Description

When enrolling an SRX device to ATP Cloud, the enrollment process might fail to complete successfully and return an error about the local certificate aamw-srx-cert key not existing.


Symptoms

The terminal output for enrollment contains the following errors.


...

Enroll local certificate aamw-srx-cert with CA server...

Configure SSL service...


error: [Error] Enrollment failed. Fail to set SSL services configuration.

Please run diagnostic process with the following cli command:

request services advanced-anti-malware diagnostics srxapi.atp-region.sky.junipersecurity.net detail pre-detection

Details:


nsd

certificate 'aamw-srx-cert': key does not exist .


Solution

1). This will occur if TPM is configured.

 

Check TPM status:​

 

user@host> show security tpm status               

TPM Status:

 Enabled: yes

 Owned: yes

 Master Binding Key: created

 Master Encryption Key: configured

 TPM Family: 1.2

 TPM Firmware version: 4.40

 

At this time, the original TPM module configuration is not supported with the ATP Cloud feature.

 

Only the following models which make use of the new Dev-ID with TPM 2.0 module support having TPM enabled alongside ATP cloud: SRX1600, SRX2300, SRX4300, SRX4700

 

2). Sometimes the commit gets stuck on the cluster and it does not allow the ssl services configuration to be successfully committed.

 

In this situation, we need to clear the stuck commit and then try to enroll the device to the cloud.

 

Modification History

2024-11-29 : Article Created

Related Information

Documentation - Trusted Platform Module Overview