<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: mgmtgwd.certificate.expired: A digital certificate with Fully Qualified Domain Name (FQDN) snap, in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/mgmtgwd-certificate-expired-A-digital-certificate-with-Fully-Qualified-Domain/m-p/463542#M45176</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/122909"&gt;@Vipul_Nagar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just renewing the self-signed certificate does essentially nothing if you don't replace the old certificate on the SVM with the new one.&amp;nbsp; "&lt;STRONG&gt;&lt;SPAN class=""&gt;You should manually remap applications associated with the old certificate to be associated with the new certificate.&lt;/SPAN&gt;&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to understand&amp;nbsp;&lt;STRONG&gt;What is using the certificate on your SVM named "backup_svm"?&lt;/STRONG&gt; If you have an application that is expecting a certificate from a specific CA or where you need to generate, export from ONTAP, and import to your backup product.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you have generated your self-signed certificate you need to apply it.&amp;nbsp; CLI command reference is here&amp;nbsp;&lt;A href="https://docs.netapp.com/us-en/ontap-cli/security-ssl-modify.html" target="_blank"&gt;security ssl modify&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The commands would be something like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ssl modify -vserver backup_svm -ca &amp;lt;CA&amp;gt; -serial &amp;lt;SERIAL&amp;gt; -common-name &amp;lt;common-name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Oct 2025 21:28:07 GMT</pubDate>
    <dc:creator>chamfer</dc:creator>
    <dc:date>2025-10-08T21:28:07Z</dc:date>
    <item>
      <title>mgmtgwd.certificate.expired: A digital certificate with Fully Qualified Domain Name (FQDN) snap, Ser</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/mgmtgwd-certificate-expired-A-digital-certificate-with-Fully-Qualified-Domain/m-p/463487#M45175</link>
      <description>&lt;P&gt;&lt;FONT face="batang,apple gothic" size="2"&gt;Hi Team&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" size="2"&gt;I'm getting below event on my OnTap which is running on 9.15.*.*&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" size="2"&gt;&lt;SPAN&gt;"mgmtgwd.certificate.expired: A digital certificate with Fuly Qualified Domain Name (FQDN) snap, Serial Number 173B18A666E8BCBF, Certificate Authority 'snap' and type server for Vserver backup_svm has expired."&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" size="2"&gt;As I know how to renew by my concern while renewing its giving below popup so just want to confirm if i simply renew it will&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic" size="2"&gt;it impact my OnTap&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;H3&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Renew client/server certificate&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;The existing certificate won't be deleted, but a copy of the certificate will be created. You should manually remap applications associated with the old certificate to be associated with the new certificate.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Existing certificate name&lt;/STRONG&gt;&lt;/FONT&gt; &lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;snap_173B18A666E8BCBF&lt;/STRONG&gt;&lt;/FONT&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Please suggest&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 08 Oct 2025 11:31:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/mgmtgwd-certificate-expired-A-digital-certificate-with-Fully-Qualified-Domain/m-p/463487#M45175</guid>
      <dc:creator>Vipul_Nagar</dc:creator>
      <dc:date>2025-10-08T11:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: mgmtgwd.certificate.expired: A digital certificate with Fully Qualified Domain Name (FQDN) snap,</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/mgmtgwd-certificate-expired-A-digital-certificate-with-Fully-Qualified-Domain/m-p/463542#M45176</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/122909"&gt;@Vipul_Nagar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just renewing the self-signed certificate does essentially nothing if you don't replace the old certificate on the SVM with the new one.&amp;nbsp; "&lt;STRONG&gt;&lt;SPAN class=""&gt;You should manually remap applications associated with the old certificate to be associated with the new certificate.&lt;/SPAN&gt;&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to understand&amp;nbsp;&lt;STRONG&gt;What is using the certificate on your SVM named "backup_svm"?&lt;/STRONG&gt; If you have an application that is expecting a certificate from a specific CA or where you need to generate, export from ONTAP, and import to your backup product.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you have generated your self-signed certificate you need to apply it.&amp;nbsp; CLI command reference is here&amp;nbsp;&lt;A href="https://docs.netapp.com/us-en/ontap-cli/security-ssl-modify.html" target="_blank"&gt;security ssl modify&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The commands would be something like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ssl modify -vserver backup_svm -ca &amp;lt;CA&amp;gt; -serial &amp;lt;SERIAL&amp;gt; -common-name &amp;lt;common-name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 21:28:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/mgmtgwd-certificate-expired-A-digital-certificate-with-Fully-Qualified-Domain/m-p/463542#M45176</guid>
      <dc:creator>chamfer</dc:creator>
      <dc:date>2025-10-08T21:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: mgmtgwd.certificate.expired: A digital certificate with Fully Qualified Domain Name (FQDN) snap,</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/mgmtgwd-certificate-expired-A-digital-certificate-with-Fully-Qualified-Domain/m-p/463548#M45179</link>
      <description>&lt;P&gt;i Chamfer,&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;I had a follow-up question regarding the &lt;STRONG&gt;certification renewal process&lt;/STRONG&gt;. While renewing, I received a &lt;STRONG&gt;notification&lt;/STRONG&gt; (as shown in my previous post). If I choose to &lt;STRONG&gt;ignore this notification and proceed&lt;/STRONG&gt;, will it have any impact on the certification status or functionality?&lt;/P&gt;&lt;P&gt;If there is any impact, could you please share a &lt;STRONG&gt;KB article or documentation&lt;/STRONG&gt; that provides more clarity on this?&lt;/P&gt;&lt;P&gt;Thanks again for addressing this question.&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Vipul Nagar&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 07:28:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/mgmtgwd-certificate-expired-A-digital-certificate-with-Fully-Qualified-Domain/m-p/463548#M45179</guid>
      <dc:creator>Vipul_Nagar</dc:creator>
      <dc:date>2025-10-09T07:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: mgmtgwd.certificate.expired: A digital certificate with Fully Qualified Domain Name (FQDN) snap,</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/mgmtgwd-certificate-expired-A-digital-certificate-with-Fully-Qualified-Domain/m-p/463638#M45187</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/122909"&gt;@Vipul_Nagar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you choose to ignore the notification and proceed, there could potentially be no impact for functionality.&amp;nbsp; For example if you are using NFS v3 on the SVM it wouldn't matter if a TLS certificate expired...... though if you are using NFS over TLS or S3 with HTTPS then you could have a disruption, depending on the client(s) settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a NetApp KB article which does provide some information&amp;nbsp;&lt;A href="https://kb.netapp.com/on-prem/ontap/DM/Encryption/Encryption-KBs/What_is_the_impact_of_an_expired_digital_certificate_used_for_a_Vserver" target="_blank"&gt;What is the impact of an expired digital certificate used for a Vserver? - NetApp Knowledge Base&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the end of the day you need to understand what protocols you are using and are they using TLS...... Also don't forget non client protocols like LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 21:47:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/mgmtgwd-certificate-expired-A-digital-certificate-with-Fully-Qualified-Domain/m-p/463638#M45187</guid>
      <dc:creator>chamfer</dc:creator>
      <dc:date>2025-10-14T21:47:45Z</dc:date>
    </item>
  </channel>
</rss>

