Failed To Request Local Certificates; Failed To Obtain Crls - HPE FlexFabric 7900 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 7900 Series:
Table of Contents

Advertisement

5.
Check the registration policy on the CR or RA, and make sure the attributes of the PKI entity
meet the policy requirements.
6.
Obtain the CRL from the CRL repository.
7.
Specify the correct source IP address that the CA server can accept. For the correct settings,
contact the CA administrator.
8.
Synchronize the system time of the device with the CA server.
9.
If the problem persists, contact Hewlett Packard Enterprise recommends Support.

Failed to request local certificates

Symptom
Local certificate requests cannot be submitted.
Analysis
The network connection is down, for example, because the network cable is damaged or the
connectors have bad contact.
No CA certificate has been obtained before you submit the certificate request.
The certificate request URL is incorrect or is not specified.
The certificate request reception authority is incorrect or is not specified.
The required parameters are not configured for the PKI entity or are mistakenly configured.
No key pair is specified for the PKI domain for certificate request, or the key pair is changed
during a certificate request process.
Exclusive certificate request applications are running in the PKI domain.
The PKI domain is not specified with the source IP address of the PKI protocol packets that the
CA server can accept, or is specified with an incorrect one.
The system time of the device is not synchronized with the CA server.
Solution
1.
Check for and fix any network connection problemes.
2.
Obtain or import the CA certificate.
3.
Use ping to verify that the CA or RA is accessible from the specified certificate request URL.
4.
Specify the correct certificate request URL.
5.
Check the registration policy on the CR/RA, and make sure the attributes of the PKI entity meet
the policy requirements.
6.
Specify the key pair used for certificate request in the PKI domain, or remove the key pair
specified in the PKI and submit a certificate request again.
7.
Use pki abort-certificate-request domain to abort the certificate request.
8.
Specify the correct source IP address that the CA server can accept. For the correct settings,
contact the CA administrator.
9.
Synchronize the system time of the device with the CA server.
10. If the problem persists, contact Hewlett Packard Enterprise recommends Support.

Failed to obtain CRLs

Symptom
CRLs cannot be obtained.
95

Advertisement

Table of Contents
loading

Table of Contents