Industry
Retail
Location
U.S.
Products
IBM Websphere
Company Size
Large
Revenue
$50B+
WebSphere Issue Derails Leading Retailer’s Ability to Manage Applications
During a critical period for any high functioning retail giant, the company suddenly ran into an issue around their critical WebSphere software. Due to SSL certificate trust problems between the Deployment Manager and node agents, the company were unable to stop applications or deploy new code, significantly restricting operational and change activities.
Despite applications continuing to run, all administrative lifecycle operations failed, including wsadmin‑based scripts used for controlled application management. Essentially, their mission-critical software had suddenly ceased to be able to perform all the functions that they needed in order to operate effectively.
The incident presented several challenges that made a resolution tricky:
Unlisted SSL Certificate
The SSL certificate that was being presented by the JVMs and node agents did not appear in any accessible keystore, meaning it was hard to locate the certificate and diagnose the issue.
Keystore Verification Limitations
Although a script was executed to check all keystores, it failed to include TAI certificates in its verification process. This was due to a mismatch between the keystore password and the TAI certificates, which prevented proper checking.
Misleading Certificate Status
Consequently, the certificate appeared to be missing when, in reality, it was present but incorrectly referenced. This confusion complicated the troubleshooting process.
Masked Root Cause
The behavior observed during the incident masked the true underlying cause, making it more difficult to identify and address the real issue during initial investigations.
The retailer eventually turned to independent support to solve their problem.
During a critical period for any high functioning retail giant, the company suddenly ran into an issue around their critical WebSphere software.
Origina Experts’ Deep-Dive Delivers the Desired Result
Expert, independent support turned out to be the right call as from the outset the issue proved difficult to diagnose. The symptoms did not align with a typical SSL certificate expiry or WebSphere configuration issue. Although all servers were running, node agents were unable to reconnect to the Deployment Manager, resulting in missing status information and failures when running basic administrative commands such as server Status. This prompted a deeper review of node agent behaviour and logs.
Our expert’s early analysis confirmed that:
Configuration synchronization between nodes and the Deployment Manager was working.
Despite this, basic WebSphere scripts and administrative tools were failing, consistently referencing an expired certificate that could not be found in any key or trust store.
As the troubleshooting progressed, further deep‑dive sessions were held to compare behavior between working and non‑working nodes. Analysis then shifted to potential external interception.
After an in-depth look into the customers systems, a breakthrough was finally reached. It turns out that the certificate alias used by the node was pointing to an incorrect (TAI) certificate. A keystore name mismatch caused automated certificate verification scripts to miss the correct certificate entirely.
Once the certificate aliases within Node Default SSL Settings were updated to reference the correct certificate alias, normal behavior was restored. The customer followed Origina’s guidance by updating the certificate aliases in Node Default SSL Settings. After making the adjustment, the affected nodes and JVMs were able to start successfully.
As a result, the SSL trust issue was resolved. The system could now establish secure connections as expected, confirming that the certificate alias configuration was correct. With Origina’s expert, in-depth assistance, the U.S retailer was able to get their systems back up and running again after weeks of uncertainty.
With Origina on-hand to address the issue, the customer could address their WebSphere issues. They managed to:
Address an issue that had persisted for nearly two months without resolution
Restore full administrative control of vital systems
Reduced operational risk
Improved agility in responding to business needs
Enabled timely implementation of updates and fixes
"Before moving the support to Origina, I worked for almost 2 months with the OEM vendors on this issue."
-IT Team Lead, U.S. Retailer