What is the next step you should take in troubleshooting this problem?

You have configured a Cisco router to act a PKI certificate server. However, you are experiencing
problems starting the server. You have verified that al CA parameters have been correctly
configured. What is the next step you should take in troubleshooting this problem?

You have configured a Cisco router to act a PKI certificate server. However, you are experiencing
problems starting the server. You have verified that al CA parameters have been correctly
configured. What is the next step you should take in troubleshooting this problem?

A.
Disable and restart the router�s HTTP server function

B.
Enable the SCEP interface

C.
Verify the RSA key pair and generate new keys

D.
Verify that correct time is being used and source are reachable

Explanation:
There are others who prefer the answer from the previous dump.
However, the question clearly states You have verified that al CA parameters have been correctly
configured
So if the configuration is correctly configured, why would you enable SCEP interface again? The
best answer is verify correct time is being used and source are reachable
Having synchronized time is vital for PKI, but PKI does not require that the time be extremely
accurate.
Time synchronization issues can cause certificate validation failures if the current time on the VPN
device is outside the validity range of the CA certificate.



Leave a Reply 0

Your email address will not be published. Required fields are marked *