Troubleshooting Pki; Failed To Retrieve A Ca Certificate - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

1848
C
97: PKI C
HAPTER

Troubleshooting PKI

Failed to Retrieve a CA
Certificate
ONFIGURATION
n ctn aabbcc
[Router-pki-cert-attribute-group-mygroup2] quit
3 Configure the certificate attribute-based access control policy
# Create the certificate attribute-based access control policy of myacp and add
two access control rules.
[Router] pki certificate access-control-policy myacp
[Router-pki-cert-acp-myacp] rule 1 deny mygroup1
[Router-pki-cert-acp-myacp] rule 2 permit mygroup2
[Router-pki-cert-acp-myacp] quit
4 Apply the SSL server policy and certificate attribute-based access control policy to
HTTPS service and enable HTTPS service.
# Apply SSL server policy myssl to HTTPS service.
[Router] ip https ssl-server-policy myssl
# Apply the certificate attribute-based access control policy of myacp to HTTPS
service.
[Router] ip https certificate access-control-policy myacp
# Enable HTTPS service.
[Router] ip https enable
Symptom

Failed to retrieve a CA certificate.

Analysis
Possible reasons include these:
The network connection is not proper. For example, the network cable may be
damaged or loose.
No trusted CA is specified.
The URL of the enrollment server for certificate request is not correct or not
configured.
No RA is specified.
The system clock of the device is not synchronized with that of the CA.
Solution
Make sure that the network connection is physically proper.
Check that the required commands are configured properly.
Use the ping command to check that the RA server is reachable.
Configures the RA for certificate request.
Synchronize the system clock of the device with that of the CA.

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents