Cisco DS-C9124-K9 Troubleshooting Guide - Page 479

Cannot Export Identity Certificate in PKCS#12 Format, Certificate Fails at Peer

Page 479 highlights

Chapter 24 Troubleshooting Digital Certificates Digital Certificate Issues Send documentation comments to [email protected] Cannot Export Identity Certificate in PKCS#12 Format Symptom Cannot export identity certificate in PKCS#12 format. Table 24-3 Cannot Export Identity Certificate in PKCS#12 Format Symptom Cannot export identity certificate in PKCS#12 format. Possible Cause RSA keys not exportable. Solution Create exportable RSA keys. Choose Switches > Security > PKI in Fabric Manager and click Create Row. Check the Exportable check box and create an RSA key pair. Or use the crypto key generate rsa exportable CLI command. Certificate Fails at Peer Symptom Certificate fails at peer. Table 24-4 Certificate Fails at Peer Symptom Certificate fails at peer. Possible Cause Solution FQDN changed after certificate was issued. Revoke certificate and re-create. See the "Configuring Certificates on the MDS Switch Using Fabric Manager" section on page 24-5 or the "Configuring Certificates on the MDS Switch Using the CLI" section on page 24-7. Local and remote clocks are not synchronized. If the clocks are not synchronized, the certificate may appear to be expired. Validate the clocks on the local and peer device. Peer does not recognize CA issuing the certificate. Create a certificate for the CAs known to the peer device. See the "Configuring Certificates on the MDS Switch Using Fabric Manager" section on page 24-5 or the "Configuring Certificates on the MDS Switch Using the CLI" section on page 24-7. Configuring Certificates on the MDS Switch Using Fabric Manager To configure certificates on an MDS switch using Fabric Manager, follow these steps: Step 1 Step 2 Step 3 Choose Switches and set the LogicalName field to configure the switch host name. Choose Switches > Interfaces > Management > DNS and set the DefaultDomainName field to configure the DNS domain name for the switch. Follow these steps to create an RSA key pair for the switch: a. Choose Switches > Security > PKI and select the RSA Key-Pair tab. b. Click Create Row and set the name and size field. c. Check the Exportable check box and click Create. OL-9285-05 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x 24-5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560

Send documentation comments to [email protected]
24-5
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
OL-9285-05
Chapter 24
Troubleshooting Digital Certificates
Digital Certificate Issues
Cannot Export Identity Certificate in PKCS#12 Format
Symptom
Cannot export identity certificate in PKCS#12 format.
Certificate Fails at Peer
Symptom
Certificate fails at peer.
Configuring Certificates on the MDS Switch Using Fabric Manager
To configure certificates on an MDS switch using Fabric Manager, follow these steps:
Step 1
Choose
Switches
and set the LogicalName field to configure the switch host name.
Step 2
Choose
Switches > Interfaces > Management > DNS
and set the DefaultDomainName field to
configure the DNS domain name for the switch.
Step 3
Follow these steps to create an RSA key pair for the switch:
a.
Choose
Switches > Security > PKI
and select the
RSA
Key-Pair
tab.
b.
Click
Create Row
and set the name and size field.
c.
Check the
Exportable
check box and click
Create
.
Table 24-3
Cannot Export Identity Certificate in PKCS#12 Format
Symptom
Possible Cause
Solution
Cannot export
identity certificate in
PKCS#12 format.
RSA keys not exportable.
Create exportable RSA keys.
Choose Switches > Security
> PKI
in Fabric Manager
and click
Create Row
. Check the
Exportable
check box and create an RSA key pair.
Or use the
crypto key generate rsa
exportable
CLI
command.
Table 24-4
Certificate Fails at Peer
Symptom
Possible Cause
Solution
Certificate fails at
peer.
FQDN changed after certificate was
issued.
Revoke certificate and re-create. See the
“Configuring
Certificates on the MDS Switch Using Fabric Manager”
section on page 24-5
or the
“Configuring Certificates on
the MDS Switch Using the CLI” section on page 24-7
.
Local and remote clocks are not
synchronized.
If the clocks are not synchronized, the certificate may
appear to be expired. Validate the clocks on the local and
peer device.
Peer does not recognize CA issuing the
certificate.
Create a certificate for the CAs known to the peer device.
See the
“Configuring Certificates on the MDS Switch
Using Fabric Manager” section on page 24-5
or the
“Configuring Certificates on the MDS Switch Using the
CLI” section on page 24-7
.