12-01-2017 02:22 AM - edited 03-20-2019 09:44 PM
02-01-2018 07:55 AM
Seems fixed in ISE 2.3 Patch 2.
My CRL retrieval warnings disappeared since the update from patch 1 to patch 2..
02-07-2018 07:29 AM
03-15-2018 04:56 PM
03-15-2018 07:18 PM
CRL works after installing ISE 2.3 patch 2
03-16-2018 05:01 AM
Hi Paul,
i've figured out with TAC how the mechanism of CRL checking works:
ISE checks the value of the AKI field in the CRL for ensuring the CRL belongs to a certificate ISE holds in it's trusted certificate store. This field has to contain the serial number of the issuing certificate.
Details can be found here: http://www.pkiglobe.org/aki_ski.html
Our problem depends on the fact the CRLs of our PKI do not contain this AKI extension which leads to following symptoms:
In fact this is a cosmetical error because downloading and checking against CRL works properly. Nevertheless you have to deal with this upcoming error message anyhow.
Maybe you have an other problem with downloading CRL, but these are my two cents in this case.
03-19-2018 04:54 PM
Thanks for sharing mate
03-23-2018 07:40 AM
Oh i forgot to mention there is a diagnostic logfile where details for CRL Downlaods are available.
You can find it under
Operations > Troubleshoot > Download Logs > Debug logs (right tab) > prrt-server.log
cheers!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide