Description

This article addresses an issue where SRX devices fail to complete the auto-re-enrollment process with a Certificate Authority (CA) when managed by any management application. The failure occurs during PKIConfirm validation in CMPv2 transactions.

Symptoms

After a successful initial enrollment with the CA, the auto-re-enrollment process fails. The SRX device does not transition to a successfully renewed state, and the local certificate eventually expires. Logs indicate that PKIConfirm validation fails even though the KUR response is valid.

 

Solution

Root Cause:

Responses for a single CMPv2 re-enrollment transaction are coming from two different RA servers. Current implementation does not support multiple RA handling within a single transaction.


Action:

- Consult accounts team to open an enhancement request to support multiple RA handling within a single enrollment/re-enrollment transaction.

- For now, ensure CA server configuration routes all CMPv2 responses for a transaction through the same RA.


Modification History

2025-11-26 : Article Created