<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Switch can't connect to HiveManager! Get following message: Peer certificate cannot be authenticated with given CA certifcates. in Aerohive Migrated Content</title>
    <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84895#M10456</link>
    <description>&lt;P&gt;Our HiveManager is resolved by a public IPv4 address and our customers devices reach HM by redirector &amp;amp;  public ip. We have accesspoints connected to these switches at the customer site and they get connected to our HM but not switches. &lt;/P&gt;</description>
    <pubDate>Tue, 08 Oct 2019 20:29:23 GMT</pubDate>
    <dc:creator>benjamin_heravi</dc:creator>
    <dc:date>2019-10-08T20:29:23Z</dc:date>
    <item>
      <title>Switch can't connect to HiveManager! Get following message: Peer certificate cannot be authenticated with given CA certifcates.</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84893#M10454</link>
      <description>&lt;P&gt;I have three SR2224P  switches and they fail to get connected to HiveManager. I get the following message when I  check the  Hivemanager status:  &lt;I&gt;"Peer certificate cannot be authenticated with given CA certifcates&lt;/I&gt;". What could be the reson? &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: I updated the HiveAgent to 1.1.19.0 , OS version is 1.0.1.26, have google dns and aerohive sntp  is configured (checked time) on all switches but still have the same problem.  &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 14:57:08 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84893#M10454</guid>
      <dc:creator>benjamin_heravi</dc:creator>
      <dc:date>2019-10-08T14:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Switch can't connect to HiveManager! Get following message: Peer certificate cannot be authenticated with given CA certifcates.</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84894#M10455</link>
      <description>&lt;P&gt;Can you tell me if your HiveManager is resolved to a private IPv4 address or a public IPv4 address? I ask because we've seen this issue with HiveManagers resolving to a public address, which is an unsupported design, so we will need to verify that the HiveManager resolves to a private address. &lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 20:12:44 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84894#M10455</guid>
      <dc:creator>samantha_lynn</dc:creator>
      <dc:date>2019-10-08T20:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Switch can't connect to HiveManager! Get following message: Peer certificate cannot be authenticated with given CA certifcates.</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84895#M10456</link>
      <description>&lt;P&gt;Our HiveManager is resolved by a public IPv4 address and our customers devices reach HM by redirector &amp;amp;  public ip. We have accesspoints connected to these switches at the customer site and they get connected to our HM but not switches. &lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 20:29:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84895#M10456</guid>
      <dc:creator>benjamin_heravi</dc:creator>
      <dc:date>2019-10-08T20:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Switch can't connect to HiveManager! Get following message: Peer certificate cannot be authenticated with given CA certifcates.</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84896#M10457</link>
      <description>&lt;P&gt;In Aerohive's current design is there is no support for the HiveManager VA when resolved to a public IPv4 address on a switch in HiveAgent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is unsupported because Aerohive's engineering designed this in way which means that a public IPv4 is only functional where HiveAgent is connecting to Aerohive's Cloud HiveManager, explicitly using only the Comodo root that is in use for the Cloud at https://cloud.aerohive.com/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When HiveManager is resolved to a private IPv4 address, a lower level of certificate checking takes place and the self-signed certificate is supported by design. When HiveManager is resolved to a public IPv4 address, a higher level of certificate checks takes place and the self-signed certificate is not supported by design.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If for example, Aerohive changed its root from Comodo to a different one in the future, the deployment might be subject to breaking, it would be fragile and at risk to this. Therefore, there this set up is not supported.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 20:37:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84896#M10457</guid>
      <dc:creator>samantha_lynn</dc:creator>
      <dc:date>2019-10-08T20:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Switch can't connect to HiveManager! Get following message: Peer certificate cannot be authenticated with given CA certifcates.</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84897#M10458</link>
      <description>&lt;P&gt;Thank you Sam! &lt;/P&gt;&lt;P&gt;If i don't misunderstand you, it's not possible to connect the Aerohive Switches to HiveManager NGs (on-premise) public IPv4. Is that right? So how can we manage the Aerohive switches at the customer site? Should we always create a site-to-site tunnel or there is another way?  &lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2019 21:37:32 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84897#M10458</guid>
      <dc:creator>benjamin_heravi</dc:creator>
      <dc:date>2019-10-12T21:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Switch can't connect to HiveManager! Get following message: Peer certificate cannot be authenticated with given CA certifcates.</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84898#M10459</link>
      <description>&lt;P&gt;That is correct, a public IPv4 address will not work.  You would want to manage the devices via the HiveManager, and/or a site-to-site tunnel would work as well. &lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 19:59:39 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/switch-can-t-connect-to-hivemanager-get-following-message-peer/m-p/84898#M10459</guid>
      <dc:creator>samantha_lynn</dc:creator>
      <dc:date>2019-10-14T19:59:39Z</dc:date>
    </item>
  </channel>
</rss>

