Cannot download CRL to my ISE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-06-2013 05:10 AM - edited 03-10-2019 08:58 PM
Hello,
I have ise 1.2, i have configured everything normally and i can browse to my CRL from any windows pc that is ok, but still my ise cannot download the CRL, i get the following error on my ISE. please help me im totally stuck in this. i have standalone CA
ise error msg>>>
Alarms: CRL Retrieval Failed
Description:
Unable to retrieve CRL from the server. This could occur if the specified url is unavailable.
Suggested Actions:
Please ensure that the download url is correct and is available for the service
Could not download Certificate Revocation List for certificate with CN=TrustedCA
- Labels:
-
AAA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-07-2013 09:03 AM
For complete configuration, please check the below link.
http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_cert.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-07-2013 10:13 PM
Hi Imran,
- Check to make sure that the CA services are up and running on the CA server.
- Replace the certificate. For a trust certificate, contact the issuing Certificate Authority (CA). For a CA-signed local certificate, generate a CSR and have the CA create a new certificate. For a self-signed local certificate, use Cisco ISE to extend the expiration date. You can delete the certificate if it is no longer used.
- Check if the configuration change is expected.
- Ensure that the download URL is correct and is available for the service.
For more information, please visit the given link:
http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_mnt.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-10-2013 01:17 PM
CRL Retrieval Failed ---- Unable to retrieve CRL from the server. This could occur if the specified CRL is unavailable.--------- Ensure that the download URL is correct and is available for the service.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-27-2013 03:54 AM
We have the same issue and believe it is due to the ISE using the system proxy settings. According to the documentation, it should be possible to add exceptions, but I don't see these fields (ISE 1.2 patch 4)
Step 1 Choose Administration > System > Settings > Proxy.
Step 2 Enter the proxy IP address or DNS-resolvable host name in Proxy Address, and specify the port through which proxy traffic travels to and from Cisco ISE in Proxy Port.
Step 3 Enter the IP Address or Address range of hosts or domains to be bypassed in Bypass Proxy Settings for these Hosts & Domain.
Step 4 Enter the username and password used to authenticate to the proxy servers in the corresponding fields.
Step 5 Click Save.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-28-2013 07:59 AM
I have the same problem, my CRL URL contained spaces and looks like ISE has problem with that. OCSP is workaround
