EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 01:52 PM . Last Modified: 2024-04-08 01:29 AM
Hello,
I attempted to replace the ssl certificate on DCO version 7.4 using the below:
After the installation, apache2 web service would not start and generated the below logs:
[Mon Mar 13 19:08:28 2017] [error] Init: Unable to read server certificate from file /etc/isx-operations/ssl/certificate.crt
[Mon Mar 13 19:08:28 2017] [error] SSL Library Error: 218529960 error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag
[Mon Mar 13 19:08:28 2017] [error] SSL Library Error: 218595386 error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error
[Mon Mar 13 19:08:49 2017] [error] Init: Unable to read server certificate from file /etc/isx-operations/ssl/certificate.crt
[Mon Mar 13 19:08:49 2017] [error] SSL Library Error: 218529960 error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag
[Mon Mar 13 19:08:49 2017] [error] SSL Library Error: 218595386 error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error
We disabled SSL on the server and were able to restart the apache2 service. Any help to get SSL working with the new certificate would be great.
Thanks!
(CID:114231008)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 01:52 PM . Last Modified: 2024-04-08 01:28 AM
Hi Operations Center
Happy to help - but before we begin I have a question for you:
May I ask you why you are on 7.4? 7.4 is vulnerable to all the vulnerabilities listed here:
StruxureWare Data Center Operation Software Vulnerability Fixes
As you can see this is quite serious from a cybersecurity point of view.
All of this is fixed on the latest release which is DCO 8.0. Also this version comes with numerous bug fixes as well as performance improvements.
Regards
Anders
(CID:114231039)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 01:52 PM . Last Modified: 2024-04-08 01:28 AM
Hi Anders,
We will upgrade our instance of DCO later this year as we would like to take advantage of the new functionalities available in the latest release. But for now, we would like to get SSL working. Can you provide some assistance?
Thanks!
(CID:114231058)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 01:52 PM . Last Modified: 2024-04-08 01:28 AM
Hi
One of the most common issues I have seen in the past is if the certificate key should be in un-expected format, then the system would be unable to read the applied certificate. However as Anders has kindly described, it is highly recommended to "upgrade"/move the product to latest version (currently 8.0.4). The great 8.x contains huge enhancements including software vulnerability fixes. "Upgrading" DCO 7.4 to 8.x is really easy, it can be done in two quick steps: a) fresh installation of 8.x on a server, b) and then restoring the latest backup file (from 7.4), thanks.
Kind regards
(CID:114231634)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 01:53 PM . Last Modified: 2024-04-08 01:28 AM
May I add to that that adding a SSL Certificate is significantly easier (less error prone) on DCO 8.x. More details here:
Changing SSL certificate on the server
(CID:114231637)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 01:53 PM . Last Modified: 2023-10-22 01:40 AM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.