エラーmgmtgwd.certificate.expired:AIQUMクライアント証明書の期限切れが原因
環境
- Active IQ Unified Manager(AIQUM)
- ONTAP 9
問題
- ONTAPは
ERROR mgmtgwd.certificate.expired
またはERROR mgmtgwd.certificate.expiring
を 毎日レポートmgmtgwd.certificate.expired: A digital certificate with Fully Qualified Domain Name (FQDN) <AIQUM_SYSTEM_ID>, Serial Number <SERIAL_NO>, Certificate Authority '<AIQUM_SYSTEM_ID>' and type client for Vserver <CLUSTER_SVM> has expired.
mgmtgwd.certificate.expiring: A digital certificate with Fully Qualified Domain Name (FQDN) <AIQUM_SYSTEM_ID>, Serial Number <SERIAL_NO>, Certificate Authority '<AIQUM_SYSTEM_ID>' and type client for Vserver <CLUSTER_SVM> will expire in the next NN day(s).
certificate show -type client
ONTAPのコマンドが、AIQUM for EMSサブスクリプションによってインストールされたクライアント証明書の有効期限が切れていることを示している
cluster1::> certificate show -type client
(security certificate show)
Vserver Serial Number Certificate Name Type
---------- --------------- -------------------------------------- ------------
cluster1 2B5E4C41 f9a179e6-091b-4325-8fe1-59d5e6e9fdd1 client
Certificate Authority: f9a179e6-091b-4325-8fe1-59d5e6e9fdd1
Expiration Date: Tue Aug 29 21:05:19 2023
- System Managerで証明書を削除すると失敗します。
The certificate could not be removed due to the following conflicts: The certificate issued by "xxxxxxxxxxxxxxx" with serial number "xxxxxxx" is in use by the rest-api EMS destination "xxxxxxxxxxx" and cannot be removed.