Problem Statement
Avaya Application Enablement Services (AES) reports a Minor avAesCertificateFailure alarm. The alarm description indicates that a certificate is about to expire or has already expired.
Impact
Certificate expiration can affect secure HTTPS access to AES and may disrupt integrations or services that rely on trusted TLS certificates if the certificate is expired or not trusted by clients.
Alarm
avAesCertificateFailure
Troubleshooting Steps
- Confirm the active alarm details in the monitoring dashboard or AES alarm view, including severity, alarm code, and affected AES system.
- Access the AES management interface over HTTPS and inspect the presented certificate details, including subject, issuer, validity start date, and expiration date.
- Check whether the AES server certificate, CA certificate, or any certificate chain component is expired or nearing expiration.
- Verify whether the certificate is self-signed, internally issued, or publicly issued, and confirm the correct renewal process for that certificate type.
- If the certificate is expired or near expiration, generate or obtain a renewed certificate using the appropriate certificate signing request and certificate authority process for the environment.
- Import or install the renewed certificate and any required intermediate/root CA certificates into AES according to the supported AES certificate-management procedure.
- Restart or refresh affected AES web/security services if required by the AES certificate installation workflow.
- Reconnect to the AES HTTPS interface and confirm that the renewed certificate is presented with the expected validity dates and trusted certificate chain.
- Confirm that the avAesCertificateFailure alarm clears in the monitoring dashboard. If it remains active, resynchronize polling or recheck for additional expired certificates on the AES system.
Resolution
No ticket-specific remediation details were recorded because the request was merged into another request. For this alarm, the expected resolution is to identify the expired or expiring AES certificate, renew or replace it with a valid certificate and complete certificate chain, then verify that HTTPS presents the new certificate and the avAesCertificateFailure alarm clears.