Forum Discussion

syavash's avatar
syavash
Icon for Nimbostratus rankNimbostratus
Aug 18, 2019

SSL instalation health check across active/stnby

Hello,

 

is there a standard health check for SSL installation across an active/stndby scenario?

i have more than 400 websites that are offloading their SSL cert on my cluster. in the past i had cases where i upgraded (a fully synced cluster) stndby to a new firmware and failed over, then lost ssl config for one or two websites. i am planning to upgrade from 13.1.1.2 to 14.1.2. how do i check ssl installation health across the cluster now before going to firmware upgrade procedure?

i know i can use ihealth and have different checks there but dont know where in ihealth i can find related info. or if there is any other method for such situation.

1 Reply

  • Hey Syyavash,

     

    Before you upgrade you just need to make sure you take a UCS file from the active & standy box and then make sure you fully sync the devices as well. You can then go on and upgrade the standby device, make it active and check if config looks fine. If it doesn't look fine, you can then collect another UCS (just in case) and then load the UCS you gathered from it before the upgrade. Config sync and UCS are your best bet for making sure SSL config stays the same.

     

    Best regards,

    Rodrigo