This article addresses an issue where SRX devices fail to complete the auto-re-enrollment process with a Certificate Authority (CA) when managed by any management application. The failure occurs during PKIConfirm validation in CMPv2 transactions.
After a successful initial enrollment with the CA, the auto-re-enrollment process fails. The SRX device does not transition to a successfully renewed state, and the local certificate eventually expires. Logs indicate that PKIConfirm validation fails even though the KUR response is valid.
Root Cause:
Responses for a single CMPv2 re-enrollment transaction are coming from two different RA servers. Current implementation does not support multiple RA handling within a single transaction.
Action:
- Consult accounts team to open an enhancement request to support multiple RA handling within a single enrollment/re-enrollment transaction.
- For now, ensure CA server configuration routes all CMPv2 responses for a transaction through the same RA.