< Home

PKI/4/GET_LOCAL_CERT_ERR

Message

PKI/4/GET_LOCAL_CERT_ERR: Realm [realm_name] failed to get local certificate through [protocol].

Description

Failed to obtain the local certificate through SCEP.

Parameters

Parameter Name Parameter Meaning

realm_name

Specifies the name of a PKI realm.

protocol

Specifies the protocol type as SCEP.

Possible Causes

  • The link between the device and CA server is Down.
  • The CA server is not working properly.
  • No CA and RA certificates are installed on the device.
  • The PKI configuration is incorrect.

Procedure

  1. Run the ping command to check whether the link between the device and CA server is reachable.

    • If not, ensure that the network configurations, including interfaces and IP addresses, are correct.
    • If so, go to step 2.

  2. Check whether the CA server is working properly.

    • If not, ensure that the CA server has the certificate service enabled and is working properly.
    • If so, go to step 3.

  3. Check whether the CA and RA certificates have been installed.

    • If not, install the CA and RA certificates and ensure that the certificates are within the validity period.
    • If so, and the CA and RA certificates are not within the validity period, update the CA and RA certificates.
    • If so, and the CA and RA certificates are within the validity period, go to step 4.

  4. Check whether the PKI configuration is correct, for example, certificate request signature algorithm, challenge password, CA ID, PKI entity common name, and CA server URL.

    • If not, modify the configuration to ensure that it is correct.
    • If so, go to step 5.

  5. Collect required information and contact technical support personnel.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >