Activating NAM HTTPS server

Answered Question
Aug 11th, 2009

Hi, I have activated https server in a NAM following the procedure in After I have loaded successfully the patch, I try to activate the server, but the following error occurs:

[email protected]# ip http secure server enable

Enabling HTTP secure server...

ERROR: Failed to enable HTTP secure server.

I have this NAM configuration:

Fri Aug 7 23:53:19 2009 Patch: nam-app.3-6.strong-crypto-patchK9-1-0 Description: Strong Crypto Patch for NAM.

IP address: x.x.x.x

Subnet mask: x.x.x.x

IP Broadcast: x.x.x.x

DNS Name: localhost.i-csnam-simb-c03.tsm.inet

Default Gateway: x.x.x.x


HTTP server: Disabled

HTTP secure server: Disabled

HTTP port: 80

HTTP secure port: 443

TACACS+ configured: No

Telnet: Disabled

SSH: Disabled

I have seen also the following error:

[Sat Aug 08 00:02:59 2009] [warn] RSA server certificate CommonName (CN) `localhost.i-csnam-simb-c03.tsm.inet' does NOT match server name!?

[Sat Aug 08 00:02:59 2009] [error] Unable to configure RSA server private key

[Sat Aug 08 00:02:59 2009] [error] SSL Library Error: 185073780 error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch

Does anyone know what is going wrong?

Thanks in advanced.


I have this problem too.
0 votes
Correct Answer by Lucien Avramov about 7 years 2 months ago

CN=hostname.domain so that is fine.

Try the other steps i mentioned earlier and revert your results.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Lucien Avramov Tue, 08/11/2009 - 00:27

Make sure you configure correctly the hostname of the nam

Try a config clear from the NAM CLI and try again.

If that doesnt help, try to reimage the nam with the --install option.

If it still the same issue, please post the show-tech from the NAM so I can have a look

luis.elvira Tue, 08/11/2009 - 01:41

Hi lavramov,

I have checked the configuration and really the hostname is not the same that th CN in the certificate:

ip host "localhost"

ip domain "i-csnam-simb-c03.tsm.inet"

So, have we to change the certificate CN to localhost??

Thank you very much,


Correct Answer
Lucien Avramov Tue, 08/11/2009 - 15:46

CN=hostname.domain so that is fine.

Try the other steps i mentioned earlier and revert your results.

luis.elvira Wed, 08/12/2009 - 22:59

Thank you very much, I made clear config and confire again and now it works :)


This Discussion