Skip to content
搜索以了解InterSystems产品和解决方案,职业机会等。

Advisory: Expiring Certificate Authority Certificates

December 8, 2020 – Advisory: Expiring Certificate Authority Certificates

InterSystems has identified an issue with product distributions containing Certificate Authority certificates that expire at the end of 2020. This issue does not affect system operation or system security in any way, although it does generate alerts about expiring certificates in the cconsole.log or messages.log files. The messages may be ignored and there are instructions below to eliminate them.

The issue affects the following versions:

  • Caché and Ensemble 2017.1, 2017.2, and 2018.1
  • All released versions of InterSystems IRIS and InterSystems IRIS for Health
  • HealthShare products based on the above versions

The System Monitor generates these messages because <install-dir>/dev/CACerts/AllCA.cer is referenced in ISC.FeatureTracker.SSL.Config. The file AllCA.cer contains certificates that expire at the end of 2020. Its use has been deprecated starting with Caché and Ensemble 2018.1.4, and IRIS 2020.1.0+.

The recommended mitigation is to remove or rename <install-dir>/dev/CACerts/AllCA.cer. Note that this file may be re-created if you upgrade an instance, so you may need to perform this mitigation step after each upgrade to or installation of an affected version. The expiring certificates will no longer be included in distributions starting with Caché and Ensemble 2018.1.5, IRIS 2019.1.2, and IRIS 2020.1.1.

Deleting this file does not affect any default InterSystems product functionality or the security of any provided software utilities. If your Caché or Ensemble application uses AllCA.cer or the ThawteCA.cer file (in the same directory), please contact the Worldwide Response Center (WRC) for assistance.

If you have any questions regarding this alert, please contact the Worldwide Response Center.

Example cconsole.log/messages.log entries (note that there may be variations depending on version):

12/02/20-11:00:25:869 (9968) 2 [Utility.Event] 6 SSL/TLS Certificate(s) expiring within 30 days. See messages.log for details.

12/02/20-11:00:25:871 (9968) 1 [Utility.Event] Certificate 0 Issuer CN=Thawte Timestamping CA,OU=Thawte Certification,O=Thawte,L=Durbanville,ST=Western Cape,C=ZA (Subject CN=Thawte Timestamping CA,OU=Thawte Certification,O=Thawte,L=Durbanville,ST=Western Cape,C=ZA)  expires in 29 days (2020-12-31).

12/02/20-11:00:25:873 (9968) 0 [Utility.Event] Certificate 0 Issuer CN=Thawte Timestamping CA,OU=Thawte Certification,O=Thawte,L=Durbanville,ST=Western Cape,C=ZA in file C:\InterSystems\20201IRIS\dev\CAcerts\AllCA.cer used by configuration(s) SSL/TLS - "ISC.FeatureTracker.SSL.Config"

12/02/20-11:00:25:875 (9968) 1 [Utility.Event] Certificate 0 Issuer emailAddress=personal-basic@thawte.com,CN=Thawte Personal Basic CA,OU=Certification Services Division,O=Thawte Consulting,L=Cape Town,ST=Western Cape,C=ZA (Subject emailAddress=personal-basic@thawte.com,CN=Thawte Personal Basic CA,OU=Certification Services Division,O=Thawte Consulting,L=Cape Town,ST=Western Cape,C=ZA)  expires in 29 days (2020-12-31).

12/02/20-11:00:25:932 (9968) 0 [Utility.Event] Certificate 1 Issuer emailAddress=premium-server@thawte.com,CN=Thawte Premium Server CA,OU=Certification Services Division,O=Thawte Consulting cc,L=Cape Town,ST=Western Cape,C=ZA in file C:\InterSystems\20201IRIS\dev\CAcerts\AllCA.cer used by configuration(s) SSL/TLS - "ISC.FeatureTracker.SSL.Config"

12/02/20-11:00:25:947 (9968) 0 [Utility.Event] Certificate 1 Issuer emailAddress=server-certs@thawte.com,CN=Thawte Server CA,OU=Certification Services Division,O=Thawte Consulting cc,L=Cape Town,ST=Western Cape,C=ZA in file C:\InterSystems\20201IRIS\dev\CAcerts\AllCA.cer used by configuration(s) SSL/TLS - "ISC.FeatureTracker.SSL.Config"

These messages are generated at 11am each day, and after each restart.

最新警报和通知

Aug 21, 2024
InterSystems 已修复了一个缺陷,在极少数情况下,该缺陷可能导致多卷数据库出现数据库损坏或 错误。只有被截断的数据库才存在风险。
Jun 03, 2024
从发布InterSystems IRIS®数据平台2022.3开始,InterSystems修改了许可证强制执行机制,以包括REST和SOAP请求。由于这种变化,在升级后,使用REST或SOAP的非处理器核数的许可证环境下,用户可能会遇到更高的许可证消耗。要确定此警报是否适用于您的InterSystems许可证,请按照下面链接的FAQ中的说明进行操作。
May 01, 2024
InterSystems has corrected an issue that can cause a small number of SQL queries to return incorrect results. See below for the specifics on impacted queries.
Nov 14, 2023
There are 10 alerts in the HealthShare HS2023-02 Alert communication. An alert summary for each issue is shown is in the table below. Details for each alert are contained in the attached document: HS2023-02-Communication.
Jun 17, 2023
InterSystems 已纠正导致进程内存使用量增加的缺陷。
May 11, 2023
InterSystems已经解决了影响Caché、Ensemble、HealthShare、InterSystems IRIS、InterSystems IRIS for Health、HealthShare HealthConnect和TrakCare的安全漏洞。 这些漏洞影响到InterSystems所有版本的产品。
Apr 28, 2023
InterSystems 已修复了一个缺陷,该缺陷可能会导致使用 IBM POWER8 或更高版本的 POWER 处理器的 AIX 系统上的数据库和Journal日志文件损坏。只有在使用数据库或Journal日志加密时才会触发此缺陷。
Apr 11, 2023
InterSystems已修复一个缺陷,该缺陷在罕见情况下会导致ECP客户端不稳定。
Apr 06, 2023
InterSystems 已修复一个导致SQL查询返回不正确结果的缺陷。该缺陷存在于以下产品和基于这些产品的任何InterSystems产品中。