Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

"Failed to generate certificate" error message

This thread has been viewed 4 times
  • 1.  "Failed to generate certificate" error message

    Posted Mar 07, 2012 08:18 AM

    Hello all,

     

    After upgrading from 5.0.3.1 to 6.1.3.0, I get the following messages on all of my controllers, constantly:

     

    Mar 7 08:06:59 cpsec[1884]: <335102> <ERRS> |cpsec| handle_gen_cert, Failed to generate certificate, return code -1.
    Mar 7 08:06:59 cpsec[1884]: <335102> <ERRS> |cpsec| handle_gen_cert, Failed to generate certificate, return code -1.
    Mar 7 08:08:27 cpsec[1884]: <335102> <ERRS> |cpsec| handle_gen_cert, Failed to generate certificate, return code -1.
    Mar 7 08:08:27 cpsec[1884]: <335102> <ERRS> |cpsec| handle_gen_cert, Failed to generate certificate, return code -1.

     

    Any ideas what might cause this?

     

    Thanks,

    Dave



  • 2.  RE: "Failed to generate certificate" error message

    Posted Mar 07, 2012 09:33 AM

    Do you have control-plane-security enabled on the controllers? What do you see under "show tpm cert-info" and "show tpm errorlog"?



  • 3.  RE: "Failed to generate certificate" error message

    Posted Mar 08, 2012 10:45 AM

    Hi,

     

    show control-plane-security is as follows:

     

    Control Plane Security - Disabled

    Auto Cert Provisioning - Disabled

    Auto Cert Allow All - Enabled

    Auto Cert Allowed Addresses - N/A

     

     

    The output of the other commands:

     

    show tmp cert-info

     

    subject=/C=US/ST=California/L=Sunnyvale/O=Aruba Networks/OU=Engineering/CN=00:0b:86:61:00:75

    - I've left out the next few lines because they contain an email address and a serial number

    - the Dates listed are within an appropriate range.

     

    show tpm errorlog 

     

    - no error logs

     

     

    Thanks,

    Dave



  • 4.  RE: "Failed to generate certificate" error message

    Posted Mar 09, 2012 10:12 AM

    Hello Dave,

     

    I would suggest opening a ticket with our TAC team so that they can have the logs analyzed and open a ticket with Engineering if 

    needed to analyze the error message and find the trigger for it being generated.

     

    -Bharatharajan Pudugraam