cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1102
Views
0
Helpful
6
Replies

ACS 4.2 (24) Certificate Revocation Failed

willgraham
Level 1
Level 1

I am unable to revoke certs using the crl.

The crl itsself appears to work fine if you browse to it.

Error message shown below.

Any help is greatly appreciated.

Thanks,

Will

6 Replies 6

andamani
Cisco Employee
Cisco Employee

Hi Will,

Could you please confirm if this is ACS for windows or ACS Appliance?

Also please post the exact version of ACS i.e. 4.2.x.y patch z

Please collect the package.cab file with the timestamp and post here.

Regards,

Anisha

It's running on windows 2003, Release 4.2(0) Build 124.

The package is a full 30mb - i'm not happy sending the entire thing (from a secuirty perspective) so can you tell me what files you are after in particular?

Thanks,


Will

In the ADMN file i noted

ADMN 02/11/2011 09:54:18 I 0159 286832 0x0 CRL: CRL: Issuer svmdc133's profile is found in the DB

Is that good or bad?

Another thing I can see are duplicate entries on the ACS server for the crl - not sure if this has anything to do with it.

Has anyone experienced this error message before when linking to a crl? I'm having trouble here!

Hi Will

Please upload the CSAdmin file with timestamp.

Regards,

Anisha

Please find timestamp from CSAuth attached.

DMN 02/24/2011 16:57:23 I 0159 286092 0x0 CRL: CRL: Issuer svmdc133's profile is found in the DB
ADMN 02/24/2011 16:57:23 I 0159 286092 0x0 CRL: CRL: Issuer svmdc133's profile is found in the DB
ADMN 02/24/2011 16:57:23 I 0159 286092 0x0 CRL: CRL: file C:\Program Files\CiscoSecure ACS v4.2\CRL\svmdc133(24-02-2011@16-57-23).crl successfully downloaded from http://svmdc133/CertEnroll/svmdc133.crl
ADMN 02/24/2011 16:57:23 I 0159 286092 0x0 CRL: CRL: successfully parsed CRL file C:\Program Files\CiscoSecure ACS v4.2\CRL\svmdc133(24-02-2011@16-57-23).crl
ADMN 02/24/2011 16:57:23 E 0159 286092 0x0 CRL: CRL: failed to find certificate for svmdc133
ADMN 02/24/2011 16:57:23 E 0159 286092 0x0 CRL: CRL: failed to get a store for crl C:\Program Files\CiscoSecure ACS v4.2\CRL\svmdc133(24-02-2011@16-57-23).crl
ADMN 02/24/2011 16:57:23 A 0159 286092 0x0 CRL: CRL: A new CRL file for issuer svmdc133 successfully retrieved
ADMN 02/24/2011 16:57:23 I 0159 286092 0x0 CRL: CRL: file C:\Program Files\CiscoSecure ACS v4.2\CRL\svmdc133(24-02-2011@16-57-23).crl successfully downloaded from http://svmdc133/CertEnroll/svmdc133.crl
ADMN 02/24/2011 16:57:23 I 0159 286092 0x0 CRL: CRL: successfully parsed CRL file C:\Program Files\CiscoSecure ACS v4.2\CRL\svmdc133(24-02-2011@16-57-23).crl
ADMN 02/24/2011 16:57:23 E 0159 286092 0x0 CRL: CRL: failed to find certificate for svmdc133
ADMN 02/24/2011 16:57:23 E 0159 286092 0x0 CRL: CRL: failed to get a store for crl C:\Program Files\CiscoSecure ACS v4.2\CRL\svmdc133(24-02-2011@16-57-23).crl
ADMN 02/24/2011 16:57:23 A 0159 286092 0x0 CRL: CRL: A new CRL file for issuer svmdc133 successfully retrieved
ADMN 02/24/2011 16:57:23 I 1155 286092 0x0 ----- Connection finished for session 286092.
ADMN 02/24/2011 16:57:23 I 0911 286092 0x0 Session 286092 is WAITING.
ADMN 02/24/2011 16:57:23 I 1040 286092 0x0 Session 286092 is PROCESSING.
ADMN 02/24/2011 16:57:23 I 1107 286092 0x0 ----- Connection started for session 286092.
ADMN 02/24/2011 16:57:23 I 1094 286092 0x0     Received HTTP request "GET /images/error.gif HTTP/1.1".
ADMN 02/24/2011 16:57:23 I 0295 286092 0x0 Parse of HTTP request stream complete.
ADMN 02/24/2011 16:57:23 I 0606 286092 0x0 File "C:\Program Files\CiscoSecure ACS v4.2\CSAdmin\WWW\images\error.gif" read for reply.
ADMN 02/24/2011 16:57:23 I 1155 286092 0x0 ----- Connection finished for session 286092.
ADMN 02/24/2011 16:57:23 I 0911 286092 0x0 Session 286092 is WAITING.