cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1479
Views
0
Helpful
5
Replies

ACS - System Errors - Could not add Certificate Revocation List

Wil Cha
Level 1
Level 1

Hi All,

I'm receiving daily system errors from ACS but unsure how to fix the issue. The following is the error I receive

Severity :

Error

Time Range :

February 17, 2014 09:08:00.000 AM - February 17, 2014 09:10:00.000 AM

Generated on February 17, 2014 9:14:56 AM EST


Logged At

Severity

Message

Category

Code

Details

ACS Instance

February 17,2014 9:09:06.936 AM

ERROR

Could not add Certificate Revocation ListCSCOacs_Internal_Operations_Diagnostics

33401

LastErrorMessage=CRL PKI verification failed
Certificate Revocation list Url=http://XXXca01.<omitted>.au/CertEnroll/cs-XXXCA01-CA.crl

XXXACS02

February 17,2014 9:08:31.916 AM

ERROR

Could not download Certificate Revocation ListCSCOacs_Internal_Operations_Diagnostics

33402

LastErrorMessage=Failed performing HTTP GET with error: Timeout was reached
Certificate Revocation list Url=http://YYYca01.<omitted>.au/CertEnroll/cs-YYYCA01-CA.crl

YYYACS02

Looks like it is unable to perform certificate recovation on particular CA servers onsite but there doesn't seem to be much configuration options in ACS? Would this be an issue with the onsite CA server?

Thanks in advance.

Regards

Wil

5 Replies 5

Wil Cha
Level 1
Level 1

No Cisco ACS experts available?

Saurav Lodh
Level 7
Level 7

Same issue here, ACS 5.2 (OCSP not available). Are there bugs/issues/workarounds for CRL PKI failing with ACS 5.2 and Microsoft CAs?

benediktdiehl
Level 1
Level 1

I am currently experiencing the exact same issue!
Could currently need some advice from an acs expert too.

jayage
Level 1
Level 1

We got the same on 5.6
Any advice?