Cisco Preparative Procedures & Operational User Guide
© 2016 Cisco Systems, Inc. All rights reserved.
in the peer’s certificate chain
Any certificate revoked in the
peer’s certificate chain
Connection fails with syslog
message
Connection fails with syslog
message
One CDP is missing in the peer’s
certificate chain
Connection fails with syslog
message
Peer certificate: connection
fails with syslog message
Intermediate CAs: connection
succeeds
One CDP CRL is empty in the
peer’s certificate chain with valid
signature
Connection fails with syslog
message
Any CDP in the peer’s certificate
chain cannot be downloaded
Connection fails with syslog
message
Peer certificate: Connection
fails with syslog message
Intermediate CAs: connection
succeeds
Certificate has CDP, but the CDP
server is down
Connection fails with syslog
message
Peer certificate: Connection
fails with syslog message
Intermediate CAs: connection
succeeds
Certificate has CDP, server is up,
and CRL is on CDP, but the CRL
has an invalid signature
Connection fails with syslog
message
Peer certificate: Connection
fails with syslog message
Intermediate CAs: connection
succeeds
Table 4 Certificate Revocation Check Mode set to Strict with a local static CRL
Checking peer certificate chain
Full certificate chain is required
Full certificate chain is required
Checking CDP in peer certificate
chain
Full certificate chain is required
Full certificate chain is required
CDP checking for Root CA
certificate of the peer certificate
chain
Any certificate validation failure
in the peer certificate chain
Connection fails with syslog
message
Connection fails with syslog
message
Any certificate revoked in the
peer certificate chain
Connection fails with syslog
message
Connection fails with syslog
message
One CDP is missing the peer
certificate chain