<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trusted Certificate Authorities - admin - Expired in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Trusted-Certificate-Authorities-admin-Expired/m-p/462733#M45130</link>
    <description>&lt;P&gt;I got exactly the same problem, but I don't know how to re-issue the AIQUM certificate.&lt;/P&gt;&lt;P&gt;Besides, the AIQUM dashboard comes up with "Cluster discovery failed. Rediscover the cluster after resolving the issue" when started, but anyway the cluster is listed under Settings/Storage Management/Cluster Setup.&lt;/P&gt;&lt;P&gt;Rebooting AIQUM and rediscovering the cluster didn't have any effect.&lt;/P&gt;&lt;P&gt;I also tried the workaround described here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/data-mgmt/AIQUM/AIQUM-Issues/CAIQUM-5308" target="_blank"&gt;https://kb.netapp.com/data-mgmt/AIQUM/AIQUM-Issues/CAIQUM-5308&lt;/A&gt;&lt;/P&gt;&lt;P&gt;No luck either so I did a rollback.&lt;/P&gt;&lt;P&gt;Getting out of ideas, I'm&amp;nbsp;about to delete the AIQUM VM and reinstall it from scratch, but that might be a waste of time in case the cause of the problem lies somewhere else.&lt;/P&gt;&lt;P&gt;Two event log entries attached. The second one refers to an expired certificate of type server-ca, CA localhost, probably issued by NetApp which I'm also unable to renew. But that might be a completely different story. Or else we've got a general problem here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're running AIQUM 9.16 and a 2-node-cluster with ONTAP&amp;nbsp; 9.13.1P6&lt;/P&gt;</description>
    <pubDate>Thu, 14 Aug 2025 15:33:06 GMT</pubDate>
    <dc:creator>ThorstenP</dc:creator>
    <dc:date>2025-08-14T15:33:06Z</dc:date>
    <item>
      <title>Trusted Certificate Authorities - admin - Expired</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Trusted-Certificate-Authorities-admin-Expired/m-p/461807#M45050</link>
      <description>&lt;P&gt;In ONTAP 9.13.1, in the Trusted Certificate Authorities, one of them is named "admin." I vaguely understand this to be a built-in cert, but it's expired. The scope is at the cluster level, so I'm wondering what the implications are. Just doing a CSR for a CA-signed cert titled "admin" doesn't seem like best practice; but I was also led to believe that this principle may be tied to some critical components of the NetApp. That may be a misnomer given that the name is "admin" which is also the name of the local account. I could use some clarity on this; I'm a bit new to engineering NetApp.&lt;BR /&gt;&lt;BR /&gt;NOTE: Our NetApp is part of an air-gapped network.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 19:27:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Trusted-Certificate-Authorities-admin-Expired/m-p/461807#M45050</guid>
      <dc:creator>MooreCE</dc:creator>
      <dc:date>2025-07-02T19:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificate Authorities - admin - Expired</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Trusted-Certificate-Authorities-admin-Expired/m-p/461846#M45053</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/123402"&gt;@MooreCE&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From testing the Trusted Certificate Authority "admin" that has the Scope of "Cluster" and Type "Client CA" is created when an ONTAP cluster is connected to NetApp ActiveIQ Unified Manager.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do delete it then you just need to through a reissue of certificate from Unified Manager to connect to the NetApp ONTAP array otherwise the ONTAP array will show as not connected in Unified Manager.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is all within an air-gapped network also.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2025 23:39:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Trusted-Certificate-Authorities-admin-Expired/m-p/461846#M45053</guid>
      <dc:creator>chamfer</dc:creator>
      <dc:date>2025-07-08T23:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificate Authorities - admin - Expired</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Trusted-Certificate-Authorities-admin-Expired/m-p/462733#M45130</link>
      <description>&lt;P&gt;I got exactly the same problem, but I don't know how to re-issue the AIQUM certificate.&lt;/P&gt;&lt;P&gt;Besides, the AIQUM dashboard comes up with "Cluster discovery failed. Rediscover the cluster after resolving the issue" when started, but anyway the cluster is listed under Settings/Storage Management/Cluster Setup.&lt;/P&gt;&lt;P&gt;Rebooting AIQUM and rediscovering the cluster didn't have any effect.&lt;/P&gt;&lt;P&gt;I also tried the workaround described here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/data-mgmt/AIQUM/AIQUM-Issues/CAIQUM-5308" target="_blank"&gt;https://kb.netapp.com/data-mgmt/AIQUM/AIQUM-Issues/CAIQUM-5308&lt;/A&gt;&lt;/P&gt;&lt;P&gt;No luck either so I did a rollback.&lt;/P&gt;&lt;P&gt;Getting out of ideas, I'm&amp;nbsp;about to delete the AIQUM VM and reinstall it from scratch, but that might be a waste of time in case the cause of the problem lies somewhere else.&lt;/P&gt;&lt;P&gt;Two event log entries attached. The second one refers to an expired certificate of type server-ca, CA localhost, probably issued by NetApp which I'm also unable to renew. But that might be a completely different story. Or else we've got a general problem here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're running AIQUM 9.16 and a 2-node-cluster with ONTAP&amp;nbsp; 9.13.1P6&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2025 15:33:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Trusted-Certificate-Authorities-admin-Expired/m-p/462733#M45130</guid>
      <dc:creator>ThorstenP</dc:creator>
      <dc:date>2025-08-14T15:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificate Authorities - admin - Expired</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Trusted-Certificate-Authorities-admin-Expired/m-p/462883#M45137</link>
      <description>&lt;P&gt;If your mutual TLS certificate between AIQUM has expired you perform the following steps:&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;&lt;P&gt;In the AIQUM left navigation pane, click &lt;STRONG&gt;Storage Management&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Cluster Setup&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;On the &lt;STRONG&gt;Cluster Setup&lt;/STRONG&gt; page, select the cluster you want to edit, and then click &lt;STRONG&gt;Edit&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the &lt;STRONG&gt;Edit Cluster&lt;/STRONG&gt; dialog box, modify the values as required.&lt;BR /&gt;If you have modified the details for a cluster added to Unified Manager, you can view the certificate details for Mutual TLS communication, based on the ONTAP version. For more information about ONTAP version, see &lt;A href="https://docs.netapp.com/us-en/active-iq-unified-manager/storage-mgmt/task_add_clusters.html" target="_blank" rel="noopener"&gt;Certificates for Mutual TLS communication&lt;/A&gt;.&lt;BR /&gt;You can view the certificate details by clicking &lt;STRONG&gt;Certificate Details&lt;/STRONG&gt;. If the certificate is expired, click the &lt;STRONG&gt;Regenerate&lt;/STRONG&gt; button to incorporate the new certificate.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click &lt;STRONG&gt;Submit&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the Authorize Host dialog box, click &lt;STRONG&gt;View Certificate&lt;/STRONG&gt; to view the certificate information about the cluster.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click &lt;STRONG&gt;Yes&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 25 Aug 2025 23:02:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Trusted-Certificate-Authorities-admin-Expired/m-p/462883#M45137</guid>
      <dc:creator>chamfer</dc:creator>
      <dc:date>2025-08-25T23:02:24Z</dc:date>
    </item>
  </channel>
</rss>

