Certificate Validation with Certificate Revocation Lists
7-46
Oracle Database Advanced Security Administrator's Guide
Oracle Net Tracing File Error Messages Associated with Certificate Validation
The following trace messages, relevant to certificate validation, may be logged
between the
entry
and
exit
entries in the Oracle Net tracing file. Oracle SSL looks
for CRLs in multiple locations, so there may be multiple errors in the trace.
Check the following list of possible error messages for information about how to
resolve them.
CRL signature verification failed with RSA status
Cause:
The CRL signature cannot be verified.
Action:
Ensure that the downloaded CRL is issued by the peer's CA and that
the CRL was not corrupted when it was downloaded. Note that the
orapki
utility verifies the CRL before renaming it with a hash value or before
uploading it to the directory. See
"Certificate Revocation List Management"
on
page 7-40 for information about using
orapki
for CRL management.
CRL date verification failed with RSA status
Cause:
The current time is later than the time listed in the next update field.
You should not see this error if CRL DP is used. The systems searches for the
CRL in the following order:
1.
File system
2.
Oracle Internet Directory
3.
CRL DP
The first CRL found in this search may not be the latest.
Action:
Update the CRL with the most recent copy.
CRL could not be found
Cause:
The CRL could not be found at the configured locations. This will
return error ORA-29024 if the configuration specifies that certificate validation
is require.
Action:
Ensure that the CRL locations specified in the configuration are correct
by performing the following steps:
1.
Use Oracle Net Manager to check if the correct CRL location is configured.
See
"Configuring Certificate Validation with Certificate Revocation Lists"
on
page 7-37
See Also:
Oracle Net Services Administrator's Guide for information
about setting tracing parameters to enable Oracle Net tracing
Summary of Contents for Database Advanced Security 10g Release 1
Page 17: ...xvii ...
Page 20: ...xx ...
Page 24: ...xxiv ...
Page 42: ...xlii ...
Page 44: ......
Page 102: ......
Page 124: ......
Page 246: ...Managing Certificates 8 28 Oracle Database Advanced Security Administrator s Guide ...
Page 284: ......
Page 384: ......
Page 414: ...Physical Security D 6 Oracle Database Advanced Security Administrator s Guide ...
Page 518: ...Index 10 ...