{"id":2417,"date":"2016-04-22T16:16:32","date_gmt":"2016-04-22T14:16:32","guid":{"rendered":"http:\/\/blog.novaknet.de\/?p=2417"},"modified":"2016-04-27T09:18:46","modified_gmt":"2016-04-27T07:18:46","slug":"sametime-video-manager-expired-certificate-exchange-root-cert-and-trust-15-years","status":"publish","type":"post","link":"https:\/\/blog.novaknet.de\/?p=2417","title":{"rendered":"Sametime Video Manager expired certificate &#8211; exchange root cert and trust 15 years"},"content":{"rendered":"<p>This is an old one, but it seems it happens a lot of again.<\/p>\n<p>With the installation of the IBM Sametime Video Manager gold edition (sept. 2013), the Video Manager generates an <strong>self-signed<\/strong> <span style=\"color: #ff0000;\"><strong>one year<\/strong> <\/span>valid ssl certificate.<\/p>\n<p><a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-46-20.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2418 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-46-20-300x96.png\" alt=\"2016-04-22_11-46-20\" width=\"300\" height=\"96\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-46-20-300x96.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-46-20-768x245.png 768w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-46-20.png 1009w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><span style=\"line-height: 1.5;\">This certificate has to be trusted inside the Sametime Media System to connect via port 5061\/5081 between Media Conference Bridge and Video Manager<\/span><\/p>\n<p>IBM Wiki:\u00a0<a href=\"http:\/\/www.ibm.com\/support\/knowledgecenter\/SSKTXQ_9.0.0\/admin\/config\/config_av_security_vmgr_cert_to_conf.dita\">Import the Video Manager&#8217;s certificate to the Conference Manager<\/a><\/p>\n<p>After a year you get a new self-signed certificate on the Video manager and the connection\u00a0between Media Conference Bridge and Video Manager ist broken (error 503). You could trust the new Video Manager certificate inside the Media Conference Bridge, but this is &#8211; again &#8211; for one year.<\/p>\n<p>IBM already documented to change the certificate to a longer valid certificate or root certificate (15 years).<\/p>\n<p>IBM Docu:\u00a0<a href=\"http:\/\/www-01.ibm.com\/support\/docview.wss?uid=swg21687024\">Sametime 9 Video Manager &#8211; A\/V call fails due to default root certificate expires in one year<\/a><\/p>\n<p>Because of many people having problem with this documentation i will give you some more details and screenshots\u00a0for this to work (from zero2hero)<\/p>\n<hr \/>\n<ol>\n<li>Login to the Sametime Video Manager ISC (https:\/\/yourvmgrserver:9043\/ibm\/console)<\/li>\n<li>Navigate to <span style=\"color: #0000ff;\"><em>Security<\/em><\/span> &gt; <span style=\"color: #0000ff;\"><em>SSL certificate &amp; key management<\/em><\/span> &gt; <span style=\"color: #0000ff;\"><em>key stores &amp; certificates<\/em><\/span><\/li>\n<li>Select the option (or key store) <span style=\"color: #0000ff;\"><strong>NodeVMGRKeyStore<\/strong><\/span><\/li>\n<li>Navigate to <em><span style=\"color: #0000ff;\">personal certificate<\/span><\/em> and press the button &#8222;<strong><span style=\"color: #800000;\">import certificate from a key<\/span><\/strong>&#8220;<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-52-39-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2438\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-52-39-2-300x135.png\" alt=\"2016-04-22_11-52-39-2\" width=\"300\" height=\"135\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-52-39-2-300x135.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-52-39-2.png 706w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<li>Select the key store <span style=\"color: #0000ff;\">NodeDefaultKeyStore<\/span> and enter the key store password (use &#8222;<span style=\"color: #0000ff;\">WebAS<\/span>&#8220; because it is the default password for all websphere based keystores) and press button &#8222;<strong><span style=\"color: #800000;\">Get key store aliases<\/span><\/strong>&#8222;<\/li>\n<li>Select in the field <span style=\"color: #0000ff;\">certificate alias to import<\/span> the value <span style=\"color: #ff0000;\"><strong>default<\/strong><\/span> and press the button <span style=\"color: #0000ff;\"><strong><span style=\"color: #800000;\">OK<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-49-31.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2423 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-49-31-300x146.png\" alt=\"2016-04-22_11-49-31\" width=\"300\" height=\"146\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-49-31-300x146.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-49-31.png 694w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/span><\/strong><br \/>\n<\/span><\/li>\n<li>You should now see a certificate called <strong><span style=\"color: #ff0000;\">default<\/span><\/strong> with a <span style=\"color: #ff0000;\">self-signed root certificate<\/span> (valid for 15years) in common.<br \/>\nPress\u00a0<strong><span style=\"color: #800000;\">SAVE<\/span><\/strong>\u00a0to write the master configuration.<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-52-39.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2424 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-52-39-300x195.png\" alt=\"2016-04-22_11-52-39\" width=\"300\" height=\"195\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-52-39-300x195.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-52-39.png 706w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><br \/>\n<\/a><span style=\"color: #993366;\"><em>You now need to assign the new certificate to the application server<\/em><\/span><\/li>\n<li>Navigate to <span style=\"color: #0000ff;\"><em>Security<\/em><\/span> &gt; <span style=\"color: #0000ff;\"><em>SSL certificate &amp; key management<\/em><\/span> &gt; <em><span style=\"color: #0000ff;\">Manage endpoint security configurations<\/span><\/em>\n<ul>\n<li>Expand the <strong><span style=\"color: #ff0000;\">INBOUND<\/span><\/strong>\u00a0tree until you see the application server name <strong><span style=\"color: #ff0000;\">STMediaServer<\/span><\/strong><\/li>\n<li>Klick on the servername <span style=\"color: #ff0000;\"><strong>STMediaServer<br \/>\n<\/strong><\/span><\/li>\n<li>Select &#8222;<em><span style=\"color: #ff0000;\">override inherited values<\/span><\/em>&#8222;, select\u00a0<em><span style=\"color: #ff0000;\">NodeDefaultSSLSetting<\/span><\/em> configuration, select\u00a0<span style=\"color: #ff0000;\"><strong>default<\/strong><\/span> certificate alias\u00a0and press the button <span style=\"color: #0000ff;\"><strong><span style=\"color: #800000;\">OK<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-53-46.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2431 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-53-46-300x234.png\" alt=\"2016-04-22_11-53-46\" width=\"300\" height=\"234\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-53-46-300x234.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-53-46.png 543w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\n<\/span><\/strong><\/span><span style=\"color: #3366ff;\"><em>Repeat this for the\u00a0<strong>OUTBOUND<\/strong>\u00a0tree until you see the application server name STMediaServer<\/em><\/span><\/li>\n<li>Expand the <strong><span style=\"color: #ff0000;\">OUTBOUND<\/span><\/strong>\u00a0tree until you see the application server name <strong><span style=\"color: #ff0000;\">STMediaServer<\/span><\/strong><\/li>\n<li>Klick on the servername <span style=\"color: #ff0000;\"><strong>STMediaServer<\/strong><\/span><\/li>\n<li>Select &#8222;<em><span style=\"color: #ff0000;\">override inherited values<\/span><\/em>&#8222;, select\u00a0<em><span style=\"color: #ff0000;\">NodeDefaultSSLSetting<\/span><\/em> configuration, select\u00a0<span style=\"color: #ff0000;\"><strong>default<\/strong><\/span> certificate alias\u00a0and press the button <span style=\"color: #0000ff;\"><strong><span style=\"color: #800000;\">OK<\/span><\/strong><\/span><\/li>\n<\/ul>\n<\/li>\n<li>Press\u00a0<strong><span style=\"color: #800000;\">SAVE<\/span><\/strong>\u00a0to write the master configuration.<\/li>\n<li>Check the values in the endpoint security tree<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2425 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-54-32-300x164.png\" alt=\"2016-04-22_11-54-32\" width=\"300\" height=\"164\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-54-32-300x164.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_11-54-32.png 694w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/li>\n<li>Restart the Sametime Video Manager in the following order\n<ul>\n<li>stop STMediaServer_was.init\u00a0(via service or batch)<\/li>\n<li>stop soliddb\u00a0(via service or batch)<\/li>\n<li>start soliddb\u00a0(via service or batch)<\/li>\n<li><strong><em><span style=\"color: #ff0000;\">WAIT 60 seconds<\/span><\/em><\/strong><\/li>\n<li>start STMediaServer_was.init\u00a0(via service or batch)<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p><span style=\"color: #993366;\"><em>After this you need to import the new Video Manager certificate into the Media\u00a0Conference Bridge.<\/em><\/span><\/p>\n<ol>\n<li>Login to the Sametime System Console\u00a0ISC (https:\/\/yoursscserver:8701\/ibm\/console)<\/li>\n<li>Navigate to <span style=\"color: #0000ff;\"><em>Security<\/em><\/span> &gt; <span style=\"color: #0000ff;\"><em>SSL certificate &amp; key management<\/em><\/span> &gt; <span style=\"color: #0000ff;\"><em>key stores &amp; certificates<\/em><\/span><\/li>\n<li>Select the option (or key store) <span style=\"color: #0000ff;\"><strong>CellDefaultTrustStore<br \/>\n<\/strong><\/span><span style=\"color: #ff0000;\"><em>&gt;&gt; you could delete the old Video Manager certificate if you wish<\/em><\/span><\/li>\n<li>Navigate to <em><span style=\"color: #0000ff;\">signer certificate<\/span><\/em> and press the button &#8222;<strong><span style=\"color: #800000;\">retrieve from port<\/span><\/strong>&#8220;<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2429 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_15-40-30-300x120.png\" alt=\"2016-04-22_15-40-30\" width=\"300\" height=\"120\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_15-40-30-300x120.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_15-40-30.png 747w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/li>\n<li>Enter the <span style=\"color: #ff0000;\">hostname<\/span> for the Video Manager (e.g. myvmgrserver.dns.local) enter the <span style=\"color: #ff0000;\">port 5061<\/span> (or any other ssl port) an press the button &#8222;<strong><span style=\"color: #800000;\">Retrieve signer information<\/span><\/strong>&#8220;<br \/>\nYou should see now the new Video Manager root certificate &#8211; valid for 15 years<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-22-55.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2426 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-22-55-300x223.png\" alt=\"2016-04-22_12-22-55\" width=\"300\" height=\"223\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-22-55-300x223.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-22-55.png 633w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<li>Enter an <span style=\"color: #ff0000;\"><em>alias name<\/em> <\/span>for the certificate e.g. <strong><span style=\"color: #ff0000;\">vmgr_cert<\/span> <\/strong>\u00a0and press the button <span style=\"color: #0000ff;\"><strong><span style=\"color: #800000;\">OK<\/span><\/strong><\/span><\/li>\n<li>You should now see a trust certificate called <strong><span style=\"color: #ff0000;\">vmg_cert<\/span><\/strong>\u00a0\u00a0(valid for 15years).<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_15-40-30-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2428\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_15-40-30-2-300x158.png\" alt=\"2016-04-22_15-40-30-2\" width=\"300\" height=\"158\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_15-40-30-2-300x158.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_15-40-30-2.png 747w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nPress\u00a0<strong><span style=\"color: #800000;\">SAVE<\/span><\/strong>\u00a0to write the master configuration.<\/li>\n<li>Navigate to <span style=\"color: #0000ff;\"><em>System administration<\/em><\/span>\u00a0&gt;\u00a0<span style=\"color: #0000ff;\"><em>Nodes <\/em><\/span>select all nodes and press &#8222;<strong><span style=\"color: #800000;\">full synchronize<\/span><\/strong>&#8220; to push\u00a0the new certificate to the all applications servers<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-24-32.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2427 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-24-32-300x112.png\" alt=\"2016-04-22_12-24-32\" width=\"300\" height=\"112\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-24-32-300x112.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-24-32-768x287.png 768w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-24-32-1024x383.png 1024w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-24-32.png 1083w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><br \/>\n<\/a>Because of having <span style=\"color: #ff0000;\">problems with the shutdown<\/span> of the application server(s) after importing or changing certificates (shutdown is waiting to manually accept new certificates) i do <span style=\"color: #0000ff;\">manually retrieve the keys<\/span> from the node with the following command<br \/>\n&gt;&gt;\u00a0\u00a0&#8222;&lt;appserverbin&gt;\\profiles\\&lt;profilename&gt;\\bin\\<strong><span style=\"color: #ff0000;\">retrievesigners -host stsscserver -port 8703<\/span><\/strong>&#8220;<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/Systemdesign2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2433 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/Systemdesign2-300x105.png\" alt=\"Systemdesign2\" width=\"300\" height=\"105\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/Systemdesign2-300x105.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/Systemdesign2.png 516w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<li>Restart the Sametime Media Server (proxy registrar and\/or conference bridge)<\/li>\n<li>Navigate to <span style=\"color: #0000ff;\"><em>Sametime System Console<\/em><\/span>\u00a0&gt; <span style=\"color: #0000ff;\"><em>Sametime Servers<\/em><\/span>\u00a0&gt; <span style=\"color: #0000ff;\"><em>Sametime Video Manager Servers\u00a0<\/em><\/span>and check if you could connect to the Video Manager\u00a0configuration<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-56-08.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2434 size-medium\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-56-08-300x92.png\" alt=\"2016-04-22_12-56-08\" width=\"300\" height=\"92\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-56-08-300x92.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-56-08-768x235.png 768w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/04\/2016-04-22_12-56-08.png 1022w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<\/ol>\n<p>All done<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is an old one, but it seems it happens a lot of again. With the installation of the IBM Sametime Video Manager gold edition (sept. 2013), the Video Manager generates an self-signed one year valid ssl certificate. This certificate has to be trusted inside the Sametime Media System to connect via port 5061\/5081 between [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[101],"tags":[],"class_list":["post-2417","post","type-post","status-publish","format-standard","hentry","category-sametime"],"_links":{"self":[{"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/posts\/2417"}],"collection":[{"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2417"}],"version-history":[{"count":12,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/posts\/2417\/revisions"}],"predecessor-version":[{"id":2445,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/posts\/2417\/revisions\/2445"}],"wp:attachment":[{"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2417"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2417"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2417"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}