Issue in dsreplication of CTS server after certificate renewal

This topic has 3 replies, 2 voices, and was last updated 5 years, 4 months ago by priya.c.

  • Author
    Posts
  • #17274
     priya.c
    Participant

    Hi Team,

    In our production environment, domain certificate was about to expire and I have renewed and imported new certificate in CTS server. I have imported to keystore and admin-keystore on two CTS servers. Replication is enabled between the two servers prior to the certificate renewal.
    But when I check the replication status, it says unable to “Unable to connect to the server XXX on port XXX. Check this port is an administration port”

    I tried to initialize the replication but below error occurs:

    Error reading data from server xxxx:4444. There is
    an error with the certificate presented by the server.
    Details: simple bind failed: xxx:4444

    Could you please let me know if i need to import the certificate to any other keystore. this is urgent as this happens in production.

    Regards
    Priya C

    #17275
     Chris Ridd
    Participant

    If this is an urgent issue and you have a support subscription, then you should raise a ticket with ForgeRock support.

    #17276
     priya.c
    Participant

    Hi Chris,

    I don’t think we have a support subscription as this is new client.

    Help me out if you have any idea. Do I need to import the certs to truststore and admin-truststore as well.

    Regards
    Priya c

    #17278
     priya.c
    Participant

    Hi Chris,

    I resolved the issue. Root cause is alias name was incorrect in admin-keystore.

    I imported with alias name “server-cert” but it should be “admin-cert”. Once i changed the alias name and restarted CTS service,replication started working.

    Regards
    Priya C

Viewing 4 posts - 1 through 4 (of 4 total)

You must be logged in to reply to this topic.

©2022 ForgeRock - we provide an identity and access platform to secure every online relationship for the enterprise market, educational sector and even entire countries. Click to view our privacy policy and terms of use.

Log in with your credentials

Forgot your details?