Troubleshooting Pki; Failed To Retrieve A Ca Certificate - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

# Create certificate attribute group mygroup1 and add two attribute rules. The first rule defines
that the DN of the subject name includes the string aabbcc, and the second rule defines that the IP
address of the certificate issuer is 10.0.0.1.
[Switch] pki certificate attribute-group mygroup1
[Switch-pki-cert-attribute-group-mygroup1] attribute 1 subject-name dn ctn aabbcc
[Switch-pki-cert-attribute-group-mygroup1] attribute 2 issuer-name ip equ 10.0.0.1
[Switch-pki-cert-attribute-group-mygroup1] quit
# Create certificate attribute group mygroup2 and add two attribute rules. The first rule defines
that the FQDN of the alternative subject name does not include the string of apple, and the second
rule defines that the DN of the certificate issuer name includes the string aabbcc.
[Switch] pki certificate attribute-group mygroup2
[Switch-pki-cert-attribute-group-mygroup2] attribute 1 alt-subject-name fqdn nctn
apple
[Switch-pki-cert-attribute-group-mygroup2] attribute 2 issuer-name dn ctn aabbcc
[Switch-pki-cert-attribute-group-mygroup2] quit
Configure the certificate attribute access control policy:
3.
# Create the certificate attribute access control policy of myacp and add two access control rules.
[Switch] pki certificate access-control-policy myacp
[Switch-pki-cert-acp-myacp] rule 1 deny mygroup1
[Switch-pki-cert-acp-myacp] rule 2 permit mygroup2
[Switch-pki-cert-acp-myacp] quit
Apply the SSL server policy and certificate attribute access control policy to HTTPS service and
4.
enable HTTPS service:
# Apply SSL server policy myssl to HTTPS service.
[Switch] ip https ssl-server-policy myssl
# Apply the certificate attribute access control policy of myacp to HTTPS service.
[Switch] ip https certificate access-control-policy myacp
# Enable HTTPS service.
[Switch] ip https enable

Troubleshooting PKI

Failed to retrieve a CA certificate

Symptom
Failed to retrieve a CA certificate.
Analysis
The network connection is not proper. For example, the network cable might be damaged or loose.
No trusted CA is specified.
The URL of the registration server for certificate request is not correct or not configured.
No authority is specified for certificate request.
The system clock of the switch is not synchronized with that of the CA.
309

Advertisement

Table of Contents
loading

Table of Contents