Hi Dossou,

Are you sure you correctly enrolled to an scep endpoint? As for ur debug you're 
trying to use an scep certificate that has not been signed.

If you are using scep you shoukd use enrollment-url 
http://x.x.x.x:80/certsrv/mscep/mscep.dll and after that the certificate should 
be issued by the ca server. If the enrollment acceptance is not automatic u you 
should allow the endpoint to issue the certificate. Also you should download 
the crl from the ca so you know what certificates are still valid.

As per your debug your certificate is not a valid certificate issued by the ca.

If the steps above did not clarify your issue I'll be more than glad to help 
you.

Enviada do meu iPhone

> Em 22/04/2014, às 19:16, s.a.dos...@videotron.ca escreveu:
> 
> Hello
> 
> I am trying to complete task 3 : IPv6 L2L IOs and keep getting this message
> 
> %PKI-6-CERTFAIL: Certificate enrollment failed.
> 
> 
> I issued debug commands on the server (debug cry pki trans ) and got this
> Apr 22 21:48:56.055: CRYPTO_CS: trans id - 3FE0CA96FD6FF8C4814CB4833029D6D1
> Apr 22 21:48:56.091: CRYPTO_CS: failed to open env data
> Apr 22 21:48:56.091: CRYPTO_CS: read SCEP: unregistered and unbound service 
> SCEP_READ_DB_12
> Apr 22 21:48:56.091: CRYPTO_CS: failed to read SCEP request
> R2#
> 
> 
> The time on the server and R10 and R11 is ok : NTP status is synchronized
> 
> Thank you for helping
> 
> 
> _______________________________________________
> Free CCIE R&S, Collaboration, Data Center, Wireless & Security Videos ::
> 
> iPexpert on YouTube: www.youtube.com/ipexpertinc
_______________________________________________
Free CCIE R&S, Collaboration, Data Center, Wireless & Security Videos ::

iPexpert on YouTube: www.youtube.com/ipexpertinc

Reply via email to