External SKLM key server reports Unavailable with expired client certificate
Applies to
- Encryption
- External Key Manager (EKM)
Issue
- The following EMS message is seen:
Message: km.keyserver.notavailable: The external key management server "<ip_address>" is not available for Vserver "vserver", status: "unknown".
- The following is also reported when running "
key-manager external show-status
"
Status Details: Response status:
OPERATION_FAILED. Reason:
INVALID_MESSAGE. Message:
java.security.cert.
CertificateExpiredException:
NotAfter: Tue Jul 05
12:00:29 EDT 2022