I need your big help... It is less than 90 days left of expiration of WebSphere 7.0's CA...
The log said:
*** CERTIFICATES WITHIN THE 90 DAYS OF THE CERTIFICATE EXPIRATION THRESHOLD (MAY BE REPLACED WITHIN 90 DAYS) ***;
CWPKI0714I: The certificate expiration monitor has recently run and discovered that the certificates, which are listed in associated messages, will be replaced within the next 90 days. This replacement is based on the configured policy to automatically replace expiring self-signed certificates 60 days prior to expiration. This notification is informs you that problems might arise when the certificates are automatically replaced.
CWPKI0715I: In some cases, automatically replacing certificates can cause outages for Web server plug-ins operating on unmanaged nodes. In such a situation, the plug-in will be unable to contact the application servers over HTTPS because it will be using signers for certificates that have been replaced by the automatic replacement process. To prevent what may be and serious outage you should act before the scheduled replacement date and replace the expiring certificates and update the plug-in kdb to use the new signers.
CWPKI0719I: The default personal certificate in the "NodeRSATokenKeyStore((cell):xxxxNode01Cellnode):xxxxNode01)" keystore is due to expire on Jun 9, 2013 and might be replaced after the Apr 10, 2013 threshold date.
I recieved the CA last 2011 and good till May 14, 2014 but the log warned me and the expiration will be on Jun 9, 2013? How can I extend from June 9, 2013 to May 14, 2014???
Also should I uncheck 2 boxes at: SSL certificate and key management > Manage certificate expiration
* Automatically replace expiring self-signed and chained certificates
* Delete expiring certificates and signers after replacement