Guest

Preview Tool

Cisco Bug: CSCuo85705 - IOS > 15.2(4)M5 PKI chain-validation continues to inherit Root TP policy

Last Modified

Oct 14, 2019

Products (69)

  • Cisco IOS
  • Cisco C897VA Integrated Services Router
  • Cisco 1905 Serial Integrated Services Router
  • Cisco 812 CiFi Integrated Services Router
  • Cisco 861W Integrated Services Router
  • Cisco 892W Integrated Services Router
  • Cisco 819 Hardened Integrated Services Router
  • Cisco C892FSP Integrated Services Router
  • Cisco 2951 Integrated Services Router
  • Cisco 881SRSTW Integrated Services Router
View all products in Bug Search Tool Login Required

Known Affected Releases

15.2(4)M6

Description (partial)

Symptom:
In a configuration where both Root and Sub have revocation check enabled,  IOS PKI Client falls back to the older behavior of inheriting the Root trustpoint policy [while downloading CRL during cert validation] in the following situations:
a) Both Root and Sub-CA CRLs are not yet downloaded
b) Root CRL is available and Sub CRL is not yet downloaded

Conditions:
IOS PKI Client configured with chain-validation:

crypto pki trustpoint Root-CA
  vrf mgmt
  source-interface eth0/0
  revocation-check crl 

crypto pki trustpoint Sub-CA
  vrf secure
  source-interface eth0/1
  revocation-check crl 
  chain-validation continue Root-CA
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.