Certificate Management, the Certificate is to Expire

Contents


1   Alarm Description

The alarm is raised when a certificate renewal is needed to prevent a secure service failure. The alarm is raised only if the node credential can cause interruption to the secure service.

Table 1    Certificate Management, the Certificate is to Expire Alarm Causes

Alarm Cause

Description

Fault Reason

Fault Location

Impact

The certificate is about to expire and is to be renewed

The number of days until the certificate expires is equal to or less than defined by the attribute expiryAlarmThreshold

The threshold for certificate expiration time has been crossed

Node credential

Secured service can fail, for example, Internet Protocol Security connection authenticated by expired certificate can fail

2   Procedure

2.1   Handle Alarm Certificate Management, the Certificate is to Expire

Prerequisites

Steps

  1. Navigate to the NodeCredential managed object given in the alarm, for example:

    >ManagedElement=NODE06ST,SystemFunctions=1,SecM=1,CertM=1,NodeCredential=1

  2. Check attribute renewalMode.

    (NodeCredential=1)>show renewalMode

    The following is an example output:

    renewalMode=MANUAL

  3. Select the appropriate action based on the result:
    • MANUAL – The alarm can be cleared by performing certificate renewal for the enrolled NodeCredential MO.
    • AUTOMATIC – Continue according to the instruction Certificate Management, Automatic Enrollment Failed instead. Further actions are outside the scope of this instruction.
  4. Based on the security policy, use the appropriate operation among the following to renew the node credential:
  5. Is the alarm cleared?

    Yes: Proceed with Step 8.

    No: Continue with the next step.

  6. Perform data collection, refer to Data Collection Guideline.
  7. Consult the next level of maintenance support. Further actions are outside the scope of this instruction.
  8. Job is completed.