Unable to renew or delete server-chain certificate due to corresponding server certificate
Applies to
- ONTAP 9
- Certificates
Issue
- Deleting a server-chain certificate fails:
cluster1::> certificate delete -vserver svm_name -type server-chain -serial ABCDEFABCDEF -cert-name XXXXXXXXX -common-name www.example.com -ca www.example.com
Error: command failed: Cannot delete server-chain certificate. Reason: There is a corresponding server certificate for it.- There are a server and server-chain certificate with identical serial numbers:
cluster1::> security certificate show -vserver svm_name
Vserver Serial Number Common Name Type---------- --------------- ----------------------------------------- ---------svm_name ABCDEFABCDEF www.example.com serverCertificate Authority: www.example.comExpiration Date: Mon Jan 01 01:00:00 2024svm_name ABCDEFABCDEF www.example.com server-chainCertificate Authority: www.example.comExpiration Date: Mon Jan 01 01:00:00 2024