Problem Statement
Avaya Application Enablement Services (AES) reports a Minor certificate alarm indicating that a certificate is about to expire or has expired. The alarm may appear in monitoring as avAesCertificateFailure with alarm code ACT. Related Avaya System Manager (SMGR) certificate alarms, such as TMA000056E, may also be present when SMGR/WebLM certificates are involved.
Impact
Certificate expiry alarms are typically non-service-affecting before expiration, but expired certificates can cause management access, TLS trust, WebLM licensing, or application functionality issues. Some systems may continue operating until a reboot or service restart, after which access or dependent services can fail. If AES uses SMGR/WebLM and the relevant certificate expires, AES may report WebLM SSL connection issues or enter a license grace period.
Alarm
Minor: avAesCertificateFailure, Alarm Code ACT — certificate about to expire or expired. Related SMGR alarm: TMA000056E — certificate about to expire on remote element.
Troubleshooting Steps
- Confirm the active alarm details in monitoring, including product type, alarm severity, maintenance object, alarm code, and whether the alarm is on AES, SMGR, or both.
- Identify which certificate is expiring or expired. Check AES certificate status and also review any related SMGR, Session Manager, or WebLM certificate alarms if AES depends on those services.
- If SMGR/WebLM legacy certificate expiry is suspected, verify certificate validity from the SMGR CLI using the supported keytool command for the applicable version, for example: keytool -list -keystore $JBOSS_HOME/server/avmgmt/conf/tm/keystore/default_keystore.jks -alias weblm_legacy -v | grep Valid. Use the site-approved keystore credential handling process when prompted.
- Review relevant logs for certificate or WebLM SSL symptoms. For AES licensing issues, check /opt/mvap/logs/log.date for WebLM SSL connection errors or license grace-period messages. For SMGR trust-management issues, review tmAuditLog.txt and /var/log/Avaya/mgmt/tm/tmTraceLog.log.
- Determine whether the certificate can be renewed or must be replaced. If SMGR reports that the selected certificate was not issued by the SMGR default CA, use the supported Replace workflow or version-specific Avaya procedure instead of Renew.
- Schedule a maintenance window before remediation. Certificate work may require service restarts. For SMGR, a JBoss restart can make the SMGR web interface unavailable temporarily, and systems using SMGR WebLM may be affected or enter grace until services recover.
- Renew or replace the expiring certificates using the supported Avaya procedure for the installed product and version. If SMGR/WebLM legacy certificates are involved, follow the version-specific WebLM legacy certificate procedure rather than a generic SMGR CA renewal procedure.
- After remediation, verify the updated certificate validity dates from the UI or CLI. If SMGR JBoss was restarted, confirm readiness with the supported status command, for example: /opt/vsp/twiddle/JBossStatus.sh 1200.
- Confirm that AES, SMGR, WebLM, and any dependent services are reachable and operating normally after the maintenance window.
- Monitor the alarm dashboard and device logs to confirm that avAesCertificateFailure and any related certificate alarms clear and do not regenerate.
Resolution
The certificate renewals were completed during a maintenance window. After renewal, monitoring no longer generated the AES certificate expiry alarms.