Issuer Certificate Mismatch when Binding a Self-Signed Certificate Created on NS

Issuer Certificate Mismatch when Binding a Self-Signed Certificate Created on NS

book

Article ID: CTX228102

calendar_today

Updated On:

Description

  • Issuer certificate mismatch error shown trying to bind a self-signed certificate created in NS with the defaut Root CA certificate:
User-added image

Resolution

During major upgrades the default CA certificate in NetScaler may be also updated.
If it happens the server certificate cannot be bound to the new CA certificate (as the certificate is new / no longer matches)
It is not recommended to create self-signed certificates on NetScaler issued from default CA certificate, if they are going to be used for a long period of time or if they are intended to be used in production environments.

Problem Cause

Self singed certificate created with an old NS version. The old certificate was replaced by a new one after an upgrade therefore is not longer valid.

Issue/Introduction

Issue Certificate mismatch when certificate was created using default NS CA certificate