P-662H/HW-D Series User’s Guide

 

Table 193 PKI Logs (continued)

 

 

 

 

LOG MESSAGE

DESCRIPTION

 

 

 

 

Rcvd data <size> too

The router received directory data that was too large (the size is listed)

 

large! Max size

from the LDAP server whose address and port are recorded in the

 

allowed: <max size>

Source field. The maximum size of directory data that the router allows

 

 

is also recorded.

 

Cert trusted: <subject

The router has verified the path of the certificate with the listed subject

 

name>

name.

 

Due to <reason codes>,

Due to the reasons listed, the certificate with the listed subject name

 

cert not trusted:

has not passed the path verification. The recorded reason codes are

 

<subject name>

only approximate reasons for not trusting the certificate. Please see

 

 

Table 194 on page 475 for the corresponding descriptions of the codes.

Table 194 Certificate Path Verification Failure Reason Codes

CODE

DESCRIPTION

 

 

1

Algorithm mismatch between the certificate and the search constraints.

2

Key usage mismatch between the certificate and the search constraints.

3

Certificate was not valid in the time interval.

4

(Not used)

5

Certificate is not valid.

6

Certificate signature was not verified correctly.

7

Certificate was revoked by a CRL.

8

Certificate was not added to the cache.

9

Certificate decoding failed.

10

Certificate was not found (anywhere).

11

Certificate chain looped (did not find trusted root).

12

Certificate contains critical extension that was not handled.

13

Certificate issuer was not valid (CA specific information missing).

14

(Not used)

15

CRL is too old.

16

CRL is not valid.

17

CRL signature was not verified correctly.

18

CRL was not found (anywhere).

19

CRL was not added to the cache.

20

CRL decoding failed.

21

CRL is not currently valid, but in the future.

22

CRL contains duplicate serial numbers.

23

Time interval is not continuous.

24

Time information not available.

25

Database method failed due to timeout.

Appendix O Log Descriptions

475