PKI server reachability is very important for the certificate generation for any tenant onboarded in CSO, which is used for site authentication and further config generation for that site of tenant.
Check whether the PKI server URLs are correctly configured for the tenant.
Go to CSO UI tenant page, Administration > Tenant setting
>
Go to CSO UI. Navigate to the respective tenant page. Then go to Administration > Certificate Management > VPN Authentication
Select the interested site and click Renew. In the example below, the site name is Test:
Go to CSO UI. Navigate to monitor > Jobs
A new Job for renew certificate will be created and running. Wait for that Job to finish.
Go to view logs of the job. The logs below are seen, which indicates the renew certificate is a success.
It confirms that PKI infrastructure is working as expected.
Job logs: Mar 4, 2021, 3:59:00 PMPhase1 Start Mar 4, 2021, 3:59:00 PMStart to renew cert for site test-site, Phase1 Mar 4, 2021, 3:59:02 PMRetry renew cert for site: test-stie with extra info Mar 4, 2021, 3:59:18 PMPhase2 Start Mar 4, 2021, 3:59:18 PMPhase1 End Mar 4, 2021, 3:59:23 PMPhase2 End Mar 4, 2021, 3:59:23 PMPhase3 Start Mar 4, 2021, 3:59:23 PMPhase3 End Mar 4, 2021, 3:59:23 PMUpdate Site cert Job success