Description

PKI server reachability is very important for the certificate generation for any tenant onboarded in CSO, which is used for site authentication and further config generation for that site of tenant.

This article explains how to verify the PKI server reachability from CSO UI. This does not cause any impact to service, but to be on the safe side, it is recommended to perform the steps along with the Resident Engineer or JTAC.

Solution

  1. Check whether the PKI server URLs are correctly configured for the tenant.

    Go to CSO UI tenant page, Administration > Tenant setting

    Click on VPN authentication. It will show the PKI related config:

    alt
  2. Go to CSO UI. Navigate to the respective tenant page. Then go to  Administration > Certificate Management > VPN Authentication

    Select the interested site and click Renew. In the example below, the site name is Test:

    alt

    alt

  3. Go to CSO UI. Navigate to monitor > Jobs

    A new Job for renew certificate will be created and running. Wait for that Job to finish.

    alt

  4. Go to view logs of the job. The logs below are seen, which indicates the renew certificate is a success.

    It confirms that PKI infrastructure is working as expected.

    Job logs:
    Mar 4, 2021, 3:59:00 PMPhase1 Start
    Mar 4, 2021, 3:59:00 PMStart to renew cert for site test-site, Phase1
    Mar 4, 2021, 3:59:02 PMRetry renew cert for site: test-stie with extra info
    Mar 4, 2021, 3:59:18 PMPhase2 Start
    Mar 4, 2021, 3:59:18 PMPhase1 End
    Mar 4, 2021, 3:59:23 PMPhase2 End
    Mar 4, 2021, 3:59:23 PMPhase3 Start
    Mar 4, 2021, 3:59:23 PMPhase3 End
    Mar 4, 2021, 3:59:23 PMUpdate Site cert Job success