< Home

PKI_1.3.6.1.4.1.2011.6.122.34.0.2.21 hwPKIRequestCertFailScep

Description

PKI/3/PKIGETCERTFAILSCEP: OID [oid] Requesting certificate through SCEP failed. (hwSCEPUrl=[scepurl], PkiRealmName=[realmname])

Application for a certificate through SCEP failed.

Attribute

Alarm ID Alarm Severity Alarm Type
1.3.6.1.4.1.2011.6.122.34.0.2.21 Minor communicationsAlarm

Parameters

Name Meaning
oid Indicates the MIB object ID of the alarm.
scepurl Indicates the URL of the SCEP server.
realmname Indicates the name of the PKI realm.

Impact on the System

The service related the certificate cannot be used.

Possible Causes

  • There is no reachable route between the device and CA server.
  • The PKI configurations of the device and CA server are incorrect.
  • The CA server is faulty.

Procedure

  1. Run the ping command to check whether there is a reachable route between the device and CA server.

    If not, check the route and link to ensure that there is a reachable route between the device and CA server.

  2. Run the display pki realm command to check whether the PKI configurations of the device and CA server are correct. The PKI configurations include the CA server URL, CA name, digest algorithm used to sign certificate enrollment requests, challenge password used in SCEP certificate application, and CA certificate digital fingerprint.

    If not, ensure that the PKI configurations are correct.

  3. Check whether the CA server is working properly.

    If not, ensure that the CA server is working properly.

  4. Collect alarm and configuration information, and contact technical support personnel.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >