NetWorker Vulnerability report: SSL Certificate Cannot Be Trusted and SSL Self-Signed Certificate

Summary: "SSL Certificate Cannot Be Trusted" and "SSL Self-Signed Certificate" are two known messages reported on NetWorker server by the different vulnerability scanner tools. This article explains the reported message and where to apply CA signed certificates to overcome the report warnings. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Running a vulnerability scanner on NetWorker could show the following messages:

  • SSL Certificate Cannot Be Trusted
  • SSL Self-Signed Certificate

On the following services (default ports):

  • GST (9001)
  • NetWorker Management Console (NMC) Apache HTTP web (9000)
  • Postgres (5432)
  • RabbitMQ (5672)
  • Auth service (9090)
  • NetWorker Web User Interface (NWUI) (9095)

Cause

NetWorker installation creates self-signed certificates server.key and server.crt which are needed by the above mentioned different services to run.
Because these are self-singed and not CA-signed certificates, vulnerability scanner tools report this as a vulnerability.

Resolution

For NetWorker Authentication Service (AUTHC) (9090) and the NetWorker Web User Interface (NWUI) (9095)

For Postgres (5432), RabbitMQ (5671)

For The NetWorker Management Console (NMC) Server's GST port (9001) and Apache HTTPD Web port (9000):

Additional Information

Affected Products

NetWorker
Article Properties
Article Number: 000186608
Article Type: Solution
Last Modified: 25 رجب 1447
Version:  8
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.