Old server certificate remains on MetroCluster destination SVM after source renewal
Applies to
- ONTAP 9
- MetroCluster
- SVM server
Issue
- "metrocluster vserver show" reports the MetroCluster SVM relationship as healthy.
Cluster::> metrocluster vserver show -vserver <vserver1>
Cluster: XXXXPartner ConfigurationVserver Vserver State------------------- ---------------------- -----------------<vserver1> <vserver1>-mc healthy- The source SVM lists only the current (renewed) server certificate.
cluster_src::> security certificate show -vserver svm1Vserver Serial Number Certificate Name Type
svm1AAAABBBBCCCCDDDDEEEEFFFF0000111122223333RootCA-Example server-caCertificate Authority: RootCA-ExampleExpiration Date: Sat Oct 27 13:43:57 2040
svm11111222233334444555566667777888899990000svm1.example.com serverCertificate Authority: IssuingCA-ExampleExpiration Date: Sun Jan 24 03:04:14 2027
- The destination SVM lists the current server certificate and an additional older server certificate.
cluster_dst::> security certificate show -vserver svm1-mcVserver Serial Number Certificate Name Type
svm1-mcAAAABBBBCCCCDDDDEEEEFFFF0000111122223333RootCA-Example server-caCertificate Authority: RootCA-ExampleExpiration Date: Sat Oct 27 13:43:57 2040
svm1-mc1111222233334444555566667777888899990000svm1.example.com serverCertificate Authority: IssuingCA-ExampleExpiration Date: Sun Jan 24 03:04:14 2027
svm1-mc99990000AAAABBBBCCCCDDDDEEEEFFFF11112222svm1.example.com_99990000AAAABBBBCCCCDDDDEEEEFFFF11112222serverCertificate Authority: IssuingCA-ExampleExpiration Date: Wed Apr 01 04:12:35 2026
