Failed To Obtain The Ca Certificate; Failed To Obtain Local Certificates - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

Failed to obtain the CA certificate

Symptom
The CA certificate cannot be obtained.
Analysis
The network connection is down, for example, because the network cable is damaged or the
connectors have bad contact.
No trusted CA is specified.
The certificate request URL is incorrect or not specified.
The system time of the device is not synchronized with the CA server.
The source IP address of the PKI protocol packets is not specified or not correct.
The fingerprint of the root CA certificate is illegal.
Solution
1.
Check for and fix any network connection problems.
2.
Verify that the required configurations are correct.
3.
Use ping to verify that the CA or RA is accessible from the specified certificate request URL.
4.
Synchronize the system time of the device with the CA server.
5.
Specify the correct source IP address for PKI protocol packets that the CA server can accept.
6.
Verify the CA certificate's fingerprint on the CA server.
7.
If the problem persists, contact Hewlett Packard Enterprise Support.

Failed to obtain local certificates

Symptom
No local certificates can be obtained.
Analysis
The network connection is down.
No CA certificate has been obtained before you try to obtain local certificates.
The LDAP server is not configured or is incorrectly configured.
No key pair is specified for the PKI domain for certificate request, or the specified key pair does
not match the local certificates to the obtained.
The PKI domain does not reference the PKI entity configuration, or the PKI entity configuration
is incorrect.
CRL checking is enabled, but CRLs do not exist locally or CRLs cannot be obtained.
The CA server does not accept the source IP address specified in the PKI domain, or the source
IP address is incorrect.
The system time of the device is not synchronized with the CA server.
Solution
1.
Check for and fix any network connection problems.
2.
Obtain or import the CA certificate.
3.
Configure the correct LDAP server.
4.
Specify the key pair used for certificate request in the PKI domain, or remove the existing key
pair and submit a certificate request again.
254

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents