Certificate Validation with Certificate Revocation Lists
7-46
Oracle Database Advanced Security Administrator's Guide
Oracle Net Tracing File Error Messages Associated with Certificate Validation
The following trace messages, relevant to certificate validation, may be logged
between the
entry
and
exit
entries in the Oracle Net tracing file. Oracle SSL looks
for CRLs in multiple locations, so there may be multiple errors in the trace.
Check the following list of possible error messages for information about how to
resolve them.
CRL signature verification failed with RSA status
Cause:
The CRL signature cannot be verified.
Action:
Ensure that the downloaded CRL is issued by the peer's CA and that
the CRL was not corrupted when it was downloaded. Note that the
orapki
utility verifies the CRL before renaming it with a hash value or before
uploading it to the directory. See
"Certificate Revocation List Management"
on
page 7-40 for information about using
orapki
for CRL management.
CRL date verification failed with RSA status
Cause:
The current time is later than the time listed in the next update field.
You should not see this error if CRL DP is used. The systems searches for the
CRL in the following order:
1.
File system
2.
Oracle Internet Directory
3.
CRL DP
The first CRL found in this search may not be the latest.
Action:
Update the CRL with the most recent copy.
CRL could not be found
Cause:
The CRL could not be found at the configured locations. This will
return error ORA-29024 if the configuration specifies that certificate validation
is require.
Action:
Ensure that the CRL locations specified in the configuration are correct
by performing the following steps:
1.
Use Oracle Net Manager to check if the correct CRL location is configured.
See
"Configuring Certificate Validation with Certificate Revocation Lists"
on
page 7-37
See Also:
Oracle Net Services Administrator's Guide for information
about setting tracing parameters to enable Oracle Net tracing
Содержание Database Advanced Security 10g Release 1
Страница 17: ...xvii ...
Страница 20: ...xx ...
Страница 24: ...xxiv ...
Страница 42: ...xlii ...
Страница 44: ......
Страница 62: ...Oracle Advanced Security Restrictions 1 18 Oracle Database Advanced Security Administrator s Guide ...
Страница 100: ...Duties of an Enterprise User Security Administrator DBA 2 38 Oracle Database Advanced Security Administrator s Guide ...
Страница 102: ......
Страница 116: ...How To Configure Data Encryption and Integrity 3 14 Oracle Database Advanced Security Administrator s Guide ...
Страница 124: ......
Страница 148: ...RSA ACE Server Configuration Checklist 5 24 Oracle Database Advanced Security Administrator s Guide ...
Страница 246: ...Managing Certificates 8 28 Oracle Database Advanced Security Administrator s Guide ...
Страница 254: ...Configuring Oracle Database for External Authentication 9 8 Oracle Database Advanced Security Administrator s Guide ...
Страница 284: ......
Страница 350: ...Troubleshooting Enterprise User Security 12 38 Oracle Database Advanced Security Administrator s Guide ...
Страница 384: ......
Страница 394: ...Data Encryption and Integrity Parameters A 10 Oracle Database Advanced Security Administrator s Guide ...
Страница 414: ...Physical Security D 6 Oracle Database Advanced Security Administrator s Guide ...
Страница 518: ...Index 10 ...