<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic questions about the certificate renew in ontap cluster. in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436491#M9734</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;we get error messages as below:&lt;/P&gt;&lt;P&gt;This message occurs when a digital certificate for a Vserver is about to expire. Client-server communication will not be secure if the certificate expires.&lt;/P&gt;&lt;P&gt;Install a new digital certificate on the system using the 'security certificate create' or 'security certificate install' command.&lt;/P&gt;&lt;P&gt;[version]&lt;/P&gt;&lt;P&gt;ontap cluster mode&lt;BR /&gt;OS Version: 9.8P5&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[my analysis]&lt;/P&gt;&lt;P&gt;I found some Self-Signed SSL certificate will expire,and i recommend the below KB.&lt;BR /&gt;---------------&lt;BR /&gt;How to renew a Self-Signed SSL certificate in ONTAP 9&lt;BR /&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_renew_a_Self-Signed_SSL_certificate_in_ONTAP_9.10.0_and_earlier" target="_blank" rel="noopener"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_renew_a_Self-Signed_SSL_certificate_in_ONTAP_9.10.0_and_earlier&lt;/A&gt;&lt;BR /&gt;---------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;but the user also stated that they have other certificates will Expiration.&lt;BR /&gt;and would like to know how to review it .&lt;/P&gt;&lt;P&gt;it seems that the below certificate is not a Self-Signed SSL certificate,&lt;/P&gt;&lt;P&gt;Q1:could you please provide information how to determine if it's a Self-Signed SSL certificate or a CA certificate ?&lt;BR /&gt;Q2:Could you please share detall info how to renew the CA certificate.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;the example is as blow:&lt;/P&gt;&lt;P&gt;------------------- removed private info - AD ------------&lt;/P&gt;&lt;P&gt;=====================================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards&lt;/P&gt;&lt;P&gt;terry&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 09:59:03 GMT</pubDate>
    <dc:creator>Terry-xiao</dc:creator>
    <dc:date>2025-06-04T09:59:03Z</dc:date>
    <item>
      <title>questions about the certificate renew in ontap cluster.</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436491#M9734</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;we get error messages as below:&lt;/P&gt;&lt;P&gt;This message occurs when a digital certificate for a Vserver is about to expire. Client-server communication will not be secure if the certificate expires.&lt;/P&gt;&lt;P&gt;Install a new digital certificate on the system using the 'security certificate create' or 'security certificate install' command.&lt;/P&gt;&lt;P&gt;[version]&lt;/P&gt;&lt;P&gt;ontap cluster mode&lt;BR /&gt;OS Version: 9.8P5&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[my analysis]&lt;/P&gt;&lt;P&gt;I found some Self-Signed SSL certificate will expire,and i recommend the below KB.&lt;BR /&gt;---------------&lt;BR /&gt;How to renew a Self-Signed SSL certificate in ONTAP 9&lt;BR /&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_renew_a_Self-Signed_SSL_certificate_in_ONTAP_9.10.0_and_earlier" target="_blank" rel="noopener"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_renew_a_Self-Signed_SSL_certificate_in_ONTAP_9.10.0_and_earlier&lt;/A&gt;&lt;BR /&gt;---------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;but the user also stated that they have other certificates will Expiration.&lt;BR /&gt;and would like to know how to review it .&lt;/P&gt;&lt;P&gt;it seems that the below certificate is not a Self-Signed SSL certificate,&lt;/P&gt;&lt;P&gt;Q1:could you please provide information how to determine if it's a Self-Signed SSL certificate or a CA certificate ?&lt;BR /&gt;Q2:Could you please share detall info how to renew the CA certificate.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;the example is as blow:&lt;/P&gt;&lt;P&gt;------------------- removed private info - AD ------------&lt;/P&gt;&lt;P&gt;=====================================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards&lt;/P&gt;&lt;P&gt;terry&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:59:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436491#M9734</guid>
      <dc:creator>Terry-xiao</dc:creator>
      <dc:date>2025-06-04T09:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: questions about the certificate renew in ontap cluster.</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436496#M9735</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/94406"&gt;@Terry-xiao&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q1) Your answer is in your output, its not self-signed as its signed by "[Deleted by moderator]"&lt;/P&gt;&lt;P&gt;Q2) Check this KB &lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_install_a_Certificate_Authority_(CA)_signed_certificate_in_ONTAP_for_System_Manager_use" target="_blank" rel="noopener"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_install_a_Certificate_Authority_(CA)_signed_certificate_in_ONTAP_for_System_Manager_use&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 04:01:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436496#M9735</guid>
      <dc:creator>chamfer</dc:creator>
      <dc:date>2022-07-13T04:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: questions about the certificate renew in ontap cluster.</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436499#M9736</link>
      <description>&lt;P&gt;Hi Chamfer,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much for your update.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Even in my test environment I'm building now, there are 89 entries, but it seems this certificates&lt;BR /&gt;are not intentionally registered, but is automatically generated and registered arbitrarily.&lt;BR /&gt;(Attach log) So i 'm not sure if we need ask user&amp;nbsp; to revew these certificates as the KB suggested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_install_a_Certificate_Authority_(CA)_signed_certificate_in_ONTAP_for_System_Manager_use" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_install_a_Certificate_Authority_(CA)_signed_certificate_in_ONTAP_for_System_Manager_use&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards&lt;/P&gt;&lt;P&gt;wenhai&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 09:38:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436499#M9736</guid>
      <dc:creator>Terry-xiao</dc:creator>
      <dc:date>2022-07-07T09:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: questions about the certificate renew in ontap cluster.</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436633#M9737</link>
      <description>&lt;P&gt;Hi Wenhai,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok, I do understand where you are coming from, but I think you are getting confused between the different types of certificates that ONTAP can configured with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Effectively&lt;SPAN&gt;&amp;nbsp;there are three types of certificates you can have on ONTAP:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Public Root Certificates (From ONTAP truststore)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;CA signed certificates, could be internal company CA or external CA body (e.g. Entrust) and they are provisioned by first going through the CSR process.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Self Signed certificates, where ONTAP generates its own certificates using the respective SVM CA.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificates that you are seeing are root CA certificates as part of ONTAP truststore, which was introduced in ONTAP 9.2.&amp;nbsp; See more here&amp;nbsp;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/What_is_the_Certificate_Truststore_in_ONTAP" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/What_is_the_Certificate_Truststore_in_ONTAP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Truststore Certificates are automatically updated as needed as part of every ONTAP release, but you are free to delete them if you do not use them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Back to you original question:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If you have root CA certificates expiring, upgrading ONTAP will resolve this OR you could just delete them.&lt;/LI&gt;&lt;LI&gt;If you have CA signed certificates you need to go through the CSR process to get new certificates&lt;/LI&gt;&lt;LI&gt;If you have self-signed certificates expiring go through the process&amp;nbsp;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_renew_a_Self-Signed_SSL_certificate_in_ONTAP_9.10.0_and_earlier" target="_blank" rel="noopener noreferrer"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_renew_a_Self-Signed_SSL_certificate_in_ONTAP_9.10.0_and_earlier&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I hope that this helps/make sense.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 02:05:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436633#M9737</guid>
      <dc:creator>chamfer</dc:creator>
      <dc:date>2022-07-13T02:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: questions about the certificate renew in ontap cluster.</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436639#M9738</link>
      <description>&lt;P&gt;Also for those reading this in the future there are three commands to view the certificates on ONTAP:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;security certificate show-generated&lt;/LI&gt;&lt;LI&gt;security certificate show-truststore&lt;/LI&gt;&lt;LI&gt;security certificate show-user-installed&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 13 Jul 2022 04:32:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/436639#M9738</guid>
      <dc:creator>chamfer</dc:creator>
      <dc:date>2022-07-13T04:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: questions about the certificate renew in ontap cluster.</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/437057#M9740</link>
      <description>&lt;P&gt;Hi ,thanks very much for update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding "&lt;SPAN&gt;The Truststore Certificates are automatically updated as needed as part of every ONTAP release,”&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;if the system is running version ontap 9.8P5,and update it to the 9.8P12,does the expired one will updaded by ontap version up ? do we need to update the current version to the latest one 9.10.1 to update the certificate?&lt;/P&gt;&lt;P&gt;Also can we perform this version up before any "Truststore Certificate" will expire?&lt;/P&gt;&lt;P&gt;Thanks and regards&lt;BR /&gt;Terry&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 01:30:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/questions-about-the-certificate-renew-in-ontap-cluster/m-p/437057#M9740</guid>
      <dc:creator>Terry-xiao</dc:creator>
      <dc:date>2022-08-02T01:30:55Z</dc:date>
    </item>
  </channel>
</rss>

