R3303-HP HSR6800 Routers Security Configuration Guide

240
5. Use the ping command to verify that the RA server is reachable.
6. Specify the authority for certificate request.
7. Configure the required entity DN parameters.
Failed to obtain CRLs
Symptom
Failed to obtain CRLs.
Analysis
Possible reasons include:
The network connection is not proper. For example, the network cable might be damaged or loose.
No CA certificate has been obtained before you try to obtain CRLs.
The IP address of LDAP server is not configured.
The CRL distribution URL is not configured.
The LDAP server version is wrong.
The domain name of the CRL distribution point failed to be resolved.
Solution
1. Make sure the network connection is physically proper.
2. Obtain a CA certificate.
3. Specify the IP address of the LDAP server.
4. Specify the CRL distribution URL.
5. Re-configure the LDAP version.
6. Configure the correct DNS server that can resolve the domain name of the CRL distribution point.