Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Blog
  • Questions
  • Learning
    • E-learning Courses
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Tutorials
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • DataMiner Insights
      • Security
      • Integration Studio
      • System Architecture
      • DataMiner Releases & Updates
      • DataMiner Apps
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
  • Downloads
  • More
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
      • General Inquiries
      • DataMiner DevOps Support
      • Commercial Requests
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

DMS system IIS SSL certificate

Solved1.23K views18th July 2023
0
Seetharam Subbharaju32 3rd June 2021 0 Comments

Hi,

Greetings DOJO Hall.

Singtel used Tenable software to do a Windows Server scan on DMA1,2,3,DEV
Attached is the full report we only look at severity = high, critical.

DMA1 VM   (private IP 172.30.105.X)

DMA2 VM   (private IP 172.30.105.X)

DMA3 VM   (private IP 172.30.105.X)

DMA DEV   (private IP 172.30.105.X)

The DMA s are all running Web Servers.

Tenable software :51192 SSL Certificate General Medium[ severity]  172.30.105.5 DMA-DEV Server.

 

Tenable software :Synopsis: The SSL certificate for this service cannot be trusted

 

Tenable software: The following certificate was at the top of the certificate

chain sent by the remote host, but it is signed by an unknown

certificate authority :

Solution: Purchase or generate a proper SSL certificate for this service.

I tried self signed certificate does seem to work.

Please advise if Singtel need to purchase SSL certificate for DMA Web Servers or there is a work around.

Regard

Raj

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 18th July 2023

2 Answers

  • Active
  • Voted
  • Newest
  • Oldest
1
Wim Bruynooghe [SLC] [DevOps Advocate]6.59K Posted 3rd June 2021 0 Comments

This depends on the use case:

  • For DMA agents which are accessed only within a private network, then you can use certificates that are signed by a self-signed root certificate. This root certificate will have to be installed on all agents and client machines (possible via a domain controller) so that the certificates are seen as trusted.
  • If a DMA agent is connected to the public Internet (or via a Dashboards Gateway/Portal), and can be accessed via a public hostname, then a certificate has to be used from a certificate authority so that any client connecting via the public hostname will see the certificate as trusted.
Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 18th July 2023
1
Ive Herreman [SLC] [DevOps Enabler]13.52K Posted 3rd June 2021 0 Comments

Hi Seetharam,

For a certificate to be trusted, it needs to be obtained from a valid Certificate authority.

There are various options, some of them are paid, others offer free certificates.

A self-signed certificate will be marked as insecure as it's not generated by a valid Certificate authority.

Ive Herreman [SLC] [DevOps Enabler] Answered question 3rd June 2021
Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas

Recent questions

Web Applications exception in Cube due to invalid certificate 0 Answers | 0 Votes
Redundancy Groups and Alarming – Duplicate Alarms 0 Answers | 0 Votes
Correlation Engine: “Test rule” doesn’t result in a hit, despite functional rule 1 Answer | 3 Votes

Question Tags

adl2099 (115) alarm (62) Alarm Console (82) alarms (100) alarm template (83) Automation (223) automation scipt (111) Automation script (167) backup (71) Cassandra (180) Connector (109) Correlation (69) Correlation rule (52) Cube (151) Dashboard (194) Dashboards (188) database (83) DataMiner Cube (57) DIS (81) DMS (71) DOM (140) driver (65) DVE (56) Elastic (83) Elasticsearch (115) elements (80) Failover (104) GQI (159) HTTP (76) IDP (74) LCA (152) low code app (166) low code apps (93) lowcodeapps (75) MySQL (53) protocol (203) QAction (83) security (88) SNMP (86) SRM (337) table (54) trending (87) upgrade (62) Visio (539) Visual Overview (345)
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin