Failed To Obtain Crls; Failed To Import The Ca Certificate - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

Failed to obtain CRLs

Symptom
CRLs cannot be obtained.
Analysis
The network connection is down because, for example, the network cable is damaged or the
connectors have bad contact.
No CA certificate has been obtained before you try to obtain CRLs.
The URL of the CRL repository is not configured, and the proper URL cannot be obtained from the
CA certificate or local certificates in the PKI domain.
The specified URL of the CRL repository is incorrect.
The device tries to obtain CRLs through SCEP, but the PKI domain does not have local certificates,
or the key pairs in the certificates have been changed or the PKI domain has incorrect URL for
certificate request.
The specified URL of the CRL repository contains incomplete address (for example, no host name or
IP address exists) and the LDAP server configuration does not exist or is incorrect in the PKI domain.
The CA does not issue CRLs.
The PKI domain is not specified with the source IP address of the PKI protocol packets that the CA
server can accept, or is specified with an incorrect one.
Solution
Make sure the network connection is physically proper.
1.
Obtain or import the CA certificate.
2.
If the URL of the CRL repository cannot be obtained, configure correct URL for certificate request,
3.
and obtain the local certificate successfully. The public key in the certificate must match the public
key in the local key pair.
Make sure the URL of the CRL repository contains the complete address, or the PKI domain is
4.
specified with the correct LDAP server.
The CA issues the CRLs.
5.
Specify the correct source IP address for PKI protocol packets that the CA server can accept. For
6.
the correct settings, contact the CA server administrator.

Failed to import the CA certificate

Symptom
The CA certificate cannot be imported.
Analysis
CRL checking is enabled, but CRLs do not exist locally or CRLs cannot be obtained.
The specified format does not match the actual format of the imported file.
Solution
Use undo crl check enable to disable CRL checking.
1.
Make sure the format of the imported file is proper.
2.
149

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents