<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic It looks like your CA server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/error-receiving-certificate-authority-certificate-status-fail/m-p/2453324#M921918</link>
    <description>&lt;P&gt;It looks like your CA server is returning a 500 error.&lt;/P&gt;&lt;P&gt;You can verify this by browsing to that same URL (&lt;A href="http://10.0.4.2/certsrv/mscep/mscep.dll/pkiclient.exe?operation=GetCACert&amp;amp;message=ESSAUDE"&gt;http://10.0.4.2/certsrv/mscep/mscep.dll/pkiclient.exe?operation=GetCACert&amp;amp;message=ESSAUDE&lt;/A&gt;) using a browser. If it's all working, you should be able to download the CA certificate this way (save it to, for example, ca.crt and try opening it).&lt;/P&gt;&lt;P&gt;I'm not certain, because I don't know how your CA is set up, but I think the enrolment URL you have configured in your trustpoint on the switch might be wrong. Does it work on any devices, or is it just these switches having problems?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--hugh&lt;/P&gt;</description>
    <pubDate>Fri, 04 Apr 2014 19:52:47 GMT</pubDate>
    <dc:creator>mclarenh</dc:creator>
    <dc:date>2014-04-04T19:52:47Z</dc:date>
    <item>
      <title>ERROR: receiving Certificate Authority certificate: status = FAIL</title>
      <link>https://community.cisco.com/t5/network-security/error-receiving-certificate-authority-certificate-status-fail/m-p/2453323#M921916</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;we have installed new MS root CA and issuing CA (Windows Server 2008 R2 Enterprise) . When I tried to get CA certificate from some Cisco devices Cisco WS-C3560-24PS it fail.&lt;/P&gt;&lt;P&gt;Debug:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;QL-SW3(config)#CRYPTO CA authenticate ESSAUDE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;092306: Mar 27 11:47:38.075 PT: CRYPTO_PKI: Sending CA Certificate Request:&lt;BR /&gt;GET /certsrv/mscep/mscep.dll/pkiclient.exe?operation=GetCACert&amp;amp;message=ESSAUDE HTTP/1.0&lt;BR /&gt;User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Cisco PKI)&lt;BR /&gt;Host: 10.0.4.2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;092307: Mar 27 11:47:38.075 PT: CRYPTO_PKI: locked trustpoint ESSAUDE, refcount is 1&lt;BR /&gt;092308: Mar 27 11:47:38.075 PT: CRYPTO_PKI: can not resolve server name/IP address&lt;BR /&gt;092309: Mar 27 11:47:38.075 PT: CRYPTO_PKI: Using unresolved IP Address 10.0.4.2&lt;BR /&gt;092310: Mar 27 11:47:38.084 PT: CRYPTO_PKI: http connection opened&lt;BR /&gt;092311: Mar 27 11:47:38.084 PT: CRYPTO_PKI: Sending HTTP message&lt;/P&gt;&lt;P&gt;092312: Mar 27 11:47:38.084 PT: CRYPTO_PKI: HTTP header:&lt;BR /&gt;&amp;nbsp;HTTP/1.0&lt;BR /&gt;User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Cisco PKI)&lt;BR /&gt;Host: 10.0.4.2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;092313: Mar 27 11:47:38.084 PT: CRYPTO_PKI: unlocked trustpoint ESSAUDE, refcount is 0&lt;BR /&gt;092314: Mar 27 11:47:38.084 PT: CRYPTO_PKI: locked trustpoint ESSAUDE, refcount is 1&lt;BR /&gt;% Error in receiving Certificate Authority certificate: status = FAIL, cert length = 0&lt;/P&gt;&lt;P&gt;QL-SW3(config)#&lt;BR /&gt;QL-SW3(config)#&lt;BR /&gt;QL-SW3(config)#&lt;BR /&gt;092315: Mar 27 11:47:53.393 PT: CRYPTO_PKI: unlocked trustpoint ESSAUDE, refcount is 0&lt;BR /&gt;092316: Mar 27 11:47:53.393 PT: CRYPTO_PKI: HTTP header:&lt;BR /&gt;&amp;nbsp;HTTP/1.1 500 Internal Server Error&lt;BR /&gt;Content-Type: text/html&lt;BR /&gt;Server: Microsoft-IIS/7.5&lt;BR /&gt;Date: Thu, 27 Mar 2014 11:47:53 GMT&lt;BR /&gt;Connection: close&lt;BR /&gt;Content-Length: 1208&lt;/P&gt;&lt;P&gt;Content-Type indicates we did not receive a certificate.&lt;/P&gt;&lt;P&gt;092317: Mar 27 11:47:53.401 PT: CRYPTO_PKI: transaction GetCACert completed&lt;BR /&gt;QL-SW3(config)#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anybody have idea ?&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-receiving-certificate-authority-certificate-status-fail/m-p/2453323#M921916</guid>
      <dc:creator>Tiago Marques</dc:creator>
      <dc:date>2020-02-21T13:08:48Z</dc:date>
    </item>
    <item>
      <title>It looks like your CA server</title>
      <link>https://community.cisco.com/t5/network-security/error-receiving-certificate-authority-certificate-status-fail/m-p/2453324#M921918</link>
      <description>&lt;P&gt;It looks like your CA server is returning a 500 error.&lt;/P&gt;&lt;P&gt;You can verify this by browsing to that same URL (&lt;A href="http://10.0.4.2/certsrv/mscep/mscep.dll/pkiclient.exe?operation=GetCACert&amp;amp;message=ESSAUDE"&gt;http://10.0.4.2/certsrv/mscep/mscep.dll/pkiclient.exe?operation=GetCACert&amp;amp;message=ESSAUDE&lt;/A&gt;) using a browser. If it's all working, you should be able to download the CA certificate this way (save it to, for example, ca.crt and try opening it).&lt;/P&gt;&lt;P&gt;I'm not certain, because I don't know how your CA is set up, but I think the enrolment URL you have configured in your trustpoint on the switch might be wrong. Does it work on any devices, or is it just these switches having problems?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--hugh&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2014 19:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-receiving-certificate-authority-certificate-status-fail/m-p/2453324#M921918</guid>
      <dc:creator>mclarenh</dc:creator>
      <dc:date>2014-04-04T19:52:47Z</dc:date>
    </item>
  </channel>
</rss>

