<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CRL error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/crl-error/m-p/1727770#M232682</link>
    <description>&lt;P&gt;I just noticed that I was not able to connect because there was na expired CRL in my CA chain.&amp;nbsp; After some investigation, it turns out the ACS server can't get the CRL information from the CA server.&amp;nbsp; It was working at one time.&amp;nbsp; Does anyone know what permissions need to be changed to get it to work?&amp;nbsp; I know I can change ACS to ignore CRL erorrs, but then what would be the point of using CRLs at all?&amp;nbsp; I'm assuming something broke when I was trying to get web enrollment to work by playing with the settings on the CA server.&amp;nbsp; Here is the error from the ACS server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message_Code = 33402 &lt;/P&gt;&lt;P&gt;Message_Severity = ERROR &lt;/P&gt;&lt;P&gt;Category = CSCOacs_Internal_Operations_Diagnostics &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Diagnostic_Info = LastErrorMessage=Failed performing HTTP GET error: 403, Certificate Revocation list Url=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://CAServer/CertEnroll/CA.crl" target="_blank"&gt;http://CAServer/CertEnroll/CA.crl&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:11:31 GMT</pubDate>
    <dc:creator>raymondhugh</dc:creator>
    <dc:date>2019-03-11T01:11:31Z</dc:date>
    <item>
      <title>CRL error</title>
      <link>https://community.cisco.com/t5/network-access-control/crl-error/m-p/1727770#M232682</link>
      <description>&lt;P&gt;I just noticed that I was not able to connect because there was na expired CRL in my CA chain.&amp;nbsp; After some investigation, it turns out the ACS server can't get the CRL information from the CA server.&amp;nbsp; It was working at one time.&amp;nbsp; Does anyone know what permissions need to be changed to get it to work?&amp;nbsp; I know I can change ACS to ignore CRL erorrs, but then what would be the point of using CRLs at all?&amp;nbsp; I'm assuming something broke when I was trying to get web enrollment to work by playing with the settings on the CA server.&amp;nbsp; Here is the error from the ACS server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message_Code = 33402 &lt;/P&gt;&lt;P&gt;Message_Severity = ERROR &lt;/P&gt;&lt;P&gt;Category = CSCOacs_Internal_Operations_Diagnostics &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Diagnostic_Info = LastErrorMessage=Failed performing HTTP GET error: 403, Certificate Revocation list Url=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://CAServer/CertEnroll/CA.crl" target="_blank"&gt;http://CAServer/CertEnroll/CA.crl&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/crl-error/m-p/1727770#M232682</guid>
      <dc:creator>raymondhugh</dc:creator>
      <dc:date>2019-03-11T01:11:31Z</dc:date>
    </item>
    <item>
      <title>CRL error</title>
      <link>https://community.cisco.com/t5/network-access-control/crl-error/m-p/1727771#M232728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the problem - I had the URL set to require https connection, but ACS does not support that.&amp;nbsp; Once I unchecked the requirement, it worked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 13:44:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/crl-error/m-p/1727771#M232728</guid>
      <dc:creator>raymondhugh</dc:creator>
      <dc:date>2011-06-28T13:44:08Z</dc:date>
    </item>
  </channel>
</rss>

