Pki Fails After Reboot; Cannot Import Certificate And Rsa Key Pairs From Backup - Cisco 9134 - MDS Multilayer Fabric Switch Troubleshooting Manual

Mds 9000 family
Hide thumbs Also See for 9134 - MDS Multilayer Fabric Switch:
Table of Contents

Advertisement

Digital Certificate Issues
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
CA certificate 0:
subject= /emailAddress=amandke@cisco.com/C=IN/ST=Karnataka/L=Bangalore/O=Cisco/O
U=netstorage/CN=Aparna CA
issuer= /emailAddress=amandke@cisco.com/C=IN/ST=Karnataka/L=Bangalore/O=Cisco/OU
=netstorage/CN=Aparna CA
serial=0560D289ACB419944F4912258CAD197A
notBefore=May
notAfter=May
MD5 Fingerprint=65:84:9A:27:D5:71:03:33:9C:12:23:92:38:6F:78:12
purposes: sslserver sslclient ike

PKI Fails After Reboot

Symptom
Table 24-5
PKI Fails After Reboot
Symptom
Possible Cause
PKI fails after a
Certificates not saved to NVRAM.
reboot.

Cannot Import Certificate and RSA Key Pairs from Backup

Symptom
Table 24-6
Cannot Import Certificate and RSA Key Pairs from Backup
Symptom
Possible Cause
Cannot import
Configured trust point is not empty.
certificate and RSA
key pairs from
backup.
An RSA key pair exists with the same
name as the trust point that the import
failed for.
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
24-10
3 22:46:37 2005 GMT
3 22:55:17 2007 GMT
PKI fails after reboot.
Cannot import certificate and RSA key pairs from backup.
Chapter 24
Solution
Save the running-config to startup- config to save the trust
point to startup. Then reimport the certificates. See the
"Configuring Certificates on the MDS Switch Using Fabric
Manager" section on page 24-5
Certificates on the MDS Switch Using the CLI" section on
page
24-7.
Solution
Delete the identity certificate, the CRL, and CA
certificates, and then disassociate the RSA key pair from
the trust point in that order. See the
and RSA Key Pairs from Backup Using Fabric Manager"
section on page 24-11
or the
RSA Key Pairs from Backup Using the CLI" section on
page
24-11.
Delete the RSA key pair.
Choose Switches > Security > PKI in Fabric Manager.
Right-click the RSA key pair that you want to delete and
click Delete Row.
Or use the no crypto key zeroize rsa CLI command
Troubleshooting Digital Certificates
or the
"Configuring
"Importing Certificate
"Importing Certificate and
OL-9285-05

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents