< Home

PKI/4/GET_CA_CERT_ERR

Message

PKI/4/GET_CA_CERT_ERR: Realm [realm_name] failed to get CA certificate through [protocol].

Description

Failed to obtain the CA certificate through SCEP.

Parameters

Parameter Name Parameter Meaning

realm_name

Specifies the name of a PKI realm.

protocol

Specifies the protocol type as SCEP.

Possible Causes

  • The link between the device and CA server is Down.
  • The CA server is not working properly.
  • The PKI configuration is incorrect.

Procedure

  1. Run the ping command to check whether the link between the device and CA server is reachable.

    • If not, ensure that the network configurations, including interfaces and IP addresses, are correct.
    • If so, go to step 2.

  2. Check whether the CA server is working properly.

    • If not, ensure that the CA server has the certificate service enabled and is working properly.
    • If so, go to step 3.

  3. Check whether the PKI configuration is correct, for example, certificate request signature algorithm, challenge password, CA ID, PKI entity common name, and CA server URL.

    • If not, modify the configuration to ensure that it is correct.
    • If so, go to step 4.

  4. Collect required information and contact technical support personnel.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >