Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Question on SSL Certificate

Sushma
New Contributor
New Contributor

Hi All

In most of the AD connections we are using SSl certificates. But as we see they are already expired but still connection is working.

Can you explain is this expected behavior/How does it work as document says a connection with an expired certificate will not work. 

 

Thank you in Advance!

6 REPLIES 6

rushikeshvartak
All-Star
All-Star
  • Does certificate initially added from UI or from server in keystore ?

Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

Hi @rushikeshvartak @Sushma ,

We are also observing the same behavior in our lower environment.

AD SSL certificate in test env is expired in NOV 2023 and AD connection is still successful and provisioning/ import is working without any issue.

Certificate is uploaded from UI.

Can you explain how this works?

Thanks,
Smitha

  • Can you share certificate expiry screenshot? 
  • Please check AD Certificate validity on server level expiry on UI is coming from DB but Expiry actuals needs to be checked in keystore. You need to take help of support team - devops 

Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

In your connection, are you connecting to SSL port of Active Directory or non ssl port (389)

 

Thanks,
Devang Gandhi
If this reply answered your question, please Accept As Solution and give Kudos to help others who may have a similar problem.

smithamg
Regular Contributor
Regular Contributor

@rushikeshvartak 

Please find the screenshots below. I checked the expiry date in AD server and its same and expired

smithamg_0-1712316308025.pngsmithamg_1-1712316436393.png

@dgandhi we are connecting via SSL port 636

Thanks,
Smitha

Please check ssl expiry from keystore with help of support ticket, which matters 


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.