
5. Security Manager now possesses revocation
knowledge of the certificate it installed on the
device. If Security Manager attempts to access
the device after gaining this knowledge, the
connection to the device will be refused the next
time an assessment of the installed certificate
occurs and the status will indicate Invalid
Identity certificate.
6. The connection is refused because the certificate has been revoked.
To verify this, you must disable enforcement of SSL/TLS and run an
Assess Only task using the same certificate policy.
After the Assess Only task is complete, the recommendation report
will provide the Connection Refused details. As you can see in the
following image, it is because the device identity certificate was
revoked. Note: The Connection Refused status can also occur
because Security Manager wasn’t able to access the CRL during the certificate assessment process.
If this is the case, perform manual steps to test Security Manager access to the CRL.
7. Because the installed device identity certificate is no longer valid, Security Manager will replace it
with a new CA signed certificate during the next Assess and Remediate task run against that
Comentarios a estos manuales