<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SCEP CA Enrollment Failure in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/scep-ca-enrollment-failure/m-p/4665790#M1092500</link>
    <description>&lt;P&gt;Good morning/afternoon,&lt;/P&gt;&lt;P&gt;Not sure if SCEP should go under general network security or VPN, but here goes.&lt;/P&gt;&lt;P&gt;I was able to get terminal enrollment functioning in our environment, but once the over head of certificate management was realized we are attempting to move to SCEP. Our server team has set up a CA which they insist should be functioning fine with SCEP.&lt;/P&gt;&lt;P&gt;I've generated two pairs of RSA keys, one for SCEP and the second for a self signed SSL certificate since our environment does not allow the use of IP HTTP server.&amp;nbsp; I'am a bit unfamilar with pki so bare with me please.&lt;/P&gt;&lt;P&gt;My trust point is configured as follows, with edits for security reasons:&lt;/P&gt;&lt;P&gt;crypto pki trustpoint &amp;lt;TP Name&amp;gt;&lt;BR /&gt;enrollment retry count 100&lt;BR /&gt;enrollment retry period 60&lt;BR /&gt;enrollment mode ra&lt;BR /&gt;enrollment url&amp;nbsp; &amp;lt;URL&amp;gt;/mscep.dll&lt;BR /&gt;serial-number none&lt;BR /&gt;ip-address none&lt;BR /&gt;fqdn&amp;nbsp; &amp;lt;our FQDN&amp;gt;&lt;BR /&gt;subject-name C=x, ST=x, L=x, O=x, OU=x, CN=x&lt;BR /&gt;revocation-check none&lt;BR /&gt;rsakeypair&amp;nbsp; &amp;lt;keypair&amp;gt;&lt;BR /&gt;auto-enroll 80 regenerate&lt;/P&gt;&lt;P&gt;&amp;nbsp;When i navigate to the URL, i get a 404. If i go to the root of the domain i get prompted for a constant username/password loop. I don't have the credentials&amp;nbsp; to test it.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I've enabled debug of crypto pki messages and transactions.&lt;/P&gt;&lt;P&gt;When i run "crypto pki authenticate &amp;lt;TP&amp;gt;",&lt;/P&gt;&lt;P&gt;i receive:&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;% Error: failed to open file.&lt;/P&gt;&lt;P&gt;% Error in receiving Certificate Authority certificate: status = FAIL, cert length = 0"&lt;/P&gt;&lt;P&gt;debug then reports:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Trustpoint&amp;gt;:Enrollment: IFS&lt;/P&gt;&lt;P&gt;Aug 8 10:55:12.920 edt: CRYPTO_PKI: (A24F3) Session started - identity not specified&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: Added x509 peer certificate - (1168) bytes:Incrementing refcount for context id-8611 to 1&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: create new ca_req_context type PKI_VERIFY_CHAIN_CONTEXT,ident 8611&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: (A24F3)validation path has 1 certs&lt;/P&gt;&lt;P&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: Unable to locate cert record by issuername&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: No trust point for cert issuer, looking up cert chain&lt;/P&gt;&lt;P&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: (A24F3) Removing verify context&lt;/P&gt;&lt;P&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: destroying ca_req_context type PKI_VERIFY_CHAIN_CONTEXT,ident 8611, ref count 1:Decrementing refcount for context id-8611 to 0&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: ca_req_context released&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: Rcvd request to end PKI session A24F3.&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: PKI session A24F3 has ended. Freeing all resources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The cert of course, does not appear under 'show pki'. I have asked the server team to check the server logs and there are no failed requests in the event logs. How could i possibly verify connection to the CA server? The routing for the SVI appears to be correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your assistance.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Aug 2022 15:24:56 GMT</pubDate>
    <dc:creator>jbulloch</dc:creator>
    <dc:date>2022-08-08T15:24:56Z</dc:date>
    <item>
      <title>SCEP CA Enrollment Failure</title>
      <link>https://community.cisco.com/t5/network-security/scep-ca-enrollment-failure/m-p/4665790#M1092500</link>
      <description>&lt;P&gt;Good morning/afternoon,&lt;/P&gt;&lt;P&gt;Not sure if SCEP should go under general network security or VPN, but here goes.&lt;/P&gt;&lt;P&gt;I was able to get terminal enrollment functioning in our environment, but once the over head of certificate management was realized we are attempting to move to SCEP. Our server team has set up a CA which they insist should be functioning fine with SCEP.&lt;/P&gt;&lt;P&gt;I've generated two pairs of RSA keys, one for SCEP and the second for a self signed SSL certificate since our environment does not allow the use of IP HTTP server.&amp;nbsp; I'am a bit unfamilar with pki so bare with me please.&lt;/P&gt;&lt;P&gt;My trust point is configured as follows, with edits for security reasons:&lt;/P&gt;&lt;P&gt;crypto pki trustpoint &amp;lt;TP Name&amp;gt;&lt;BR /&gt;enrollment retry count 100&lt;BR /&gt;enrollment retry period 60&lt;BR /&gt;enrollment mode ra&lt;BR /&gt;enrollment url&amp;nbsp; &amp;lt;URL&amp;gt;/mscep.dll&lt;BR /&gt;serial-number none&lt;BR /&gt;ip-address none&lt;BR /&gt;fqdn&amp;nbsp; &amp;lt;our FQDN&amp;gt;&lt;BR /&gt;subject-name C=x, ST=x, L=x, O=x, OU=x, CN=x&lt;BR /&gt;revocation-check none&lt;BR /&gt;rsakeypair&amp;nbsp; &amp;lt;keypair&amp;gt;&lt;BR /&gt;auto-enroll 80 regenerate&lt;/P&gt;&lt;P&gt;&amp;nbsp;When i navigate to the URL, i get a 404. If i go to the root of the domain i get prompted for a constant username/password loop. I don't have the credentials&amp;nbsp; to test it.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I've enabled debug of crypto pki messages and transactions.&lt;/P&gt;&lt;P&gt;When i run "crypto pki authenticate &amp;lt;TP&amp;gt;",&lt;/P&gt;&lt;P&gt;i receive:&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;% Error: failed to open file.&lt;/P&gt;&lt;P&gt;% Error in receiving Certificate Authority certificate: status = FAIL, cert length = 0"&lt;/P&gt;&lt;P&gt;debug then reports:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Trustpoint&amp;gt;:Enrollment: IFS&lt;/P&gt;&lt;P&gt;Aug 8 10:55:12.920 edt: CRYPTO_PKI: (A24F3) Session started - identity not specified&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: Added x509 peer certificate - (1168) bytes:Incrementing refcount for context id-8611 to 1&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: create new ca_req_context type PKI_VERIFY_CHAIN_CONTEXT,ident 8611&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: (A24F3)validation path has 1 certs&lt;/P&gt;&lt;P&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: Unable to locate cert record by issuername&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: No trust point for cert issuer, looking up cert chain&lt;/P&gt;&lt;P&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: (A24F3) Removing verify context&lt;/P&gt;&lt;P&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: destroying ca_req_context type PKI_VERIFY_CHAIN_CONTEXT,ident 8611, ref count 1:Decrementing refcount for context id-8611 to 0&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: ca_req_context released&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: Rcvd request to end PKI session A24F3.&lt;BR /&gt;Aug 8 10:55:12.921 edt: CRYPTO_PKI: PKI session A24F3 has ended. Freeing all resources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The cert of course, does not appear under 'show pki'. I have asked the server team to check the server logs and there are no failed requests in the event logs. How could i possibly verify connection to the CA server? The routing for the SVI appears to be correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your assistance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 15:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scep-ca-enrollment-failure/m-p/4665790#M1092500</guid>
      <dc:creator>jbulloch</dc:creator>
      <dc:date>2022-08-08T15:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP CA Enrollment Failure</title>
      <link>https://community.cisco.com/t5/network-security/scep-ca-enrollment-failure/m-p/4667372#M1092574</link>
      <description>&lt;P&gt;I was able to progress on this, and resolve the issue with a configuration issue on the CA (windows server) side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we receive a HTTP 301, which is apparently a redirect message. Has anyone ever troubleshot this? Is this a server side issue as research may suggest?&lt;/P&gt;&lt;P&gt;&amp;lt;TP&amp;gt;:unlocked trustpoint &amp;lt;TP&amp;gt; refcount is 0&amp;lt;TP&amp;gt;:locked trustpoint &amp;lt;TP&amp;gt;, refcount is 1&lt;BR /&gt;Aug 10 10:55:38.816 edt: CRYPTO_PKI: Header length received: 287&lt;BR /&gt;Aug 10 10:55:38.816 edt: CRYPTO_PKI: parse content-length header. return code: (0) and content-length : (223)&lt;BR /&gt;Aug 10 10:55:38.816 edt: CRYPTO_PKI: Complete data arrived &amp;lt;TP&amp;gt;:unlocked trustpoint &amp;lt;TP&amp;gt;, refcount is 0&lt;BR /&gt;Aug 10 10:55:38.816 edt: CRYPTO_PKI: Reply HTTP header:&lt;BR /&gt;HTTP/1.1 301 Moved Permanently&lt;BR /&gt;Content-Type: text/html; charset=UTF-8&lt;BR /&gt;Location:&amp;nbsp; &amp;lt;URL&amp;gt;&lt;BR /&gt;Server: Microsoft-IIS/10.0&lt;BR /&gt;Date: Wed, 10 Aug 2022 14:55:38 GMT&lt;BR /&gt;Connection: close&lt;BR /&gt;Content-Length: 223&lt;/P&gt;&lt;P&gt;Content-Type indicates we did not receive a certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 17:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scep-ca-enrollment-failure/m-p/4667372#M1092574</guid>
      <dc:creator>jbulloch</dc:creator>
      <dc:date>2022-08-10T17:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP CA Enrollment Failure</title>
      <link>https://community.cisco.com/t5/network-security/scep-ca-enrollment-failure/m-p/5279334#M1120513</link>
      <description>&lt;P&gt;Have you been able to resolve this issue using DNA?&lt;/P&gt;&lt;P&gt;-MaybeFig&lt;/P&gt;&lt;P&gt;"It is nice to touch some grass sometimes.."&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 13:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/scep-ca-enrollment-failure/m-p/5279334#M1120513</guid>
      <dc:creator>MaybeFig</dc:creator>
      <dc:date>2025-04-08T13:25:18Z</dc:date>
    </item>
  </channel>
</rss>

