Sun Microsystems, Inc.  Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition
   Home | Current Systems | Former STK Products | EOL Systems | Components | General Info | Search | Feedback

Asset ID: 1-71-1907953.1
Update Date:2017-05-30
Keywords:

Solution Type  Technical Instruction Sure

Solution  1907953.1 :   Process To Renew a TLS Certificate on Oracle Communications Session Border Controller SCX and SCZ Releases  


Related Items
  • Acme Packet 4600
  •  
  • Acme Packet 4500
  •  
  • Acme Packet 6100
  •  
  • Acme Packet 6300
  •  
  • Acme Packet 3820
  •  
Related Categories
  • PLA-Support>Sun Systems>CommsGBU>Session Delivery Network>SN-SND: Acme Service Provider
  •  




In this Document
Goal
Solution
References


Created from <SR 3-9250168841>

Applies to:

Acme Packet 3820 - Version S-Cx6.4.0 and later
Acme Packet 4600 - Version S-Cx6.4.0 and later
Acme Packet 6100 - Version S-Cz7.0.2 and later
Acme Packet 6300 - Version S-Cz7.0.2 and later
Acme Packet 4500 - Version S-Cx6.4.0 and later
Information in this document applies to any platform.

Goal

Process to renew a SSL certificate

Solution

In order to renew the certificate, please try the below procedure:

  1. Create a backup configuration file using the ACLI "backup-config <filename>" command.
  2. Create a new certificate-record object with the same parameter settings but with a new name. ie: if your name is "voip.domain.com", create a new object named  "voip.domain.com.renew2014". 
    • The existing certificate record name cannot be used because the import of the new certificate would fail, as an existing certificate name cannot be overwritten.
  3. Don't delete the current certificate. Don't delete the current tls-profile.
  4. Create a new certificate signing request CSR.
  5. Import the new certificate.
  6. In the exiting tls-profile object, change the parameter "end-entity-certificate" parameter to "voip.domain.com.renew2014" and save/activate the config.
  7. If you do your end-2-end tests and seems the work fine then this is your new config.


If any issues occur, you can rollback by changing back the end-entity-certificate parameter into "voip.domain.com"

You can also refer to the following document for a more detailed process for updating the TLS certificate.

Transport Layer Security Certificate Update Procedure(1598288.1)

References

<NOTE:1598288.1> - Transport Layer Security Certificate Update Procedure

Attachments
This solution has no attachment
  Copyright © 2018 Oracle, Inc.  All rights reserved.
 Feedback