Make sure you have auto-certs allowed in control plane security:
(host) (config) #show control-plane-security
Control Plane Security Profile
------------------------------
Parameter Value
--------- -----
Control Plane Security Enabled
Auto Cert Provisioning Enabled
Auto Cert Allow All Enabled
Auto Cert Allowed Addresses N/A
if you don't, turn it on:
(host) (config) #control-plane-security
(host) (Control Plane Security Profile) #auto-cert-allow-all