No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

HUAWEI CLOUD Stack 6.5.0 Troubleshooting Guide 02

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
How Do I Restore the ER or IR Certificate That Failed to Be Updated?

How Do I Restore the ER or IR Certificate That Failed to Be Updated?

When certificate update fails, restore the ER or IR certificate in a timely manner by using the backup certificate. This prevents Deployment Portal, Maintenance Portal, and Operation Portal login failures due to a certificate exception.

Precautions

  • When the old ER certificates are updated, the system automatically backs up the old ER certificates to the /opt/oss/manager/var/tmp/er_Random code directory on each Deploy node. For example, the directory is /opt/oss/manager/var/tmp/er_101011111.
  • When the old IR certificates are updated, the system automatically backs up the old IR certificates to the /opt/oss/manager/var/tmp/ir_Random code directory on each Deploy node. For example, the directory is /opt/oss/manager/var/tmp/ir_101011111.
  • The latest backup certificates are used for certificate restoration.
  • Services are automatically restarted so that the certificates can take effect after update. You are advised to perform this operation in off-peak hours.

Procedure

  1. Use PuTTY to log in to each Deploy node as the sopuser user in SSH mode.

    The default password is D4I$awOD7k.

  2. Run the following command to switch to the ossadm user:

    su - ossadm

  3. Run the following command to restore the IR certificate based on the type of the certificates that fails to be updated:

    cd /opt/oss/manager/apps/UniEPService/tools/common

    Table 23-3 Certificates to be restored

    Certificate Type

    Operation

    Restoring the ER certificates of Deploy nodes

    bash restorecertificate.sh -certtype er

    When information similar to the following is displayed, enter the serial number of Deployment Portal or the product and press Enter:

    Replacing the er certificates...please  waiting.
    1.management
    2.product name
    Please select the number of the product information:

    Restoring ER certificates of O&M and operation nodes

    Restoring IR certificates of ManageOne Deployment Portal, ManageOne Maintenance Portal, and ManageOne Operation Portal

    bash restorecertificate.sh -certtype internal

    The following information is displayed:

    Replacing the certificate will interrupt services. Are you sure you want to continue? (y/n):

  4. Enter y and press Enter.

    The system automatically stops the service, restores the certificates and then starts the service.
    • If the following information is displayed, the certificate has been restored.
      Certificates replaced successfully.
    • If other information is displayed, the certificate fails to be restored. Contact Huawei technical support.

Translation
Download
Updated: 2019-06-01

Document ID: EDOC1100062375

Views: 1747

Downloads: 12

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next