cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
716
Views
5
Helpful
1
Replies

CSCvr71672 - Cisco PKI Root Certificates not installed in recent images, LOCAL ERROR - CRTVERFL

rudimocnik
Level 1
Level 1

Hi

 

I have a C1111-4PLTE router running IOS-XE SDWAN 16.10.4. Looking at the connections-history is see:

PEER     PEER     PEER             SITE        DOMAIN PEER             PRIVATE  PEER             PUBLIC                                   LOCAL      REMOTE     REPEAT               
TYPE     PROTOCOL SYSTEM IP        ID          ID     PRIVATE IP       PORT     PUBLIC IP        PORT    LOCAL COLOR      STATE           ERROR      ERROR      COUNT DOWNTIME       
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
vbond    dtls     -                0           0      193.XX.XX.101   12346    193.XX.XX.101  12346   lte              tear_down       CRTVERFL   NOERR      91    2020-05-09T05:52:22+0200
vbond    dtls     -                0           0      193.XX.XX.101   12346    193.XX.XX.101   12346   lte              connect         DCONFAIL   NOERR      0     2020-05-09T05:40:45+0200

The bug states that the workaround is to install Cisco root but states no link on where could I download it. I found this link and installed the Cisco Root CA 2048 (crca2048) - PEM and it installed it with

Which certificate do I need?

 

Thanks

Rudi

1 Reply 1

rudimocnik
Level 1
Level 1

I just upgraded to 16.12.3 and the issue was solved. The root certs are present in this release.

 

Rudi