beautypg.com

Troubleshooting pki, Failed to retrieve a ca certificate, Symptom – H3C Technologies H3C SecBlade LB Cards User Manual

Page 157: Analysis, Solution, Failed to request a local certificate

background image

146

c.

Create the certificate attribute-based access control policy of myacp and add two access

control rules:

[LB] pki certificate access-control-policy myacp

[LB-pki-cert-acp-myacp] rule 1 deny mygroup1

[LB-pki-cert-acp-myacp] rule 2 permit mygroup2

[LB-pki-cert-acp-myacp] quit

d.

Apply the SSL server policy and certificate attribute-based access control policy to HTTPS
service and enable HTTPS service.
# Apply SSL server policy myssl to HTTPS service.

[LB] ip https ssl-server-policy myssl

# Apply the certificate attribute-based access control policy of myacp to HTTPS service.

[LB] ip https certificate access-control-policy myacp

# Enable HTTPS service.

[LB] ip https enable

Troubleshooting PKI

Failed to retrieve a CA certificate

Symptom

Failed to retrieve a CA certificate.

Analysis

Possible reasons include:

The network connection is not proper. For example, the network cable might be damaged or loose.

No trusted CA is specified.

The URL of the registration server for certificate request is not correct or not configured.

No authority is specified for certificate request.

The system clock of the device is not synchronized with that of the CA.

Solution

1.

Make sure the network connection is physically proper.

2.

Check that the required commands are configured properly.

3.

Use the ping command to verify that the RA server is reachable.

4.

Specify the authority for certificate request.

5.

Synchronize the system clock of the device with that of the CA.

Failed to request a local certificate

Symptom

Failed to request a local certificate.

Analysis

Possible reasons include:

This manual is related to the following products: