Start a Conversation

Unsolved

This post is more than 5 years old

781

October 10th, 2016 15:00

networker upgrade from sha1 to sha2

Hi

Can someone please  point me to any documentation on how to upgrade a networker server's digital cert from sha1 to sha2?

Thanks

JAC

1.7K Posts

October 11th, 2016 07:00

Are you referring to this?:

After upgrading the VMware Backup Appliance from a NetWorker 8.1 or 8.2 release to NetWorker 9.0, you cannot use the Mozilla Firefox browser to launch the EMC Backup and Recovery Configuration Utility window or the EMC Data Protection Restore Client.

To resolve this issue, execute the following commands on the VMware Backup Appliance as the root user:

/usr/java/latest/bin/ keytool -delete -alias tomcat -storepass changeit

/usr/java/latest/bin/keytool -genkeypair -v -alias tomcat -keyalg RSA -sigalg SHA256withRSA -keystore /root/.keystore

-storepass changeit -keypass changeit -validity 3650 -dname "CN=localhost.localdom, OU=Avamar, O=EMC, L=Irvine, S=California, C=US"

emwebapp.sh --restart

If not then, what are you referring to?

Thank you,

Carlos

68 Posts

October 11th, 2016 07:00

Hi,

never heard about that.

I'm only aware of nsrauth/oldauth for authentication.

But that's not what you are searching for, right?

mkeil

4 Posts

October 13th, 2016 07:00

Thanks for your reply Carlos

on port 9001 on the networker servers - a vulnerability report shows the following

01/01/1971 18/01/2038 Active 1024 128 sha1WithRSAEncryption TLSv1.

i need to get that changed to sha2  - just looking to see how to do that?

4 Posts

October 13th, 2016 08:00

hanks for your reply Carlos

on port 9001 on the networker servers - a vulnerability report shows the following

01/01/1971 18/01/2038 Active 1024 128 sha1WithRSAEncryption TLSv1.

i need to get that changed to sha2  - just looking to see how to do that?

68 Posts

October 13th, 2016 22:00

Which version are you using?

Have you checked if it is fixed with a newer version?

5 Practitioner

 • 

274.2K Posts

October 15th, 2016 19:00

Perhaps you're still using pre-8.0.2, I never done this in the past but prior SSL experience tells me, you may find the location of Tomcat binaries from NMC installation log and then use Tomcat key tools to change it.  If this issue is still unresolved by next Friday (Oct 21), I may have some free time to try this in my own lab.

Good luck!

BV2/Joe Chang

4 Posts

October 26th, 2016 06:00

Hi Joe

using networker 8.2.2 is the version in use

any thoughts?

John

No Events found!

Top