Smart questions
Smart answers
Smart people
INTELLIGENT WORK FORUMS
FOR COMPUTER PROFESSIONALS

Member Login

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips now!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!

Join Tek-Tips
*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

LINK TO THIS FORUM!

Add Stickiness To Your Site By Linking To This Professionally Managed Technical Forum.
Just copy and paste the
code below into your site.

Partner With Us!

"Best Of Breed" Forums Add Stickiness To Your Site
Partner Button
(Download This Button Today!)

Feedback

"...Thank you for the best reply I've ever had to a forum question - it's extremely comprehensive and legible and answers my query thoroughly..."

Geography

Where in the world do Tek-Tips members come from?
imbadatthis (TechnicalUser)
2 May 12 10:54
Howdy,
Cisco 3900, Router, certificate issue:

the CRL Distribution points provide me with an LDAP and HTTP query.
myunderstanding is that it should cycle through them when one fails.

I need to figure out how to force it to d/l CRList off the http crl ?

config im using :

CODE

crypto pki trustpoint NAME
 enrollment retry count 5
 enrollment retry period 3
 enrollment mode ra
 enrollment url http://172.YY.ZZ.ZZX/certsrv/mscep/mscep.dll
 serial-number
 ip-address 172.XX.XXX.YYY
 query certificate
 vrf SOMETHING
 revocation-check crl

when I issue a crypto pki crl request TRUSTPIONT_NAME

i get the error message that the LDAP server could not be reached.
but it doesn't move on from there...

certificate is VALID and shows status as granted with the CA trusted.
when I check the certificate itself I do see both HTTP and LDAP CDP's in there... (CRL dist points) .

any help would be appreciated as this is driving me nuts :(

CODE

error:
MDT: %PKI-4-CRL_LDAP_QUERY: An attempt to retrieve the CRL from ldap://...........
 

We must go always forward, not backward
always up, not down and always twirling twirling towards infinity.
 

imbadatthis (TechnicalUser)
8 May 12 12:34
hellloo... is this thing on ? :p
 

We must go always forward, not backward
always up, not down and always twirling twirling towards infinity.
 

imbadatthis (TechnicalUser)
9 May 12 16:49
resolved......
 

We must go always forward, not backward
always up, not down and always twirling twirling towards infinity.
 

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close