cancel
Showing results for 
Search instead for 
Did you mean: 

Certificate problems when deploying new 12.8.2.2 OVA

Certificate problems when deploying new 12.8.2.2 OVA

michael_bliss
New Contributor

Ive deployed the 12.8.2.2 OVA to VMWare ESXi 6.7, as Im sure everyone is aware, in 6.7 you cannot pre-configure IP address and Hostname when deploying the OVA any more, this means you get stuck with a DHCP address and "hivemanager-ng.aerohive.com" as the hostname.

 

Ive tried changing these details via the HMVA Management portal, and while it does change the IP and Hostname, it doesnt seem to change the certificate that gets created when deploying the OVA.

 

Im now stuck with all browsers blocking access because the valid names on the cert are the DHCP address and "hivemanager-ng.aerohive.com". When adding an exception rule to the browsers to trust the cert, you get looped back to "This Connection is not Secure" and cannot load the controller home page.

 

I have managed to get the homepage loaded by changing back to the original DHCP address and creating an entry in my local HOSTS file for "hivemanager-ng.aerohive.com", this is less than ideal though as it means the portal can only be accessed from my workstation.

 

I would really appreciate any assistance as im stuck now and cannot find a way forward.

5 REPLIES 5

michael_bliss
New Contributor

Winning!!

 

https://thehivecommunity.aerohive.com/s/article/CAPWAP-Guide-for-HiveManager-NG

michael_bliss
New Contributor

Good Morning, I think that will get me to where I am now. I can access the new controller via aerohive-ng.aerohive.com (entry in hosts) and sign in successfully.

 

Ive imported the VHM file from my old controller and all settings have moved across. I then set one of my AP's to Managed but for what ever reason, the controller cannot see it.

 

I can ping the AP from the controller and ping the controller from the AP so im not sure why the AP wont go into a managed state.

 

The AP i'm trying to add to Managed has this setting set,

 

capwap client server name cloud-ie-cws-4.aerohive.com

 

Ive tried changing it to the IP of my new controller but to no avail. Im busy searching the forum for a solution, hopefully Ill find something.

 

samantha_lynn
Esteemed Contributor III

Thank you for your patience, I've been asking around to see what our best course of action would be and the consensus is that the best path would be to redeploy the HiveManager, let it pull an address from the DHCP server, then assign the address it pulls statically to the HiveManager. Is that something we could try?

michael_bliss
New Contributor

Thank you for the detailed response.

 

Ive tried with IE, Edge, FF and Chrome. Its odd behavior for sure, normally if I run into cert issues on a site, I can add an exception and continue as normal, but for some reason this isnt the case with 12.8.2.2.

 

I currently only have a wildcard cert and our SCM processes are rather slow but ill see if I can get it moving so that we can get this sorted.

 

In the meantime, I have access to the console via a HOSTS file entry, would it be ok to import the VHM data and start migrating AP's to the new controller, or should I wait until everything is sorted?

GTM-P2G8KFN