ALM-4287766530 The CA certificate is nearly expired
Description
PKI/4/PKICACERTNEARLYEXPIRED: OID [OID] the CA certificate is nearly expired. (CACertIssuer=[issuer], CACertSubject=[subject], CACertStartTime=[starttime], CACertFinishTime=[finishtime])
The CA certificate is about to expire.
Attribute
Alarm ID |
OID |
Alarm Severity |
Alarm Type |
---|---|---|---|
4287766530 |
1.3.6.1.4.1.2011.6.122.34.0.2.11 |
Warning |
Communication alarm |
Parameters
Name |
Meaning |
---|---|
OID |
Indicates the MIB object ID of the alarm. |
issuer |
Indicates the issuer of the CA certificate. |
subject |
Indicates the subject of the CA certificate. |
starttime |
Indicates the start time of the CA certificate. |
finishtime |
Indicates the end time of the CA certificate. |
Impact on the System
The service will be invalid after the certificate expires.
Possible Causes
The CA certificate is about to expire. The CA certificate expiration time is less than the certificate expired prewarning time configured by the pki set-certificate expire-prewarning command.
Procedure
- Run the display clock command to check whether the device time is correct.
If not, run the clock datetime command in the user view to change the device time.
- Apply for a new certificate through SCEP or CMPv2 online or apply for a new certificate offline. For details, see "PKI Configuration" in the Huawei AR1000V Product Documentation.
Clearing
After the fault is rectified, the system clears this alarm, removing the need to manually clear it. This alarm will not be displayed on the Current Alarms page.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot