Certificate Management, Automatic Enrollment Failed

Contents

1Introduction
1.1Alarm Description
1.2Prerequisites

2

Procedure

1   Introduction

This instruction concerns alarm handling.

1.1   Alarm Description

The alarm is raised when automatic certificate enrollment or renewal failed to execute because of local misconfiguration or remote enrollment service denial.

Note:  
The alarm is raised only if the renewalMode in a NodeCredential Managed Object (MO) is set to AUTOMATIC.

The possible alarm causes and fault locations are explained in Table 1.

Table 1    Alarm Causes

Alarm Cause

Description

Fault Reason

Fault Location

Impact

Automatic certificate enrollment or renewal has failed

Automatic enrollment or renewal failed to execute because of local misconfiguration or break in remote enrollment service

Configuration or customization error


This can be for one of the following reasons:


  • Local misconfiguration

  • Failure in remote enrollment service

Node credential

Certificate is not renewed, which causes certificate expiration


Expired certificate can cause secured service failure, for example, Internet Protocol Security connection authenticated by non-existing or expired certificate can fail

The alarm attributes are listed and explained in Table 2.

Table 2    Alarm Attributes

Attribute Name

Attribute Value

Major Type

193

Minor Type

6946819

Managed Object Class

NodeCredential

Managed Object Instance

ManagedElement=<node_name>,SystemFunctions=1,SecM=1,CertM=1,NodeCredential=<node_credential_id>

Specific Problem

Certificate Management, Automatic Enrollment Failed

Event Type

processingErrorAlarm (4)

Probable Cause

x733ConfigurationOrCustomizationError (307)

Additional Text

Automatic enrollment or renewal failed to execute because of local misconfiguration or remote enrollment service denial

Perceived Severity

warning (6)

Note:  
When the automatic online node credential renewal has failed and the threshold for certificate expiration time has been crossed, another alarm Certificate Management, the Certificate is to Expire is raised.

1.2   Prerequisites

This section provides information on the documents, tools, and conditions that apply to the procedure.

1.2.1   Documents

This instruction references the following documents:

1.2.2   Tools

No tools are required.

1.2.3   Conditions

Before starting this procedure, ensure that the following conditions are met:

2   Procedure

Do the following:

  1. Navigate to the NodeCredential Managed Object (MO) given in the alarm, for example:

    >ManagedElement=NODE06ST,SystemFunctions=1,SecM=1,CertM=1,NodeCredential=1

  2. Compare if the existing configuration information for the NodeCredential MO matches with the information received from the IT or security administrator.

    The values of attributes enrollmentServerGroup and enrollmentAuthority can be checked in the NodeCredential MO with the following command:

    (NodeCredential=1)>show

  3. Change the attribute renewalMode to MANUAL.

    For information on how to change attribute renewalMode , refer to Configure Renewal Mode of Node Credential.

    Note:  
    When renewalMode is set to MANUAL, the alarm is cleared but the problem remains.

  4. Select the appropriate action based on the result in Step 2:
  5. Select the appropriate action based on the result in Step 2:
  6. Renew the certificate.

    For information on how to renew the certificate, refer to Renew Node Credential Online.

  7. Was the Renew Node Credential Online procedure successful?

    Yes: Continue with the next step.

    No: Proceed with Step 9.

    Note:  
    The cause of the failure is shown in resultinfo of the attribute nodeCredentialId.

  8. Change the attribute renewalMode back to AUTOMATIC.

    For information on how to change the attribute renewalMode, refer to Configure Renewal Mode of Node Credential.

  9. Is the alarm cleared?

    Yes: Proceed with Step 12.

    No: Continue with the next step.

  10. Perform data collection, refer to Data Collection Guideline.
  11. Consult the next level of maintenance support. Further actions are outside the scope of this instruction.
  12. Job is completed.


Copyright

© Ericsson AB 2014, 2015, 2016. All rights reserved. No part of this document may be reproduced in any form without the written permission of the copyright owner.

Disclaimer

The contents of this document are subject to revision without notice due to continued progress in methodology, design and manufacturing. Ericsson shall have no liability for any error or damage of any kind resulting from the use of this document.

Trademark List
All trademarks mentioned herein are the property of their respective owners. These are shown in the document Trademark Information.

    Certificate Management, Automatic Enrollment Failed