Failed To Request Local Certificates - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

Specify the key pair used for certificate request in the PKI domain, generate the proper key pair,
4.
and make sure it matches the local certificates to the obtained.
Reference the proper PKI entity in the PKI domain, and correctly configure the PKI entity.
5.
Obtain CRLs.
6.
Specify the correct source IP address for PKI protocol packets that the CA server can accept. For
7.
the correct settings, contact the CA server administrator.
Synchronize the system time of the device with the CA server.
8.

Failed to request local certificates

Symptom
Local certificate requests cannot be submitted.
Analysis
The network connection is down because, for example, the network cable is damaged or the
connectors have bad contact.
No CA certificate has been obtained before you submit the certificate request.
The URL of the registration server is not correct or not specified.
The registration acceptance authority is not specified or is not correctly specified.
The required parameters are not configured for the PKI entity or are mistakenly configured.
No key pair is specified for the PKI domain for certificate request, or the key pair is changed during
a certificate request process.
Exclusive certificate request applications are running in the PKI domain.
The PKI domain is not specified with the source IP address of the PKI protocol packets that the CA
server can accept, or is specified with an incorrect one.
The system time of the device is not synchronized with the CA server.
Solution
Make sure the network connection is physically proper.
1.
Obtain or import the CA certificate.
2.
Use ping to verify that the registration server is reachable.
3.
Specify the correct URL of the registration server.
4.
Check the registration policy on the CR/RA, and make sure the attributes of the PKI entity meet the
5.
policy requirements.
Specify the key pair used for certificate request in the PKI domain, or remove the key pair specified
6.
in the PKI and submit a certificate request again.
Use pki abort-certificate-request domain to abort the certificate request.
7.
Specify the correct source IP address for PKI protocol packets that the CA server can accept. For
8.
the correct settings, contact the CA server administrator.
Synchronize the system time of the device with the CA server.
9.
148

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents