IBM Support

Deploy to Runtime Precheck fails with error certificate doesn't match

Troubleshooting


Problem

When you select Precheck as part of deploying an Automation Document Processing to runtime, the precheck fails.  The cpds pod log shows:
ERROR   ] [DBAContentDeployment]  UTIL Error:  canPingGitServer: error.exception.GIT_failToConnect
javax.net.ssl.SSLPeerUnverifiedException: Certificate for <icp4adeploy-cdra-svc.ejsentdemo.svc>
 doesn't match any of the subject alternative names: [list of services]

Cause

IBM Cloud Pak for Business Automation propagates certificate information throughout the system as needed to make SSL calls.  If changes are made to the deployment, the changes can alter where the certificate information needs to be propagated to.  The deployment operators cannot always detect that the change is needed.

Resolving The Problem

Delete the <meta.name>-fncm-custom-ssl-secret through the console or by using the oc delete secret command.  Deleting this secret causes the certificate information to repropagate as needed.

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBYVB","label":"IBM Cloud Pak for Business Automation"},"ARM Category":[{"code":"a8m3p000000hAKPAA2","label":"Operate-\u003EADP Install\\Upgrade\\Setup"}],"ARM Case Number":"TS013447808","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
10 July 2023

UID

ibm17010761