cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6463
Views
0
Helpful
1
Replies

Oct 10 08:56:24.226: %PKI-3-CERTIFICATE_INVALID: Certificate chain validation has failed.

Ibrahim Jamil
Level 6
Level 6

Hello Guys

 

what is issue behind the below log : "172.106.6.15" is GW-2 , I am using Site to Site VPN based Certificate , Cisco IOS acts as as CA Server

 

GW-1#
Oct 10 08:56:24.225: %PKI-4-CRLINSERTFAIL: Trustpoint "GW-1" unknown (error 1804:E_VALIDITY : validity period start later than end)
Oct 10 08:56:24.226: %PKI-3-CERTIFICATE_INVALID: Certificate chain validation has failed.
Oct 10 08:56:24.226: %CRYPTO-5-IKMP_INVAL_CERT: Certificate received from 172.106.6.15 is bad: certificate invalid

1 Reply 1

GioGonza
Level 4
Level 4

Hello @Ibrahim Jamil

 

You need to check the lifetime you have for the CA and also the certificates you are signing on the Router, the concern happens when the times are not valid and probably the certificate has a later date, the logs is the following: 

 

error 1804:E_VALIDITY : validity period start later than end

 

Check the configuration and let me know. 

 

HTH

Gio