cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7739
Views
5
Helpful
4
Replies

Expressway client certificate check error

asmlicense
Level 1
Level 1

Hello all, I have problem with certificate deployment in Expressway E and C. I upload MS root CA, intermediate CA and client certificates.

When I check client certificate I get the following error:

Invalid: unable to get certificate CRL, please ensure that you have uploaded a CRL for the CA that signed this client certificate.

In CRL managment I uploaded Root CA CRL file and get the following error:

File upload failed: The file provided is not a valid X.509 PEM encoded CRL file.

Thats why SIP is inactive between E and C.

EXP version is 8.6

CUCM is in mixed mode.

Any idea?

1 Accepted Solution

Accepted Solutions

Jaime Valencia
Cisco Employee
Cisco Employee

Did you download the latest CRL in base 64?

HTH

java

if this helps, please rate

View solution in original post

4 Replies 4

Jaime Valencia
Cisco Employee
Cisco Employee

Did you download the latest CRL in base 64?

HTH

java

if this helps, please rate

I just downloaded it from CA and could not find if it base64 or not? How can I know it?

asm,

If you open the file using Notepad, if it starts with ----BEGIN CERTIFICATE---- then that is Base64 encoded, anything else is DER encoded.

Thanks,
Justin

Thank you,
Justin Ferello
Technical Support Specialist, ScanSource KBZ

I have successfully deployed certificates. Secure Traversal Test is Success, but SIP is still inactive. What can be a problem?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: