cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted

Root certificate expiration

Jump to solution

Regarding the issue with the expiring root cetificate-- - I  have EPO 5.9 managing 500 servers using VS 8.8. I see that the primary certificate Is installed on the EPO server but does it need to be on all the endpoint servers also?

2 Solutions

Accepted Solutions
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 8

Re: Root certificate expiration

Jump to solution

Yes, That is correct.

There is one Certificate which is getting expired on 30/05/2020.

You need to check below one:

Either the below one or AAA should be available:

certcomm.PNG

The primary certificate that needs to be validated is in a customer's environment as below.

Subject      CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
Thumbprint   2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Expiration     2038-01-18 5:59:59 PM


To quickly determine if a system is running the primary certificate, an administrator can query for the existence of the following registry key:

Also this can checked from the MMC to see the certificate.

Having said that this should not affect you agent to service communication.

Was my reply helpful?

If you find this post useful, please give it a Kudos! Also, please don't forget to select "Accept as a Solution" if this reply resolves your query!

View solution in original post

Highlighted

Re: Root certificate expiration

Jump to solution

HI All,

I'm able to push the same certificate through ePO, and it worked for all my Windows 2K8,12,16 servers for this I have used KB92948.

But my query is, I'm unable to find the certificate status of Win 2K0 and 2K3 servers in ePO. So is there any way to get the status of this in ePO? Kindly help. @vnaidu 

Thanks in advance.

View solution in original post

7 Replies
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 8

Re: Root certificate expiration

Jump to solution

Hello @mmzathti 

Thanks for your post.

MA communication to an On-Prem ePO server is not affected.

Additionally, You can refer the below KB article for cert related.

https://kc.mcafee.com/corporate/index?page=content&id=KB92937

Was my reply helpful?

If you find this post useful, please give it a Kudos! Also, please don't forget to select "Accept as a Solution" if this reply resolves your query! 

Highlighted

Re: Root certificate expiration

Jump to solution

I'm sorry but I am still not clear on whether I need to do anything.  My on-prem EPO server does have the good primary cert.  Is that adequate?

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 8

Re: Root certificate expiration

Jump to solution

Yes, That is correct.

There is one Certificate which is getting expired on 30/05/2020.

You need to check below one:

Either the below one or AAA should be available:

certcomm.PNG

The primary certificate that needs to be validated is in a customer's environment as below.

Subject      CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
Thumbprint   2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Expiration     2038-01-18 5:59:59 PM


To quickly determine if a system is running the primary certificate, an administrator can query for the existence of the following registry key:

Also this can checked from the MMC to see the certificate.

Having said that this should not affect you agent to service communication.

Was my reply helpful?

If you find this post useful, please give it a Kudos! Also, please don't forget to select "Accept as a Solution" if this reply resolves your query!

View solution in original post

Highlighted

Re: Root certificate expiration

Jump to solution

HI All,

I'm able to push the same certificate through ePO, and it worked for all my Windows 2K8,12,16 servers for this I have used KB92948.

But my query is, I'm unable to find the certificate status of Win 2K0 and 2K3 servers in ePO. So is there any way to get the status of this in ePO? Kindly help. @vnaidu 

Thanks in advance.

View solution in original post

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 6 of 8

Re: Root certificate expiration

Jump to solution

Hi @Hemurali 

Article https://kc.mcafee.com/corporate/index?page=content&id=KB92948 has the details how to query it from EPO.

Highlighted

Re: Root certificate expiration

Jump to solution
Hi @patrakshar,

Thanks for the reply. I have already followed the same KB for querying from ePO and I mentioned the same in my earlier post as well. But as per that KB, I think that only supports non EOL versions of Windows.

But I want to get the status of EOL(2000,2003/R2) Windows. Is there any way that we can get?
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 8 of 8

Re: Root certificate expiration

Jump to solution

Those OS are not supported any more and the provided tools are not tested on those OS. 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community