Cannot Export Identity Certificate In Pkcs#12 Format; Certificate Fails At Peer; Configuring Certificates On The Mds Switch Using Fabric Manager - Cisco 9134 - MDS Multilayer Fabric Switch Troubleshooting Manual

Mds 9000 family
Hide thumbs Also See for 9134 - MDS Multilayer Fabric Switch:
Table of Contents

Advertisement

Chapter 24
Troubleshooting Digital Certificates
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

Cannot Export Identity Certificate in PKCS#12 Format

Symptom
Table 24-3
Cannot Export Identity Certificate in PKCS#12 Format
Symptom
Possible Cause
Cannot export
RSA keys not exportable.
identity certificate in
PKCS#12 format.

Certificate Fails at Peer

Symptom
Table 24-4
Certificate Fails at Peer
Symptom
Possible Cause
Certificate fails at
FQDN changed after certificate was
peer.
issued.
Local and remote clocks are not
synchronized.
Peer does not recognize CA issuing the
certificate.

Configuring Certificates on the MDS Switch Using Fabric Manager

To configure certificates on an MDS switch using Fabric Manager, follow these steps:
Step 1
Choose Switches and set the LogicalName field to configure the switch host name.
Step 2
Choose Switches > Interfaces > Management > DNS and set the DefaultDomainName field to
configure the DNS domain name for the switch.
Follow these steps to create an RSA key pair for the switch:
Step 3
a.
b.
c.
OL-9285-05
Cannot export identity certificate in PKCS#12 format.
Certificate fails at peer.
Choose Switches > Security > PKI and select the RSA Key-Pair tab.
Click Create Row and set the name and size field.
Check the Exportable check box and click Create.
Solution
Create exportable RSA keys. Choose Switches > Security
> PKI in Fabric Manager and click Create Row. Check the
Exportable check box and create an RSA key pair.
Or use the crypto key generate rsa exportable CLI
command.
Solution
Revoke certificate and re-create. See the
Certificates on the MDS Switch Using Fabric Manager"
section on page 24-5
or the
the MDS Switch Using the CLI" section on page
If the clocks are not synchronized, the certificate may
appear to be expired. Validate the clocks on the local and
peer device.
Create a certificate for the CAs known to the peer device.
See the
"Configuring Certificates on the MDS Switch
Using Fabric Manager" section on page 24-5
"Configuring Certificates on the MDS Switch Using the
CLI" section on page
24-7.
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
Digital Certificate Issues
"Configuring
"Configuring Certificates on
24-7.
or the
24-5

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents