
OPERATIONAL DEFECT DATABASE
...

...
HPE Virtual Connect returns a self-signed certificate even when a CA signed certificate has been uploaded and processed by Virtual Connect Manager (VCM). The result may depend on the browser being used. For example, Firefox may return a CA signed certificate but an IE browser may return a self-signed certificate for the same VCM IP address.The following example shows the certificates of IE on the right, and Firefox on the left, for the same VCM IP:This issue occurs because certain browsers like IE prefer to use ECDSA certificates over SHA256 certificates. The CA signed certificate is SHA256 as shown above, and both the self-signed and CA signed certificates exist in VCM. In this case, IE negotiates ECDSA cyphers with VCM, which presents the self- signed certificate to the IE client browser.
Any HPE c7000 BladeSystem enclosure and in all VCM versions.
As a workaround, disable the "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384" cypher suite from the VCM GUI - Users/Authentication - Web SSL Configuration. This leaves the client with only one option to select the CA signed SHA256 certificate.The following is an example of the VCM web SSL configuration page, with the cypher de-selected:Optionally, VCM failover can be performed; this will cause even the standby VCM to disable the ECDSA certificate. However, this step is optional under normal circumstances because any web connection to standby VCM is redirected to the Primary VCM IP address which presents the CA signed certificate. However, a failover will prevent security scanners from detecting a self- signed certificate in the standby VCM instead of a CA signed certificate.RECEIVE PROACTIVE UPDATES: Receive support alerts (such as Customer Advisories), as well as updates on drivers, software, firmware, and customer replaceable components, proactively in your e-mail through HPE Support Alerts. Sign up for Support Alerts at the following URL:Proactive Updates Subscription Form.NAVIGATION TIP:For hints on navigating HPE.com to locate the latest drivers, patches and other support software downloads, refer to theNavigation Tips document.SEARCH TIP:For hints on locating similar documents on HPE.com, refer to theSearch Tips document.
Operating Systems Affected:Not Applicable
No external links available for this bug
Click on a version to see all relevant bugs
Hewlett Packard Enterprise Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.