Page 1 of 1

New Certificates (467)

Posted: Wed Nov 16, 2016 12:51 pm
by MISTERX
We are using SAP. In SAP-Systems the certificates are loaded and stored via Tx STRUST. This will be done by admin. SAP-Systems do not load certs automatically. But a SAP-System generates notices a few days in advance, before actual cert will be invalid.
Yesterday PTV has published new cert - old cert was valid till November, 19th, EOD.
This has happened almost 5 days before validity of actual cert ends.

We were facing the issue, that new cert was active before SAP-System has triggered the coming end of validity and admins missed to renew in STRUST. So at the end SAP-Users were suddenly no longer able to work, because SAP-System was not able to consume PTV-Internet-Services.

To make the long story short: Did anybody know if the renewal of certs by PTV is generally 5 days before end of validity?

Re: New Certificates (467)

Posted: Thu Nov 17, 2016 2:22 pm
by f.gailfuß
From PTV perspective: Certificate updates are always done a few days in advance leaving us enough time to react to deployment problems that might arise. In the past the certificate updates went perfectly smooth, at least from what we know.

Although using renowned certificate providers, we've just learned that the certificate rollout is not always an automatic process but might require manual steps on some systems. Because of this we're going to handle upcoming certificate updates like any other deployment update and announce it in advance.

Re: New Certificates (467)

Posted: Thu Nov 17, 2016 2:33 pm
by MISTERX
Cheers Frank

sounds like a good plan. This will help us!

How (and to whom) the announcement will be published? I personally prefer mail to dedicated receivers - like known technical contacts at customer site.

Is this feasible.

Re: New Certificates (467)

Posted: Thu Nov 17, 2016 2:36 pm
by Bernd Welter
Hello Rolf,
  • For custom clouds we have individual email recipients lists (be aware that your special addresses are part of it)
  • For xServer INTERNET we inform all email addresses who have access to the affected PRODUCTION service (this is based on a webshop).
Best regards Bernd