PowerStore: security scan may report multiple issues due to missing certificate
Summary: Security scans may report several issues if the PowerStore appliance does not have a Certificate Authority signed server certificate present.
Symptoms
A security scan may report multiple security alerts during a scan of the PowerStore.
Below is a known set of items from a Qualys scan that are relevant to this issue:
QID 38169: SSL Certificate - Self-Signed Certificate
QID 38170: SSL Certificate - Subject Common Name Does Not Match Server FQDN
QID 38173: SSL Certificate - Signature Verification Failed Vulnerability
QID 38685: SSL Certificate - Invalid Maximum Validity Date Detected
Cause
These alerts show up in the scan due to no Certificate Authority (CA) signed server certificate being present.
Resolution
Create and import a CA signed certificate.
To import a CA signed server certificate, follow the steps from the following knowledge article. Be sure to carefully read the limitations associated with some versions, and the steps of the procedure: