problem with the ios certificate server does not update the CRL

Hi all

The background is that I'm putting a DMVPN solution with tunnels ipsec between the rays created by using certificates.

I use a cisco 877 as the CA server (its 12.4 (6) T5) running to provide certificates for the spoke routers. This part works very well - rays can apply for a certificate and get a number very well.

The problem is CA, life of LCR is set to 24 hours, but the CA is not updated the LCR so when the rays see CRL (as defined in their trustpoint) they point to a mistake that the CRL is obsolete and does not connect.

If making a ' #sh cryptographic pki server ' it lists a ' CRL NextUpdate timer. It has a timestamp that is 24 hours after the last certificate was revocked. The only way I can get the LCR to be rebuilt must revoke a certificate.

So, my question is, am I missing something here? I thought that it would automatically generations a new CRL list file every 24 hours.

Can anyone help?

Thank you.

Hey Marc (?)

This seems to correspond to this bug:

CSCsy95838    AC IOS: LCR of the not updated, update timer not started

However, it does not mention if 12.4 (6) T5 is affected, only that it was found 12.4 (15) T3 and resolved to 12.4 (15) T10 and other more recent versions.

I suggest trying the last 12.4 (15) Tx, 15.0 (1) Mx or 15.1 (4) Mx version if you can.

I assumed that you have much of it, but just in case: as a workaround, you can disable CRL checking on all routers DMVPN, of course they will still allow connections from routers with a revoked RADIUS.

As (temporary?) substitute for a Revocation list, you can use a 'certificate ACL' with which you can create kind of a 'local CRL Manual:

  crypto pki certificate map certACL 10    serial-number ne    serial-number ne    etc. 

  crypto pki trustpoint myTP
   match certificate certACL
(note the "ne" stands for "not equal" so you are permitting any certificate whose serial number is not listed)
Of course, you would have to configure (and maintain!) participating on each router in the DMVPN so it's heavy, but I guess if you revoke often certs, that it might be an option.
HTH
Herbert

--

If this post answered your question, please click the button of "right answer".

Tags: Cisco Security

Similar Questions

  • Hello, I had a problem with my band. It does not really suppose he numbered scenes everything in order and he has so far in until I missed an and changed for the good order. But now when I go back to where I left and I have create a new scene

    Hello, I had a problem with my band. It does not really suppose he numbered scenes everything in order and he has so far in until I missed an and changed for the good order. But now when I go back to where I left and I have create a new scene number come up as * it and I need to change personally. is their any way I can change it to order normally?

    Hello

    You can manage this through the "Manage scene numbers" option in the menu 'Production '.

    There is a setting in this dialog box to assign scene numbers automatically to the new scenes.

  • Problem with Windows Fax and Scan does not connect to the Internal Modem

    Just got a new Acer Aspire 5542-5416 computer laptop with Windows 7 64 bit Home Premium, 4 GB of Ram and a 320 GB hard drive. It has a 56 k modem integrated fax of like the old days, but I can't make it work. The laptop did not come with the Windows CD.

    If I open the program Windows Fax and Scan, it is not able to connect to the modem. Basically, if I click on tools > fax accounts > Add..., I get a box with 2 choices: to connect to a fax modem or connect to a fax on my network server. When I want to connect a fax modem I get a message that says: an error has occurred. Please, try the operation again later or contact your administrator. It allows me to do this then just clock OK and them I'm right where I started.

    While in Windows Fax and Scan, if I click on tools > fax settings... nothing happens. No menu settings or anything ever appears. Quite simply, the program does nothing. If I try tools > Fax Status Monitor... I get a box that says entrance exam status, ready to receive a fax. It has a blue progress bar as something takes over, but it gets about 1/100 to and never goes further or ends. There is no box, but there are 3 buttons: view details, answer call or cancel. If I hit details, I get an empty list. If I click on answer call I get an error that says that the fax service is not available.

    If I try tools > Options, general tab has only a single option box is checked: play a sound when come it to new messages. If I try to print a Word or PDF file to a fax using Fax in the printer list, I get the same box with 2 choices: to connect to a fax modem or connect to a fax on my network server, but I get the same error message: an error has occurred. Please, try the operation again later or contact your administrator.

    I've searched the Internet high and low for a solution but no luck. There is a lot of discussion about this problem, but none of the solutions work for me. If I go to Device Manager, the modem is working properly and if I click on the Modem query on the Diagnostics tab, it seems to be able to communicate with the modem very well. I tried to roll back the driver and updated again and still no luck, same problem. If I go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Accounts in the registry, there is no subkeys under the folder accounts I can delete.

    Has anyone else had a similar problem? Is there any solution for this? I did a Windows Update last night and has not yet solve it. Thank you.

    Sorry about that.

    Here is the link:

    http://social.msdn.Microsoft.com/forums/en-us/windowscompatibility/thread/c75ae899-D05B-411D-a7f2-00fdd33b8589/

  • Dell Openmanage 7.4 64-bit on Poweredge 6850 with 2012 Windows Datacenter Server does not recognize the storage controllers

    Hi, masters!

    I installed the package Dell OMSA 7.4 (OM-SrvAdmin-Dell-Web-WINX64-7.4.0-866_A00) on my Poweredge 6850 with Windows Server 2012 - Datacenter. Everything works fine, except for the storage controller. The OMSA displays the message: no storage controller found. Can you help me?
    Thank you

    Diramos

    Hello Diramos,

    That is a difficult question because OMSA stopped supporting older systems of the gen 8 back to 6.x what OMSA 6.5 works with 8 Gen but most customers will find the more stable 5.5 with 8 gen systems.  Now, the other problem is that Sever 2012 is not listed as an operating system supported for Dell 8th gen systems either.  Obviously, it works, since you have it installed, but you may encounter compatibility problems.  Particularly like this this is not a systems management configuration that will work well.

    Windows 2008 R2 work OMSA 6.5.

    Let us know if you have any other questions.

  • Files from the server does not update the when editing in Machine Windows 7

    I am editing the files on a server with a machine running windows 7 pro. Some files are not updated when changes are made, but the machine seems to be storing it locally. Does anyone have an idea on how to fix this? Thank you!

    Hello

    As you are working on a Windows Server environment I suggest you you posted the question under Windows Server TechNet forum for assistance from the public pro IT. see the following link:

    http://social.technet.Microsoft.com/forums/en/category/w7itpro

    Hope this helps

  • Mobile sync db DOM with adf base db server does not

    Hello
    We have successfully installed and run the ADF base and apps mobile adf for the fusion order demo app.
    Now, we strive to synchronize the client and server dbs.
    Our database server is Oracle Database 10g Enterprise Edition Release 10.2.0.4.0 and customer db is what came with the laboratories for this mobile customer FOD app zip file.
    Our Jdev, sits on the same box as the above mentioned db server, and that is why we have installed the MS and MDK on the same box, under two houses (D:\Olite10g_1 and D:\Olite10g_2).

    And then we followed the instructions given in the thread by Dennis T (jdeveloper and customer data synchronization blackberry mobile and Mobile Client for Oracle ADF Developer's Guide (section 8.3 creation Data Sync Publications on the server).)

    Also, since the mobile client guide mentioned developer that sync is not possible for autonomous databases, we have changed the deployment of the application profile
    to change the client to use database connection properties "synchronized database on the client" with the name as MOBILEFOD, same as what gave us to the deployment properties of the 'model' project according to the mobile client app dev guid, section 8.3

    Now, when I try to deploy the objects of publishing app under the instructions of Dennis, Jdev reports the following error: "no entity object is enabled for the synchronization. Publication has not been created for the application. "and completed the deployment without doing anything.

    Then we have redeployed the client app from applications - deploy the menu, and now when the application opens, it asks username username-password - server... I give address/localhost/127.0.0.1 syncuser-syncuser-ip, but all three options for the server give the same error: "'databases' element is not valid in this document.

    Can anyone help please?
    Kind regards
    Hemant

    Hello









    It comes to my working copy.
    You may need to remove as get you the basics of item data is not valid"


  • problem with zooworld game on facebook does not

    for the last month or two, my zooworld page will not load on my computer... it will be on my laptop other friends computers... and girls suggested zooworld defrag, cleansweep and erase cookies, which was done and page still load. ZooWorld said the problem is with the Explorer of windows xp or on the internet... but this is a problem for the past month and I can't find out where the problem lies... someone can help me?

    Sometimes applications don't load. You have the latest plug-ins? Maybe that's the problem. Or use another browser.

  • Problem with interactive PDF on MAC does not not on PC

    I'm an interactive PDF that will be sent to many people.

    The PDF file contains links that open other PDF files. These all work perfectly on Mac. When on a PC the half opened, half don't. I don't know much about PC at all, they use acrobat pro V9.

    Has anyone encountered this problem? and know a solution?

    The files are always kept at togther connects so broken arnt

    Thank you

    Grace

    Thank you. Solved the problem, I Redid the folder with the links, that worked.

    Something went funny obiously in the folder!

  • Please Adobe guys, please! the problem with PREVIEWS. 13.7 does not YET

    As a professional, I use software 'professional' we need to play previews in real-time.

    I can't say to can the customers: "oh sorry, it is not real-time, but imagine it runs a little faster as you watch.

    A lot of time (and versions) there is this characteristic essential and ancient, has been broken. Nowadays AFX is unusable.

    Please, fix thisand what it NOW OR what we are going to switch to another of the alternatives (Nuke, movement, etc.)

    Thank you!

    As the ticket of Esferobite linked to points out, a quick and easy solution until the bug is corrected is to hide the time to insight into the timeline indicator. The best way to do is to press the "(tilde) key on the Panel composition to make it full screen.

    The reason that works, what the bug is, and what Adobe on the subject are mentioned in the post that is associated.

  • What is the problem with this query? exception does not work.

    DECLARE
    v_employee_id EMPLOYEES. EMPLOYEE_ID % TYPE;
    v_last_name EMPLOYEES. LAST_NAME % TYPE;
    v_salary EMPLOYEES. % SALARY TYPE.
    e_invalid_emp EXCEPTION;
    BEGIN
    SELECT last_name, salary v_employee_id, v_last_name, v_salary, employe_id
    EMPLOYEES where employee_id = & employee_id;

    IF SQL % NOTFOUND THEN
    RAISE e_invalid_emp;
    END IF;

    DBMS_OUTPUT. Put_line(v_employee_id||) e '|| v_last_name | » '|| v_salary);

    EXCEPTION
    WHEN e_invalid_emp THEN
    DBMS_OUTPUT. Put_line ("' employee not found...");
    END;
    /
  • Problem with my printer - printer spooler does not

    Printer Spooler not working do not, said no installed printer, doesn't let me install again running with windows Xp.  I can do no problem before working with this printer for 10 months with no problems, is there a solution.

    Often, but not always, the symptoms you describe are caused by a corrupt print job stuck in the queue or a damaged printer driver.  However before you clean things up, on general principles, that you can download, install, update and run full scans with each of these two free programs:

    AntiMailware MalwareBytes
    SUPERAntiSpyware

    Do not operate the two scans simultaneously.  Each will take a long time, so start it and then go do something else for a while.

    Cleaning of printers

    NOTE: If after completing step has the print spooler is not always running after you launched the command "net start spooler", you will not be able to follow all the steps in "First Article".  Use of the special procedure for printers Lexmark described below and follow in its first Article.  If still no joy, use the alternative method that is linked below.

    A. Clean on print jobs pending

    • Open a command prompt window (start > run > cmd > OK)
    • Type the following in the black command prompt window, and then press ENTER after each line

    net stop spooler
    del/q '% windir%\system32\spool\PRINTERS\*.* '.
    net start spooler
    output

    B. clean the old printer drivers and install the latest drivers by using the directions in One Article.

    A special procedure for computers that have or had a Lexmark or Dell-badged Lexmark printer.

    Open a command prompt window (start > run > cmd > OK)

    Type the following in the black command prompt window and press enter

    dependent on the spooler of sc config = RPCSS
    output

    Note that there is no space before the =

    If you want to use a Lexmark or Dell-badged Lexmark printer after having done the above, you will need to reinstall it.

    Alternative to the method of his Article: http://members.shaw.ca/bsanders/CleanPrinterDrivers.htm

  • Problem with ssl on ISA Server 2004 traffic shaping

    Hello

    I use "Bandwidthsplitter" addon for ISA Server 2004 (Enterprise Edition) for shaping traffic and quota control. I have a serious problem with it. This addon does not take into account the ssl traffic user, and I need to restart the Microsoft ISA Server priodically Control Service or allow the users to be connected via ssl until they themselves kill their session.

    I will be grateful if someone help me to solve this problem.

    Thanks in advance

    Bijan

    Hello

    The question you posted would be better suited to the TechNet community. Please visit the link below to find a community that will support what ask you

    http://social.technet.Microsoft.com/forums/en-us/Forefrontedgegeneral/threads

  • Dual booting - problem with the disk when trying to start windows

    original title: problems with dual boot.  Windows does not play well with others.

    Hello

    I have Windows Vista Home Premium 64-bit included with the computer.  I installed Fedorah and it works on my computer.  When I installed it, but I had my hard drive partion.  I left most of the hard drive (about 400 concerts) as it was, when I booted up Fedorah worked well and gave me the option to boot or windows.  When I started in the window, however, it wouldn't let me start my computer, it says I have a problem with my drive.  With XP, it gives me no problem, I didn't ignore the disk check, but with Vista for some reason it doesn't let me start.  It gives me a few options of restoration to the previous status confuses the computer he says I manually type in which windows in the command line.  I don't have my windows CD, the only other option that I have that seems to work when I click it is restoring to factory fault which I don't want to do because I don't want to lose all my files.  Please tell me what I need to do.

    http://Fedoraforum.org/

    Fedora forums at the link above.

    A refund Stsrtup of Vista Disk link.

    Download the 64-bit on the right.

    Download the ISO on the link provided and make a record of repair time it starts.

    Go to your Bios/Setup, or the Boot Menu at startup and change the Boot order to make the DVD/CD drive 1st in the boot order, then reboot with the disk in the drive.

    At the startup/power on you should see at the bottom of the screen either F2 or DELETE, go to Setup/Bios or F12 for the Boot Menu.

    When you have changed that, insert the Bootable disk you did in the drive and reboot.

    http://www.bleepingcomputer.com/tutorials/tutorial148.html

    Link above shows what the process looks like and a manual, it load the repair options.

    NeoSmart containing the content of the Windows Vista DVD 'Recovery Centre', as we refer to him. It cannot be used to install or reinstall Windows Vista, and is just a Windows PE interface to recovering your PC. Technically, we could re-create this installation with downloadable media media freely from Microsoft (namely the Microsoft WAIK, several gigabyte download); but it is pretty darn decent of Microsoft to present Windows users who might not be able to create such a thing on their own.

    Read all the info on the website on how to create and use:

    http://NeoSmart.net/blog/2008/Windows-Vista-recovery-disc-download/

    ISO Burner:http://www.snapfiles.com/get/active-isoburner.html

    It's a very good Vista startup repair disk.

    You can do a system restart tool, system, etc it restore.

    It is NOT a disc of resettlement.

    See you soon.

    Mick Murphy - Microsoft partner

  • Adobe lightroom does not update when I use the application manager to download upgrades.

    Hello

    I have problems with adobe lightroom.  It is not updated when I use the application manager to download the new updates.  I tried to uninstall the application and re-download it, however the application manager will not allow that to happen because it shows that it is already installed and up to date. I think that the problem may have started when I installed lightroom using a link which you offered when creative cloud first started offering of lightroom.  This version of the program does not appear to work with the application manager.  Please let me know what I should do to fix the problem.

    Best regards

    S

    Hello

    Please, try to remove Adobe Extension manager and install again. The reinstallation of the extensions Manager try to day light the room.

    If it does not resolve that question please make a complete own using adobe cleaner tool and reinstall everything.

    Thank you

    Kapil Malik

  • I keep having problems with my server DNS does not. Computer Blu - Ray player and wireless both have problems with the connection.

    I have problems with the server DNS does not.  I have been using my wireless on my computer and watching netflix on my Blu - ray player at the same time.  The Blu - Ray player froze and wouldn't connect.  At first, I thought that the network has not been configured correctly, but it worked not five minutes before.  I tried many things and I realized it was that my DNS server does not.  Does anyone have any suggestions?

    original title: DNS server does not

    Hi Dwright,

    1. have you made changes on the computer recently?
    2. not the problem only occurs when you watch netflix on Blu - Ray player?

    Method 1
    I suggest you try the steps from the following link to fix the server DNS does not problem.
    a. click on start and then Control Panel.
    b. go to the networking and sharing Center and then click on change adapter settings.
    c. right-click on connection to the Local network and select Properties.
    d. Select Internet Protocol Version 6, and then click Properties.
    e. Select obtain DNS server automatically an address and press Ok.
    f. Select obtain IP address automatically.
    g. Repeat steps for Internet Protocol version 4 as well.

    Method 2
    Try resetting Winsock2 from the following link:

    How to determine and to recover from Winsock2 corruption in Windows Server 2003, Windows XP and Windows Vista (applies to Windows 7)
    http://support.Microsoft.com/kb/811259

    Method 3
    Reset TCP\IP.
    How to reset the Internet Protocol (TCP/IP) (applies to Windows 7)
    http://support.Microsoft.com/kb/299357

    Additional information:
    Windows wireless and wired network connection problems
    http://Windows.Microsoft.com/en-us/Windows/help/wired-and-wireless-network-connection-problems-in-Windows

Maybe you are looking for