
275
Solution
1.
Use the
undo crl check enable
command to disable CRL checking in the PKI domain.
2.
Make sure the format of the imported file is correct.
3.
If the problem persists, contact Hewlett Packard Enterprise Support.
Failed to import the local certificate
Symptom
The local certificate cannot be imported.
Analysis
•
The PKI domain does not have a CA certificate, and the local certificate file to be imported does
not contain the CA certificate chain.
•
CRL checking is enabled, but the device does not have a CRL in the PKI domain and cannot
obtain one.
•
The specified format in which the local certificate file is to be imported does not match actual
certificate file format.
•
The device and the certificate do not have the local key pair.
•
The certificate has been revoked.
•
The certificate is out of the validity period.
•
The system time is incorrect.
Solution
1.
Obtain or import the CA certificate.
2.
Use the
undo crl check enable
command to disable CRL checking, or obtain the correct CRL
before you import certificates.
3.
Make sure the format of the file to be imported is correct.
4.
Make sure the certificate file contains the private key.
5.
Make sure the certificate is not revoked.
6.
Make sure the certificate is valid.
7.
Configure the correct system time for the device.
8.
If the problem persists, contact Hewlett Packard Enterprise Support.
Failed to export certificates
Symptom
Certificates cannot be exported.
Analysis
•
The PKI domain does not have local certificates when you export all certificates in PKCS12
format.
•
The specified export path does not exist.
•
The specified export path is illegal.
•
The public key of the local certificate to be exported does not match the public key of the key
pair configured in the PKI domain.
•
The storage space of the device is full.
Содержание 10500 series
Страница 326: ...312 No duration limit for this SA ...