Certificate Management, Automatic Enrollment Failed

Contents


1   Alarm Description

The alarm is raised when automatic certificate enrollment or renewal failed to execute because of local misconfiguration or remote enrollment service denial.

Note:  
The alarm is raised only if the renewalMode in a NodeCredential Managed Object (MO) is set to AUTOMATIC.

Table 1    Certificate Management, Automatic Enrollment Failed Alarm Causes

Alarm Cause

Description

Fault Reason

Fault Location

Impact

Automatic certificate enrollment or renewal has failed

Automatic enrollment or renewal failed to execute because of local misconfiguration or break in remote enrollment service

Configuration or customization error


This can be for one of the following reasons:


  • Local misconfiguration

  • Failure in remote enrollment service

Node credential

Certificate is not renewed, which causes certificate expiration


Expired certificate can cause secured service failure, for example, Internet Protocol Security connection authenticated by non-existing or expired certificate can fail

2   Procedure

2.1   Handle Alarm Certificate Management, Automatic Enrollment Failed

Prerequisites

Steps

  1. Navigate to the NodeCredential Managed Object (MO) given in the alarm, for example:

    >ManagedElement=NODE06ST,SystemFunctions=1,SecM=1,CertM=1,NodeCredential=1

  2. Compare if the existing configuration information for the NodeCredential MO matches with the information received from the IT or security administrator.

    The values of attributes enrollmentServerGroup and enrollmentAuthority can be checked in the NodeCredential MO with the following command:

    (NodeCredential=1)>show

  3. Change the attribute renewalMode to MANUAL.

    For information on how to change attribute renewalMode, refer to Configure Renewal Mode of Node Credential.

    Note:  
    When renewalMode is set to MANUAL, the alarm is cleared but the problem remains.

  4. Select the appropriate action based on the result in Step 2:
  5. Select the appropriate action based on the result in Step 2:
  6. Renew the certificate.

    For information on how to renew the certificate, refer to Renew Node Credential Online.

  7. Was the Renew Node Credential Online procedure successful?

    Yes: Continue with the next step.

    No: Proceed with Step 9.

    Note:  
    The cause of the failure is shown in resultinfo of the attribute nodeCredentialId.

  8. Change the attribute renewalMode back to AUTOMATIC.

    For information on how to change the attribute renewalMode, refer to Configure Renewal Mode of Node Credential.

  9. Is the alarm cleared?

    Yes: Proceed with Step 12.

    No: Continue with the next step.

  10. Perform data collection, refer to Data Collection Guideline.
  11. Consult the next level of maintenance support. Further actions are outside the scope of this instruction.
  12. Job is completed.


Copyright

© Ericsson AB 2014–2017. All rights reserved. No part of this document may be reproduced in any form without the written permission of the copyright owner.

Disclaimer

The contents of this document are subject to revision without notice due to continued progress in methodology, design and manufacturing. Ericsson shall have no liability for any error or damage of any kind resulting from the use of this document.

Trademark List
All trademarks mentioned herein are the property of their respective owners. These are shown in the document Trademark Information.

    Certificate Management, Automatic Enrollment Failed