Description

This article provides a work-around for correcting the error condition.

Symptoms

Job Type: Execute RPC, which says 'Success'; however, device enrollment will get failed which can be seen under Job Result 

image.png
image.png

Job Result: 

<output  xmlns:junos="http://xml.juniper.net/junos/22.4R0/junos">Platform is supported by ATP Cloud: VSRX.</output>
<output>Version 22.4R2.8 is valid for bootstrapping.</output>
<output>License found with name: ATP Cloud.</output>
<output>Enrolling with ATP Cloud license serial number: 060xxxxxxx5-qxxC1.</output>
<output>Going to enroll single device for VSRX: 3025FBxxxxFF@06032xxxxx05-qxxxC1 with hostname vSRX-22.4R2.8.</output>
<output>Application Signature DB version on this device is: 3720. Using latest version of Application Signature DB is recommended.</output>
<output>Communicate with cloud...</output>
<output>License type for this device: premium.</output>
<output>License of your device will expire in 364 days.</output>
<output>Remove related security-intelligence service configurations...</output>
<output>Remove related advanced-anti-malware service configurations...</output>
<output>Remove related SSL service configurations...</output>
<output>Remove related PKI configurations...</output>
<output>Clear local certificate aamw-srx-cert...</output>
<output>Clear key pair: aamw-srx-cert...</output>
<output>Clear CA profile aamw-cloud-ca...</output>
<output>Clear CA profile aamw-secintel-ca...</output>
<output>Configure CA...</output>
<output>Request aamw-secintel-ca CA...</output>
<output>Wait aamw-secintel-ca CA download status...</output>
<output>Load aamw-secintel-ca CA...</output>
<output>Request aamw-cloud-ca CA...</output>
<output>Wait aamw-cloud-ca CA download status...</output>
<output>Load aamw-cloud-ca CA...</output>
<output>Retrieve CA profile aamw-ca...</output>
<output>CA certificate ready: aamw-ca...</output>
<output>CA certificate ready: aamw-cloud-ca...</output>
<output>CA certificate ready: aamw-secintel-ca...</output>
<output>Generate key pair: aamw-srx-cert...</output>
<output>Enroll local certificate aamw-srx-cert with CA server...</output>
<xnm:error xmlns:xnm="http://xml.juniper.net/xnm/1.1/xnm">
<source-daemon>op-script</source-daemon>
<message>[Error] Enrollment failed. Fail to set client certificate aamw-srx-cert with time issues. Setting device time correctly will resolve this issue. Please run diagnostic process.
Please run diagnostic process with the following cli command:
 request services advanced-anti-malware diagnostics srxapi.ap-northeast-1.sky.junipersecurity.net detail pre-detection</message>
</xnm:error>
<xnm:error xmlns:xnm="http://xml.juniper.net/xnm/1.1/xnm">
<source-daemon>op-script</source-daemon>
<message></message>
</xnm:error>

 

Below output can be seen on the device

[email protected]> request services advanced-anti-malware diagnostics srxapi.ap-northeast-1.sky.junipersecurity.net detail pre-detection 
    [INFO]    Try to get IP address for hostname srxapi.ap-northeast-1.sky.junipersecurity.net
DNS check                                            : [OK]
    [INFO]    Try to test Juniper ATP server connectivity
    [INFO]    Successfully connected to srxapi.ap-northeast-1.sky.junipersecurity.net:443
    [INFO]    Successfully connected to ca.junipersecurity.net:8080
    [INFO]    Successfully connected to va.junipersecurity.net:80
Juniper ATP reachability check                       : [OK]
    [INFO]    Time difference between ATP server and this device: 1358 second(s)
Time check                                           : [Failure]
Error: Time difference is too large between server and this device. Please adjust your local time
    [INFO]    Configuration checking passed: PKI
    [INFO]    Configuration checking passed: SSL
    [INFO]    Configuration checking passed: AAMW Connection
    [INFO]    Configuration checking passed: SecIntel URL
    [INFO]    Configuration checking passed: SecIntel Authentication
Configuration activation check                       : [OK]
    [INFO]    Try ICMP service in Juniper ATP
Juniper ATP ICMP service check                       : [OK]
    [INFO]    To-ATP connection is using ge-0/0/0.0, according to route
Interface configuration check                        : [OK]
Outgoing interface MTU is default value
    [INFO]    Check IP MTU with length 1472
    [INFO]    Check IP MTU with length 864
    [INFO]    Check IP MTU with length 560
    [INFO]    Check IP MTU with length 408
    [INFO]    Check IP MTU with length 332
    [INFO]    Check IP MTU with length 294
    [INFO]    Check IP MTU with length 275
    [INFO]    Check IP MTU with length 265
    [INFO]    Check IP MTU with length 260
    [INFO]    Check IP MTU with length 258
    [INFO]    Check IP MTU with length 257
Warning: Outgoing interface MTU larger than path MTU
IP Path MTU is 256
    [INFO]    VSRX detected. Checking system licenses
VSRX License check                                   : [OK]

[email protected]> show system uptime 
Current time: 2024-07-09 06:34:56 UTC
Time Source:  LOCAL CLOCK 
System booted: 2024-06-16 02:40:29 UTC (3w2d 03:54 ago)
Protocols started: 2024-06-16 02:42:05 UTC (3w2d 03:52 ago)
Last configured: 2024-07-09 06:29:44 UTC (00:05:12 ago) by root
 6:34AM  up 23 days,  3:54, 1 users, load averages: 0.60, 1.49, 3.86

 

Below Output can be seen on SD-PE

# mysql -uroot -pmariadb -A feeder -e "select * from device where name='vSRX-22.4R2.8' \G;"
*************************** 1. row ***************************
                    id: 0934a635-2831-4e44-ac06-d38e7f3a2f2a
                 emsId: 12
               emsSdId: 1998848
            lsysDevice: 0
   lsysRootDeviceEmsId: 12
 lsysRootDeviceEmsSdId: 1998848
                  name: vSRX-22.4R2.8
           description: NULL
                domain: NULL
          feedSourceId: 7971b4a0-9197-4ae5-952d-d9fb509e56a6
                    ip: 10.x.x.x
                 model: VSRX
          serialNumber: 3025FBBA6CFF
 secondarySerialNumber: NA
               cluster: 0
              createTs: 1720507871
              updateTs: 1720508137
            initStatus: FAILURE
          enrollStatus: ENROLL_FAILURE
feedSourceConfigStatus: NULL
      initStatusReason: Sky Enrollment Failed
  enrollFailureDetails: ['[Error] Enrollment failed. Fail to set client certificate aamw-srx-cert with time issues. Setting device time correctly will resolve this issue. Please run diagnostic process.', 'Please run diagnostic process with the following cli command:', ' request services advanced-anti-malware diagnostics srxapi.ap-northeast-1.sky.junipersecurity.net detail pre-detection', 'None']
           connectorId: NULL
       perimeterDevice: 1

 

Solution

Step 1: To set/change clock or NTP settings follow KB15756 [juniper.net]

After updating/changing the timestamp verify the same on device

Example: 
[email protected]> show system uptime    
Current time: 2024-07-09 07:01:54 UTC
Time Source:  NTP CLOCK 
System booted: 2024-06-16 03:04:19 UTC (3w2d 03:57 ago)
Protocols started: 2024-06-16 03:05:56 UTC (3w2d 03:55 ago)
Last configured: 2024-07-09 07:01:47 UTC (00:00:07 ago) by root
 7:01AM  up 23 days,  3:58, 1 users, load averages: 0.93, 1.24, 3.28

Step 2: Now need to enrol device back under secure fabric by following below steps. 

a) SD UI > Devices > Secure Fabric > Sites > Unselect the affected device -> click ok, then it will create Execute RPC job which will be visible under Job Management. 

b) SD UI > Devices > Secure Fabric > Sites > select the affected device > click ok, then it will create Execute RPC job which will be visible under Job Management and Make sure device enrolment is successful 

Job Type: Execute RPC

Job Result: 

<output  xmlns:junos="http://xml.juniper.net/junos/22.4R0/junos">Platform is supported by ATP Cloud: VSRX.</output>
<output>Version 22.4R2.8 is valid for bootstrapping.</output>
<output>License found with name: ATP Cloud.</output>
<output>Enrolling with ATP Cloud license serial number: 060320xxxxxx-qu4C1.</output>
<output>Going to enroll single device for VSRX: 3025xxxxxCFF@06032xxxx05-qu4C1 with hostname vSRX-22.4R2.8.</output>
<output>Application Signature DB version on this device is: 3720. Using latest version of Application Signature DB is recommended.</output>
<output>Communicate with cloud...</output>
<output>License type for this device: premium.</output>
<output>License of your device will expire in 364 days.</output>
<output>Remove related security-intelligence service configurations...</output>
<output>Remove related advanced-anti-malware service configurations...</output>
<output>Remove related SSL service configurations...</output>
<output>Remove related PKI configurations...</output>
<output>Clear local certificate aamw-srx-cert...</output>
<output>Clear key pair: aamw-srx-cert...</output>
<output>Clear CA profile aamw-cloud-ca...</output>
<output>Clear CA profile aamw-secintel-ca...</output>
<output>Configure CA...</output>
<output>Request aamw-secintel-ca CA...</output>
<output>Wait aamw-secintel-ca CA download status...</output>
<output>Load aamw-secintel-ca CA...</output>
<output>Request aamw-cloud-ca CA...</output>
<output>Wait aamw-cloud-ca CA download status...</output>
<output>Load aamw-cloud-ca CA...</output>
<output>Retrieve CA profile aamw-ca...</output>
<output>CA certificate ready: aamw-ca...</output>
<output>CA certificate ready: aamw-cloud-ca...</output>
<output>CA certificate ready: aamw-secintel-ca...</output>
<output>Generate key pair: aamw-srx-cert...</output>
<output>Enroll local certificate aamw-srx-cert with CA server...</output>
<output>Configure SSL service...</output>
<output>Configuration added successfully for SSL service.</output>
<output>Configure advanced-anti-malware service...</output>
<output>Configuration added successfully for advanced-anti-malware service.</output>
<output>Configure security-intelligence service...</output>
<output>Configuration added successfully for security-intelligence service.</output>
<output>Check configuration on device...</output>
<output>SSL profile:                          [OK]</output>
<output>SecIntel CA:                          [OK]</output>
<output>Cloud CA:                             [OK]</output>
<output>Client cert found:                    [OK]</output>
<output>SSL profile action:                   [OK]</output>
<output>URL for advanced-anti-malware:        [OK]</output>
<output>Profile for advanced-anti-malware:    [OK]</output>
<output>URL for security-intelligence:        [OK]</output>
<output>Profile for security-intelligence:    [OK]</output>
<output>All configurations are correct for enrollment.</output>
<output>Communicate with cloud...</output>
<output>Wait for aamw connection status...</output>
<output>Device enrolled successfully!</output>
<output>Please see following links for more information:</output>
<output>ATP Cloud sample config:
 https://www.juniper.net/documentation/en_US/release-independent/sky-atp/topics/example/configuration/sky-atp-policy-creating-cli.html</output>
<output>ATP Cloud quick start guide:
 http://www.juniper.net/documentation/en_US/release-independent/sky-atp/information-products/topic-collections/sky-atp-qsg.pdf</output>
<output>ATP Cloud technical documents:
 http://www.juniper.net/documentation/en_US/release-independent/sky-atp/information-products/pathway-pages/index.html</output>
<output>It is recommended to run diagnostic process with the following cli command to make sure all configurations are valid:
 request services advanced-anti-malware diagnostics srxapi.ap-northeast-1.sky.junipersecurity.net detail</output>


Note : If you face any issues, please contact JUNIPER JTAC Support for assistance.

Modification History

Article Created -9th July 24