Trouble-shooting TLS

This section provides some information about common TLS configuration errors.

If TLS isn’t working, the following are items that can cause issues.

Troubleshoot DNS

To obtain the DNS information, issues the following RACLI command on the Recovery Appliance.

racli list san

To check if the certificate has the the DNS information, make sure that the trusted certificate has no information and that the signed certificate has DNS information.

openssl x509 -text -noout -in cert.pem | grep  -i 'dns'
openssl x509 -text -noout -in <>.p12 | grep  -i 'dns'

Troubleshoot Certificates

Get certificate details from metadata table including type.

racli list certificate

Get certificate details from wallet.

orapki wallet display --wallet /raacfs/raadmin/config/ra_wallet/wallet/ --complete

Tips