IBM Support

Security Network IPS fails certificate validation after replacing SiteProtector certificates

Troubleshooting


Problem

You might find that your Security Network IPS (GX) sensor is unable to communicate with SiteProtector after replacing the SiteProtector certificates with CA signed certificates.

Symptom

The GX will be unable to communicate with SiteProtector and debug level logging for the iss-spa process on the GX will show errors like the following:

PXSSLCLIENT-LOWLEVEL: SSL:iss_get_cert_action, Leaf cert is not self-signed and chain could not be validated.

[{"Product":{"code":"SS9SBT","label":"Proventia Network Intrusion Prevention System"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"General Information","Platform":[{"code":"PF009","label":"Firmware"}],"Version":"4.6.1;4.6.2","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
26 January 2021

UID

swg21988160