Updated on 2024-01-25 GMT+08:00

ALM-15795010 hwPKICACertNearlyExpired

Description

PKI/4/PKICACERTNEARLYEXPIRED: OID [oid] the CA certificate is nearly expired. (CACertIssuer=[issuer], CACertSubject=[subject], CACertStartTime=[starttime], CACertFinishTime=[finishtime])

The CA certificate is about to expire.

Attribute

Alarm ID

OID

Alarm Severity

Alarm Type

15795010

1.3.6.1.4.1.2011.6.122.34.0.2.11

Warning

Communication alarm

Parameters

Name

Meaning

oid

Indicates the MIB object ID of the alarm.

issuer

Indicates the issuer of the CA certificate.

subject

Indicates the subject of the CA certificate.

starttime

Indicates the start time of the CA certificate.

finishtime

Indicates the end time of the CA certificate.

Impact on the System

The service will be invalid after the certificate expires.

Possible Causes

The CA certificate is about to expire. The CA certificate expiration time is less than the certificate expired prewarning time configured by the pki set-certificate expire-prewarning command.

Procedure

  1. Run the display clock command to check whether the device time is correct.If not, run the clock datetime command in the user view to change the device time.
  2. Apply for a new certificate through SCEP or CMPv2 online or apply for a new certificate offline. For details, see the Huawei AR SeriesV300R021 Configuration Guide - PKI Configuration

Clearing

The alarm needs to be cleared manually.