Loader

Certificate Troubleshooter

The purpose of this troubleshooter is to help diagnose issues with EMS or OLT certificates: 

  1. Verify that there are no expired certificate alarms within the alarms view.   If these alarms exist, you need to get new certificates before the EMS and OLT can communicate.  Typical custom certificates have lifetimes of two years or less.  (Tellabs self signed certificates are good until 2049)
  2. Verify that there are no certificate expiring alarms within the events view as a preventative measure.  Certificate expiring events are sent once the certificates are down to 90 days and are re-issued weekly until expiry.
  3. You must have a login to the OLT with the certificate admin rights to view the certificates on the OLT.  You can also validate the OLT certificate and validity dates by displaying the certificates at the CLI and verifying their validity: 
  4. On the EMS you can use the Certificate Mgr to see the EMS certificate and check its validity
    First go to the directory \Tellabs\PanoramaPon\bbmgr\server on the server machine and issue the command certificateMgr.bat.
    You will be presented with the main menu, select 99, then 1 display certificate detail.
  5. Select 1, then the name of the device certificate, it will be the one that has the u,u,u attributes.  For stock certificates, it will be named TellabsDevice.  For custom certs, will vary.  You can then check the certificate validity dates: 
  6. Both the EMS and OLT will not allow a certificate to be assigned to device if it is not valid.  So if the certs are both within their validity dates, one other possible issue is that the trust anchors are incorrect.
  7. For proper operation the EMS and OLT must have a certificate signed by someone they trust.
    The device certificate is what a device offers when it tries to authenticate a connection.
    The anchor certificate is what a device uses to authenticate a certificate that is presented to authenticate a connection.
  8. Verify that the certificates are set up properly for operation.
FEEDBACK: Are you happy with this material?