<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Delete Expired Certificates In NAC in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83827#M9178</link>
    <description>&lt;P&gt;Workaround found.&amp;nbsp;&lt;/P&gt; &lt;P&gt;The repository contained duplicate CA certs that could not be deleted one at a time, but could via the legacy NAC manager.&lt;/P&gt; &lt;P&gt;Currently looking into a bug fix for XMC.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Dec 2019 16:38:26 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2019-12-17T16:38:26Z</dc:date>
    <item>
      <title>Delete Expired Certificates In NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83823#M9174</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt; &lt;P&gt;Working on an issue where NAC is complaining of old expired certificates, so would like to clean these up.&lt;/P&gt; &lt;P&gt;One of the alarms are something along the lines of:&lt;/P&gt; &lt;PRE&gt;&lt;CODE&gt;Device: 192.168.60.11&lt;BR /&gt;Severity: Critical&lt;BR /&gt;Message: AAA Configuration Truststore: Invalid Certificate Found Certificate expired on 2018-11-25 10:53 GMT Alias: 0 Serial Number: 3b 48 6d f7 b6 8d f4 b5 42 f3 90 72 af 49 20 3b CN=xxx-CERTROOTCA01-CA DC=xxx DC=xxx DC=uk CN=xxx-CERTROOTCA01-CA DC=xxx DC=gxxx DC=uk Valid From: 2013-11-25 10:43 GMT Valid Until: 2018-11-25 10:53 GMT RSA (2048 bits) SHA1withRSA&lt;BR /&gt;&lt;/CODE&gt;&lt;/PRE&gt; &lt;P&gt;What has been happening is overtime as and when the RADIUS cert has expired, new ones have been updated and the old ones have remained in NAC.&lt;/P&gt; &lt;P&gt;I think the location of the certificate store is at /opt/nac/radius/raddb/certs&lt;/P&gt; &lt;P&gt;When I do an ‘ls’ I see something along the lines of:&lt;/P&gt; &lt;PRE&gt;&lt;CODE&gt;drwxr-xr-x 3 root root 4.0K May 3 2019 ./&lt;BR /&gt;drwxr-xr-x 8 root root 4.0K Mar 17 2019 ../&lt;BR /&gt;-rw-r----- 1 root root 245 Nov 30 2017 dh&lt;BR /&gt;-rw-r--r-- 1 root root 14K May 3 2019 external_ca.pem&lt;BR /&gt;-rw-r--r-- 1 root root 6.4K Jul 19 2018 external_server.keystore&lt;BR /&gt;-rw-r--r-- 1 root root 2.2K Nov 30 2017 external_server.keystore.bak&lt;BR /&gt;-rw-r--r-- 1 root root 2.2K Dec 6 2017 external_server.keystore.bak.1&lt;BR /&gt;-rw-r--r-- 1 root root 6.4K Jul 19 2018 external_server.keystore.bak.10&lt;BR /&gt;-rw-r--r-- 1 root root 6.3K Dec 14 2017 external_server.keystore.bak.2&lt;BR /&gt;-rw-r--r-- 1 root root 6.3K Jan 22 2018 external_server.keystore.bak.3&lt;BR /&gt;-rw-r--r-- 1 root root 6.3K Feb 20 2018 external_server.keystore.bak.4&lt;BR /&gt;-rw-r--r-- 1 root root 6.3K Mar 22 2018 external_server.keystore.bak.5&lt;BR /&gt;-rw-r--r-- 1 root root 6.3K Apr 20 2018 external_server.keystore.bak.6&lt;BR /&gt;-rw-r--r-- 1 root root 6.3K Jun 1 2018 external_server.keystore.bak.7&lt;BR /&gt;-rw-r--r-- 1 root root 6.4K Jun 4 2018 external_server.keystore.bak.8&lt;BR /&gt;-rw-r--r-- 1 root root 6.4K Jul 16 2018 external_server.keystore.bak.9&lt;BR /&gt;-rw-r--r-- 1 root root 8.7K Jul 19 2018 external_server.pem&lt;BR /&gt;-rw-r--r-- 1 root root 14K May 3 2019 external_trust.pem&lt;BR /&gt;-rwxr-xr-- 1 root root 2.5K Mar 17 2019 generate_client_cert*&lt;BR /&gt;-rwxr-xr-- 1 root root 3.1K Mar 17 2019 generate_server_cert*&lt;BR /&gt;-rw-r----- 1 root root 112 Nov 30 2017 index.txt&lt;BR /&gt;-rw-r--r-- 1 root root 20 Sep 30 2018 index.txt.attr&lt;BR /&gt;-rw-r----- 1 root root 21 Nov 30 2017 index.txt.attr.orig&lt;BR /&gt;-rw-r----- 1 root root 0 Nov 30 2017 index.txt.old&lt;BR /&gt;-rw-r--r-- 1 root root 4.2K Oct 3 2017 Makefile&lt;BR /&gt;-rw-r----- 1 root root 5.0K Mar 17 2019 random&lt;BR /&gt;-rw-r--r-- 1 root root 7.7K Oct 3 2017 README&lt;BR /&gt;drwxr-xr-x 2 root root 4.0K Nov 30 2017 selfsigned/&lt;BR /&gt;-rw-r----- 1 root root 1.6K Nov 30 2017 selfsigned_ca.pem&lt;BR /&gt;-rw-r----- 1 root root 3.5K Nov 30 2017 selfsigned_server.pem&lt;BR /&gt;-rw-r----- 1 root root 3 Nov 30 2017 serial&lt;BR /&gt;-rw-r----- 1 root root 3 Nov 30 2017 serial.old&lt;BR /&gt;-rw-r--r-- 1 root root 578 Oct 3 2017 xpextensions&lt;BR /&gt;&lt;/CODE&gt;&lt;/PRE&gt; &lt;P&gt;There are several alarms about several certificates that have expired, and have to be careful I don’t remove the current valid certificate&amp;nbsp;that is valid from 2018-07-18 to 2020-07-17.&lt;/P&gt; &lt;P&gt;My assumption here is that the current ‘external_server_keystore’ is perhaps what holds this, and the others maybe old?&lt;/P&gt; &lt;P&gt;I can’t see a way to do it through the GUI, so assume this will have to be done via the shell?&lt;/P&gt; &lt;P&gt;In addition below is a view of the AAA Trusted Certificate:&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="55273e794e9141139daaef51fc17a4f4_8e84cf04-24fe-45a5-baac-b48072aebf28.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5994i2B56539EBC1F16A8/image-size/large?v=v2&amp;amp;px=999" role="button" title="55273e794e9141139daaef51fc17a4f4_8e84cf04-24fe-45a5-baac-b48072aebf28.jpg" alt="55273e794e9141139daaef51fc17a4f4_8e84cf04-24fe-45a5-baac-b48072aebf28.jpg" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Although I can delete these individual certs from the GUI, I would like to look at the cert to see its details and valid dates before&amp;nbsp;removing to check if its necessary or not.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Any advise much appreciated in advance.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2019 00:50:37 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83823#M9174</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-11-23T00:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Delete Expired Certificates In NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83824#M9175</link>
      <description>&lt;P&gt;Hey Martin,&lt;/P&gt; &lt;P&gt;In XMC →&amp;nbsp;Control →&amp;nbsp;Access Control →&amp;nbsp;Engines →&amp;nbsp;Right click a NAC appliance and click “Web View”.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;In the browser that pops up click on Diagnostics →&amp;nbsp;Certificate Diagnostics&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;I believe it will break out the Trusted Root certificates to provide more information about each one.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;If you SSH into the NAC box and go into /opt/nac/radius/raddb/certs you can also view them through the openssl application.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;openssl x509 -in &amp;lt;certificate&amp;gt;&amp;nbsp;-text&lt;/P&gt; &lt;P&gt;That should display the contents of the certificate. I think that you want to view the “external trust.pem”. To view this file make sure that you escape the space.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;openssl x509 -in external\ trust.pem -text&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thanks&lt;/P&gt; &lt;P&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 21:36:27 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83824#M9175</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2019-11-25T21:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Delete Expired Certificates In NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83825#M9176</link>
      <description>&lt;P&gt;Hi Ryan,&lt;/P&gt; &lt;P&gt;Thanks for posting back…. slightly annoyed with myself, as should have thought of the webview &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt; &lt;P&gt;Really appreciate the advise as was stuck.&lt;/P&gt; &lt;P&gt;Do have an issue though, in deleting the certificate. See images below:&lt;/P&gt; &lt;P&gt;This shows a list of all the certs:&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="458bfb6611aa4d7e97b3ecbb1c8b130a_b33f9181-c300-4ad4-90d8-541e44faac6e.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3942iC8D425C7688E2AAD/image-size/large?v=v2&amp;amp;px=999" role="button" title="458bfb6611aa4d7e97b3ecbb1c8b130a_b33f9181-c300-4ad4-90d8-541e44faac6e.png" alt="458bfb6611aa4d7e97b3ecbb1c8b130a_b33f9181-c300-4ad4-90d8-541e44faac6e.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;This shows I’ve just deleted the top cert:&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="458bfb6611aa4d7e97b3ecbb1c8b130a_0a393284-b60e-4067-9511-7e8d2f379bb0.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/716iDA2D6DD9DF3185CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="458bfb6611aa4d7e97b3ecbb1c8b130a_0a393284-b60e-4067-9511-7e8d2f379bb0.png" alt="458bfb6611aa4d7e97b3ecbb1c8b130a_0a393284-b60e-4067-9511-7e8d2f379bb0.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;When I click ‘OK’, it seems to have added it in again and continuing with ‘Yes’ doesn’t remove the cert:&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="458bfb6611aa4d7e97b3ecbb1c8b130a_138b307f-305b-495a-b139-8553bb2acb6f.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1360i35BED82BC5B0EBB9/image-size/large?v=v2&amp;amp;px=999" role="button" title="458bfb6611aa4d7e97b3ecbb1c8b130a_138b307f-305b-495a-b139-8553bb2acb6f.png" alt="458bfb6611aa4d7e97b3ecbb1c8b130a_138b307f-305b-495a-b139-8553bb2acb6f.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Maybe I’m doing something wrong, but be good to get your opinion.&lt;/P&gt; &lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 22:39:11 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83825#M9176</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-11-25T22:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: Delete Expired Certificates In NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83826#M9177</link>
      <description>&lt;P&gt;Opened a GTAC case on that last issue, possible bug.&lt;/P&gt; &lt;P&gt;There seems to be a part workaround in that I have to delete two of the certificates together in order to remove it, but again will post back when I’ve got more detail.&lt;/P&gt; &lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 07:37:07 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83826#M9177</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-11-28T07:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Delete Expired Certificates In NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83827#M9178</link>
      <description>&lt;P&gt;Workaround found.&amp;nbsp;&lt;/P&gt; &lt;P&gt;The repository contained duplicate CA certs that could not be deleted one at a time, but could via the legacy NAC manager.&lt;/P&gt; &lt;P&gt;Currently looking into a bug fix for XMC.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 16:38:26 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-expired-certificates-in-nac/m-p/83827#M9178</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-12-17T16:38:26Z</dc:date>
    </item>
  </channel>
</rss>

