cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
719
Views
0
Helpful
3
Replies

Issue register a new FTD to FMC - CRL expired error

Chess Norris
Level 4
Level 4

Hello,

I am having an issue register two new FTD devices (4112-X) to FMC.

I see the following output when running pigtail on the FTD.

 

MSGS: 07-04 10:00:35 firepower SF-IMS[50075]: [87506] sftunneld:sf_peers [INFO] Peer 10.66.0.55 needs a single connection
MSGS: 07-04 10:00:35 firepower SF-IMS[50075]: [87506] sftunneld:sf_ssl [INFO] Connect to 10.66.0.55 on port 8305 - management0
MSGS: 07-04 10:00:35 firepower SF-IMS[50075]: [87506] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to 10.66.0.55 (via management0)
MSGS: 07-04 10:00:35 firepower SF-IMS[50075]: [87506] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to 10.66.0.55:8305/tcp
MSGS: 07-04 10:00:35 firepower SF-IMS[50075]: [87506] sftunneld:sf_ssl [INFO] Wait to connect to 8305 (IPv6): 10.66.0.55
MSGS: 07-04 10:00:35 firepower SF-IMS[50075]: [87506] sftunneld:sf_ssl [INFO] Connected to 10.66.0.55:8305 (IPv4)
MSGS: 07-04 10:00:35 firepower SF-IMS[50075]: [87506] sftunneld:sf_ssl [ERROR] CRL Expired
MSGS: 07-04 10:00:35 firepower SF-IMS[50075]: [87506] sftunneld:sf_ssl [ERROR] Unable to load SSL verification data(2): CRL expired
MSGS: 07-04 10:00:35 firepower SF-IMS[50075]: [87506] sftunneld:sf_ssl [ERROR] Unable to create SSL context(2): error:00000000:lib(0):func(0):reason(0)

 

Anyone know how to solve this?

 

Thanks

/Chess

1 Accepted Solution

Accepted Solutions

Chess Norris
Level 4
Level 4

It seems like it was a time issue after all. Both the FMC and the Chassis Manager used the same NTP server. However, the timezone on the Chassis Manager was different from FMC. After changing this, I was able to add the FTD in FMC.

/Chess

View solution in original post

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

Both having same issue ?

 

what version FMC and FTD ?

 

check some troublehoot tips :

 

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215540-configure-verify-and-troubleshoot-firep.html#anc25

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Chess Norris
Level 4
Level 4

@balaji.bandi FMC is version 7.0.2 and FTD 6.6.1

Yes, I went through the troubbleshooting tips and verified communication, time etc., but I couldn't find any solutions.

There is a simmilair thread here - https://community.cisco.com/t5/network-security/ftd-rejecting-ssl-cert-from-fmc/td-p/4316774 

but it's not clear if the threadstarter were able to resolve the issue.

 

Thanks

/Chess

Chess Norris
Level 4
Level 4

It seems like it was a time issue after all. Both the FMC and the Chassis Manager used the same NTP server. However, the timezone on the Chassis Manager was different from FMC. After changing this, I was able to add the FTD in FMC.

/Chess

Review Cisco Networking products for a $25 gift card