IBM Support

QRadar: Patching to 7.4.2 regenerates default certificates in compliance with a check in the patch

Troubleshooting


Problem

Administrators patching to any version of 7.4.2, if custom certificates are used, the certificates are reverted to the QRadar default self-signed certificates. When the GUI loads, it reports an unsecure connection.

Symptom

When you patch to any version of 7.4.2, a Certificate renewal prompt is shown for the default certificates.

The following check is shown by the patch:

Patch: 2072
--------------------------------------------------------------------------------

Hostname 'hostname.qradar.example' requires certificates to be renewed.
This is due to use of upper case and RFC 4343 compliance fixes in this patch.

    On all managed hosts patched from the Console, the certificates will be updated as well.

Do you wish to continue? (Y/N):

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtNAAQ","label":"Deployment"}],"ARM Case Number":"TS005682659","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.4.2"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
18 August 2021

UID

ibm16469925