R3303-HP HSR6800 Routers Security Configuration Guide

239
Troubleshooting PKI
Failed to obtain a CA certificate
Symptom
Failed to obtain a CA certificate.
Analysis
Possible reasons include:
The network connection is not proper. For example, the network cable might be damaged or loose.
No trusted CA is specified.
The URL of the registration server for certificate request is not correct or not configured.
No authority is specified for certificate request.
The system clock of the device is not synchronized with that of the CA.
Solution
1. Make sure the network connection is physically proper.
2. Check that the required commands are configured properly.
3. Use the ping command to verify that the RA server is reachable.
4. Specify the authority for certificate request.
5. Synchronize the system clock of the device with that of the CA.
Failed to request a local certificate
Symptom
Failed to request a local certificate.
Analysis
Possible reasons include:
The network connection is not proper. For example, the network cable might be damaged or loose.
No CA certificate has been obtained.
The current key pair has been bound to a certificate.
No trusted CA is specified.
The URL of the registration server for certificate request is not correct or not configured.
No authority is specified for certificate request.
Some required parameters of the entity DN are not configured.
Solution
1. Make sure the network connection is physically proper.
2. Obtain a CA certificate.
3. Regenerate a key pair.
4. Specify a trusted CA.