RSA DLP Network ERROR - HttpChannel.sendViaClient(144) | javax.net.ssl.SSLException: Certificate not verified
2 years ago
Originally Published: 2016-01-28
Article Number
000049868
Applies To
RSA Product Set: DLP
RSA Product/Service Type: Enterprise Manager
RSA Version/Condition: 8.8/9.0
Platform: CentOS
 
Issue
- When you see all RSA DLP network nodes down on the EM webinterface. 
- When you observe the below error in the em.log file located under path: C:\Program Files(x86)\RSA\Enterprise Manager\Logs\em.log

Error: 
 
28 Jan 2016 12:46:02,860 | ERROR - HttpChannel.sendViaClient(144) | javax.net.ssl.SSLException: Certificate not verified.
28 Jan 2016 12:46:02,860 | ERROR - CommonDeviceServiceImpl.setControllerReachability(262) | Controller 1x.xx.xx.xx is not reachable
28 Jan 2016 12:46:06,970 | ERROR - EMApplicationEventMulticaster$1.run(180) | Unexpected exception occurred during event processing: Incident id <544801> was not found; job is recoverable and will be retried

 
Cause
The suspected cause of the issue would due to expired certificate on the network appliances. 
Resolution
Steps: 

1- Start the process of renewing the SSL certificates on all  RSA DLP network nodes via doing below set of actions starting by NC:
 
While logged in as "Tablus" user:

Type below commands: 
 
#resetdevice 
# killca 
#cd /opt/tablus/bin 
# ./initssl.sh 
#cd /opt/rsa/bin 
# ./initssl.sh 
#tabservice start