
Operation Manual – PKI
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 PKI Configuration
1-22
1.13.2 Failed to Request a Local Certificate
I. Symptom
Failed to request a local certificate.
II. Analysis
Possible reasons include these:
z
The network connection is not proper. For example, the network cable may be
damaged or loose.
z
No CA certificate has been retrieved.
z
The current key pair has been bound to a certificate.
z
No trusted CA is specified.
z
The URL of the enrollment server for certificate request is not correct or not
configured.
z
No RA is configured.
z
Some required parameters of the entity DN are not configured.
III. Solution
z
Make sure that the network connection is physically proper.
z
Retrieve a CA certificate.
z
Regenerate a key pair.
z
Specify a trusted CA.
z
Use the
ping
command to check that the RA server is reachable.
z
Configure the RA for certificate request.
z
Configure the required entity DN parameters.
1.13.3 Failed to Retrieve CRLs
I. Symptom
Failed to retrieve CRLs.
II. Analysis
Possible reasons include these:
z
The network connection is not proper. For example, the network cable may be
damaged or loose.
z
No CA certificate has been retrieved before you try to retrieve CRLs.
z
The IP address of LDAP server is not configured.
z
The URL for CRL distribution is not configured.
z
The LDAP server version is wrong.