Re-establishing SIC Trust with Virtual Devices
In the event you encounter connectivity problems due to the loss of SIC Trust for a specific Virtual Device (Virtual System or Virtual Router), you can use the procedure below to manually re-establish the SIC trust.
To manually re-establish SIC Trust with a Virtual Device:
Follow the instructions in the sk34098.
- On the VSX Gateway or each VSX Cluster Member:
- Connect to the command line the VSX Gateway or each VSX Cluster Member.
- Log in to the Expert mode.
- Examine the VSX configuration to determine the ID of the Virtual Device:
vsx stat -v
- Reset the SIC with the specified Virtual Device:
vsx sic reset <
ID>
- On the Management Server:
- Connect to the command line the Management Server.
- Log in to the Expert mode.
- On the Multi-Domain Server, change the context to the applicable Target Domain Management Server used to manage the Virtual Device:
# mdsenv <
IP Address or Name of Domain Management Server>
- Determine the SIC name of the Virtual Device:
# cpca_client lscert -stat valid -kind SIC | grep -i -A 2 <
Name of Virtual Device Object>
- Revoke the SIC certificate of the Virtual Device:
# cpca_client revoke_cert -n <
CN=...,O=...,>
- Connect with SmartConsole to the Security Management Server or Main Domain Management Server used to manage the VSX Cluster.
- From the view or , double-click the Virtual Device object.
- Click .
This action creates a new SIC certificate for the Virtual Device and saves it on the VSX Gateway or each VSX Cluster Member.