Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Adding Multiple IPSs to IME

hello,

while trying to add multiple IPSs to the IME interface, i added the first IPS successfully, but when i try to add any other IPS device i got an error  "IO Exception when try to get certificate..."

please find error attached.

anyone can advice where is the issue?

regards,

2 ACCEPTED SOLUTIONS

Accepted Solutions
New Member

Adding Multiple IPSs to IME

I don't know how MARS will react on TLS-certificate regeneration but I know that you'll not add sensor to IPS without certificate renew.

New Member

Adding Multiple IPSs to IME

It will be very difficult procedure so I say "no, it is impossible to revert to old certificate". But it is interesting that MARS doesn't say you any warning about certificate expired in Jul, 22.

8 REPLIES
New Member

Adding Multiple IPSs to IME

Your TLS certificate on the sensor is expired.

Login to sensor CLI and regenerate it by command:

tls generate-key

New Member

Adding Multiple IPSs to IME

do that have any relation if i have cs-mars in place that is collecting logs?

in other words, can ips report logs Simultaneously to cs-mars and ime right? and my problem is not related to this issue?

if so then tls generate key will not affect the IPS config on CS-mars right?

New Member

Adding Multiple IPSs to IME

Your problem is only in certificate expiration as I can see it.

What protocol do you use in MARS<->IPS relationship?

New Member

Adding Multiple IPSs to IME

Access type is SSL!

New Member

Adding Multiple IPSs to IME

I don't know how MARS will react on TLS-certificate regeneration but I know that you'll not add sensor to IPS without certificate renew.

New Member

Adding Multiple IPSs to IME

can we revert back if we generated tls certificate and we faced any porblem?

New Member

Adding Multiple IPSs to IME

It will be very difficult procedure so I say "no, it is impossible to revert to old certificate". But it is interesting that MARS doesn't say you any warning about certificate expired in Jul, 22.

New Member

Adding Multiple IPSs to IME

welcome to CiSco Devices

i generated the  new tls certifcate,

i asked mars to rediscover, i got  an error related to a new certificate to accept, i accepted it and things with mars got fine, i checked with IME and problem is solved.

thanks man for you help,

479
Views
0
Helpful
8
Replies
CreatePlease login to create content