apc
196
Erasmus_apc
Sisko Erasmus_apc
112
TheNotoriousKMP_apc
Sisko TheNotoriousKMP_apc
108
View All

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Solved Go to Solution
Back to APC UPS Data Center & Enterprise Solutions Forum
Solved
Anonymous user
Not applicable

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

0 Likes
7
2360
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

SSL issues

Having gone through the ordeal of upgrading the firmware on our AP7900 rack-mount PDUs so that they actually work with modern browsers, I am now attempting to upload proper SSL certificates, and am unable to get past the error code -32 on your software. The certificate is being issued from OpenSSL, and I've tried removing anything beyond the very basic stuff (subjectAltName, etc.)

It's become clear that the SSL implementation on these devices is a fragile hack job, and it would be nice to see a detailed list of things that will cause it problems posted somewhere. I'll paste the signed certificate below and would appreciate any feedback on what could be "wrong."

-----BEGIN CERTIFICATE-----
MIIDuDCCAqCgAwIBAgIJAJNgZffPbRl9MA0GCSqGSIb3DQEBCwUAMIGwMQswCQYD
VQQGEwJDQTEQMA4GA1UECAwHT250YXJpbzEQMA4GA1UEBwwHVG9yb250bzEtMCsG
A1UECgwkUG9pbnQgb2YgUHJlc2VuY2UgVGVjaG5vbG9naWVzLCBJbmMuMRYwFAYD
VQQLDA1JVCBEZXBhcnRtZW50MRUwEwYDVQQDDAxQb2ZQIFJvb3QgQ0ExHzAdBgkq
hkiG9w0BCQEWEG1uZXd0b25AcG9mcC5jb20wHhcNMTYwNTI4MDMzNzE0WhcNMjYw
NTI2MDMzNzE0WjBrMQswCQYDVQQGEwJDQTEQMA4GA1UECBMHT250YXJpbzEtMCsG
A1UEChMkUG9pbnQgb2YgUHJlc2VuY2UgVGVjaG5vbG9naWVzLCBJbmMuMRswGQYD
VQQDExJhcGMxLnBvZnAuaW50ZXJuYWwwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJ
AoGBAL+HaXcq0Ff0tMeSqqAv/ohc1SCfsUTNbBdYxCPNyt6P0J0HCjvuK7/fVoXj
iPp/Wu+HXpuqFpxNx3kCH9G+ZFo+ZW70KOF25pcuY+HWo5psvkGiWKJbomA9mtRb
ymbo7hzf7lWTZzDK0eVFfzLgUG/dEqyPAi5IRoNqdtZ32IhvAgMBAAGjgZwwgZkw
DAYDVR0TAQH/BAIwADAsBglghkgBhvhCAQ0EHxYdT3BlblNTTCBHZW5lcmF0ZWQg
Q2VydGlmaWNhdGUwHQYDVR0OBBYEFET+IRCTByjxJLo4eOw6Otbvmv9eMB8GA1Ud
IwQYMBaAFJPcfeAF85zYZY3bZvEqEkoczsSjMBsGA1UdEQQUMBKBEG1uZXd0b25A
cG9mcC5jb20wDQYJKoZIhvcNAQELBQADggEBAHXP6klemNx2Qi8zbRBlBAZViNSn
JqTC6Xo8AaVtN7v56AmwAlFsqFbRAe08cKyW1SLOzYoz8HscBNMGfru8SmobwEYm
EWRWEcGa0GwBX6Nq6DY/EhQejN30yw0EK0QS7R7Vc1H2Ye+ijgNSef7u6ilSYaLw
jIgCvpwTC6tBGXz6iVRnyDrhnTQBx/SPUnZ2KrBenihPRNWLtO0ffFzYTcQVaR/Q
FuTim5kaKYrbJOzRAknGlqOZvRi3f+XlVNpwcijqYMxnvaKOt/7WlNcsDYyXxBkq
QVmpn2eh+jhoyMwzXXeL0qPXaBhpodMtp1maTQZzDkCd99fISLrKhUG32WE=
-----END CERTIFICATE-----

Labels
  • Labels:
  • Racks, Rack Accessories, & Cooling
Reply

Link copied. Please paste this link to share this article on your social media post.

  • All forum topics
  • Previous Topic
  • Next Topic

Accepted Solutions
Benji_apc
Ensign Benji_apc
Ensign

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

0 Likes
0
2359
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

I can just chime in.

Please APC, finally fix your SSL issues, we have 2016!

See Answer In Context

Reply

Link copied. Please paste this link to share this article on your social media post.

Replies 7
Terry_Kennedy_apc
Commander Terry_Kennedy_apc
Commander

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

0 Likes
0
2359
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

I don't think the APC stuff is particularly fragile, just very unusual (and in the case of the Security Wizard, unpleasant). Remember, the CPU in that generation of management card is rather underpowered for SSL in general and modern ciphers in particular. That is presumably what caused the design decision to do everything in a PC utility (the APC Security Wizard) instead of the more usual "generate a CSR on the device itself".

I assume the error -32 you mention is from the Security Wizard? If you're getting any sort of error on the device itself, it is usually from either loading a certificate with a longer-than-1024 key length or trying to give it something that hasn't been pre-digested by the Security Wizard.

Can you describe the exact order of steps you went through to generate the error?

Reply

Link copied. Please paste this link to share this article on your social media post.

Anonymous user
Not applicable

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

0 Likes
0
2359
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

For a product purchased 2 years ago, I'm very unimpressed with that CPU and the lack of modern crypto support.

Not dealing with the device yet, just trying to get through the software. I've downloaded the CSR and signed it in OpenSSL as I've done with literally hundreds of other devices. Now getting the error when I try to put the signed certificate back into the APC software.

Reply

Link copied. Please paste this link to share this article on your social media post.

Terry_Kennedy_apc
Commander Terry_Kennedy_apc
Commander

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

0 Likes
0
2359
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

The limitations of the CPU were probably known going back to when those cards were designed. But the world was a different place and there was less emphasis on SSL then, and certainly the broswer authors weren't in a race to see who could break the most features in the shortest amount of time back then, either.

If the hundreds of other devices weren't APC, then you've never dealt with the APC Security Wizard. I have attached 3 short videos showing the creation of a CSR from the Security Wizard, creating the certificate on a Unix box with OpenSSL, then using the Security Wizard to import it and create the .p15 file the APC device wants. Note that you can't just type text into the "File name" text box as I do halfway through the second SecWiz video - you have to enter it in the Browse picker box or things won't work right.

I use an IP address as the CN, since these NMC cards will rewrite http://ups.example.com to https://192.168.100.117 if they have SSL enabled, so using the actual FQDN as the common name will give you "issued to a different server" SSL warnings in your browser.

 

 

Attachments
Reply

Link copied. Please paste this link to share this article on your social media post.

Anonymous user
Not applicable

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

0 Likes
0
2359
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

I know how it's supposed to work, it just isn't. Posting here is a last resort, I can assure you I did my homework beforehand. Using the software to generate a CSR, signing it with my OpenSSL CA, trying to import it back into the software. It doesn't like something about the certificate, and it would be nice if it told me what.

I think we'll just stick with SSH and plan to replace these devices. The state of security "back then" is no excuse for the fact that these devices are sold today with 15-year-old encryption standards.

Reply

Link copied. Please paste this link to share this article on your social media post.

Benji_apc
Ensign Benji_apc
Ensign

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

0 Likes
0
2360
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:59 PM

I can just chime in.

Please APC, finally fix your SSL issues, we have 2016!

Reply

Link copied. Please paste this link to share this article on your social media post.

BillP
Administrator BillP Administrator
Administrator

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:58 PM

0 Likes
0
2359
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:58 PM

We are listening and working on a few things including a new, updated Security Wizard and a Wizard version that supports mass creation of CSR as well as mass import of signed certs through a CLI version of the wizard which can be scripted.

Reply

Link copied. Please paste this link to share this article on your social media post.

Anonymous user
Not applicable

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:58 PM

0 Likes
0
2359
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-06-27 11:42 PM . Last Modified: ‎2024-03-18 11:58 PM

Hey all,
Because installing private SSL's on NMC is a reoccurring theme, I decided to create a discussion after some progress was made during a support chat.

https://forums.apc.com/spaces/7/ups-management-devices-powerchute-software/forums/general/95305/uplo...

Reply

Link copied. Please paste this link to share this article on your social media post.

Preview Exit Preview

never-displayed

You must be signed in to add attachments

never-displayed

 
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of