How to republish CRL Signer certificate when CRL Signer certificate cannot be found in the external Directory Server
Originally Published: 2003-02-12
Last Modified: 2023-10-06
Article Number
000053992
Applies To
Keon Certificate Authority
Keon Certificate Authority 6.5
UNIX (AIX, HP-UX, Solaris)
Sun Solaris
Issue
How to republish CRL Signer certificate when CRL Signer certificate cannot be found in the external Directory Server
CRL Signer certificate cannot be found in the external Directory Server
Network problems between KCA and external Directory Server
xudad[13493]: [ID 373491 local0.info] (AUDIT FAILURE) Signer certificate publication: md5=898cd449c2bd2b2e7b6be613ee47af94 failed [XrcNOTFOUND:unable to locate requested member or object]
buildAttrTable: unable to locate requested member or object: EMAIL
Resolution
There is no functionality that can republish the CRL Signer certificate if the publishing fails when CRL Signer certificate is created.

A workaround for this is to "Download" the CRL Signer certificate and manually store the certificate in the external Directory server. Alternatively, after external publishing has been fixed, create a new CRL Signer certificate either manually or with CRL timer.