Forum Discussion
why the device certificate verify failed when the device certificate is not expired?
The SSL error you're encountering, despite the device certificate not being expired, could be due to the presence of an old certificate on the other DNS nodes. Here are some steps to troubleshoot and resolve the issue:
Check Trusted Certificates: Verify that the new device certificate is correctly installed on DNS01 and that the old certificate has been removed from the trusted certificates on other DNS nodes KMFusa
Restart Services: Restarting the big3d service on DNS01 and the gtmd service on the local system might help re-establish the iQuery connection.
Update Certificates: Ensure that all DNS nodes have the updated device certificate.
- Herman2024Jan 07, 2025Cirrus
Thanks lisa52smith Jeffrey_Granier for your advices. I saw there are multiple certificates in other DNS nodes "Device Trust Certificate" with the same serial number. How to verify and confirm whether one client certificate belong to DNS01? I saw the serial number in some certificate is in the format like mac address, don't know what these certificates are. Please advise, thanks in advance!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com