< Home

PKI/4/LOCAL_EXPIRED

Message

PKI/4/LOCAL_EXPIRED: LOCAL certificate ([subject_name]) has expired for [day] days.

Description

A local certificate expired.

Parameters

Parameter Name Parameter Meaning

subject_name

Specifies the subject of a local certificate.

day

Specifies the number of days after a local certificate expired.

Possible Causes

  • The certificate failed to be updated automatically.
  • The certificate was not updated manually.

Procedure

  • Apply for certificates online using SCEP or CMPv2.

    • If the automatic certificate update function is configured, the device automatically updates certificates using SCEP or CMPv2 when the certificates are about to expire or have expired.

      You need to ensure that the link between the device and CA server is reachable, the PKI configuration is correct, and the CA server is working properly.

    • If the automatic certificate update function is not configured, and SCEP is used, run the pki enroll-certificate realm command in the system view to manually update the certificates. If CMPv2 is used, run the pki cmp keyupdate-request session command in the system view to manually update the certificates.

      Ensure that the link between the device and CA server is reachable, the PKI configuration is correct, and the CA server is working properly.

  • Apply for certificates offline.

    1. Send the certificate request file to the CA server through the web system, disk, or email to apply for a CA certificate and local certificate.

    2. Run the pki delete-certificate command in the system view to delete the old CA certificate and local certificate from the device memory.

    3. Use methods such as SFTP to upload the obtained CA and local certificates to the storage medium of the device, and run the pki import-certificate command in the system view to import the certificates to the memory of the device.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >