Problem Statement
Avaya Aura Session Manager raises a major certificate expiration alarm for a Session Manager identity certificate, such as securitymodule_http, when the certificate is nearing its expiration date.
Impact
If the certificate expires, Session Manager may be unable to establish new secured SIP, HTTP/Personal Profile Manager, or System Manager communication sessions. Security may also be compromised where TCP or UDP fallback is not available or not permitted.
Alarm
OP_MMTC20049 - Certificates nearing expiration date (Major)
Troubleshooting Steps
- Review the active alarm details and identify the certificate named in the equipment information, such as the Session Manager identity certificate securitymodule_http.
- Confirm the remaining certificate validity period. Session Manager typically logs warning messages starting 60 days before expiration, raises a major alarm when the certificate is within 30 days of expiration, and raises a critical alarm when the certificate is within 15 days of expiration.
- Determine whether the affected certificate is used for SIP, HTTP/Personal Profile Manager, or communication between Session Manager and System Manager.
- Obtain or generate a replacement certificate according to the applicable Avaya Aura Session Manager administration procedure and the organization certificate authority process.
- Install the renewed certificate on the affected Session Manager component.
- Verify that the new certificate is valid, trusted, and has the expected expiration date.
- Confirm that secured connections continue to function after the certificate update.
- Check the alarm dashboard or Session Manager alarms to confirm the certificate expiration alarm clears. If it does not clear automatically, refresh alarm status or follow the product procedure for clearing resolved alarms.
Resolution
Renew and install the expiring Session Manager certificate before it reaches expiration. After the replacement certificate is installed and validated, the OP_MMTC20049 certificate expiration alarm should clear once Session Manager recognizes the updated certificate state.