12-26-2019 10:06 AM
I have upgraded the Cisco ISE 2.2 to 2.6 recently, it is distributed deployment. After teh upgradation, i am seeing this alarm from my primary MnT node;
Error Message:
Alarm Name :
Log Collection Error
Details :
Syslog parsing error : String index out of range: -1
i am not sure about the reason for this alarm but wanted to make this alarm shuts off.
Please reply here of anyone has some suggestion for this issue
Solved! Go to Solution.
01-02-2020 10:41 AM
12-26-2019 09:52 PM
12-27-2019 05:38 AM
Thank you Sir,
DO you know from where i can find the string configuration in ISE?
12-29-2019 05:27 PM
12-30-2019 10:31 AM
Which logging category need to be set on DEBUG level for these logs?
12-30-2019 10:37 AM
This is the error message i found form the logs
2019-12-15 00:02:07,231 WARN [pool-81918-thread-1][] cisco.epm.cert.validator.CRLCache -::::- Unable to download CRL javax.naming.NamingException: [LDAP: error code 1 - 000004DC: LdapErr: DSID-0C090A4C, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v3839 ]; remaining name ''
Is there any suggestion on this?
01-02-2020 10:41 AM
01-08-2020 10:10 PM
I have seen this since ISE 2.2 - it's due to ISE's attempt at trying to download a CRL by inspecting the CDP (CRL Distribution Point). If the certificate was created using Microsoft CA (which is very common in the Enterprise), then the default template includes the CA's URL as an LDAP address. But ISE has no credentials to bind to that URL using LDAP - hence, it fails.
If I remember correctly, you can fix that error by specifying a manual CRL URL for every trusted CA cert that you have added in ISE. This then causes ISE to ignore the CDP, and use your manual URL instead.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide