Troubleshooting Pki; Failed To Retrieve A Ca Certificate - 3Com 4510G Configuration Manual

3com switch 4510g family
Table of Contents

Advertisement

# Create certificate attribute group mygroup2 and add two attribute rules. The first rule defines that
the FQDN of the alternative subject name does not include the string of apple, and the second rule
defines that the DN of the certificate issuer name includes the string aabbcc.
[Switch] pki certificate attribute-group mygroup2
[Switch-pki-cert-attribute-group-mygroup2] attribute 1 alt-subject-name fqdn nctn apple
[Switch-pki-cert-attribute-group-mygroup2] attribute 2 issuer-name dn ctn aabbcc
[Switch-pki-cert-attribute-group-mygroup2] quit
3)
Configure the certificate attribute-based access control policy
# Create the certificate attribute-based access control policy of myacp and add two access control
rules.
[Switch] pki certificate access-control-policy myacp
[Switch-pki-cert-acp-myacp] rule 1 deny mygroup1
[Switch-pki-cert-acp-myacp] rule 2 permit mygroup2
[Switch-pki-cert-acp-myacp] quit
4)
Apply the SSL server policy and certificate attribute-based access control policy to HTTPS service
and enable HTTPS service.
# Apply SSL server policy myssl to HTTPS service.
[Switch] ip https ssl-server-policy myssl
# Apply the certificate attribute-based access control policy of myacp to HTTPS service.
[Switch] ip https certificate access-control-policy myacp
# Enable HTTPS service.
[Switch] ip https enable

Troubleshooting PKI

Failed to Retrieve a CA Certificate

Symptom
Failed to retrieve a CA certificate.
Analysis
Possible reasons include these:
The network connection is not proper. For example, the network cable may be damaged or loose.
No trusted CA is specified.
The URL of the registration server for certificate request is not correct or not configured.
No authority is specified for certificate request.
The system clock of the device is not synchronized with that of the CA.
Solution
Make sure that the network connection is physically proper.
Check that the required commands are configured properly.
Use the ping command to check that the RA server is reachable.
Specify the authority for certificate request.
Synchronize the system clock of the device with that of the CA.
10-21

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents