Article Number
000019572
Applies To
Keon Certificate Authority 6.0
Microsoft Windows 2000 SP2
Microsoft Windows NT 4.0 SP6a
Sun Solaris
SCEP
Issue
SCEP URL requests fail on Keon Certificate Authority 6.0
SCEP Error logs:
\RSA_KeonCA\WebServer\logs\scep-error.log
\RSA_KeonCA\WebServer\logs\scep-access.log
Show the following errors:
operation=GetCACert&message=RouterCA HTTP/1.0 200 47
operation=GetCACert&message=RouterCA HTTP/1.0 404 409
Cause
The RSAKeonCAAdministratorsGuide.pdf document states on page 293 that the SCEP URL format should be as follows:
http://<scep-server-host>:<scep-server-port>/domainID=<jurisdiction-id>/pkiclient.exe
Resolution
The "domainID=" value in the SCEP URL is not required. The correct format for the SCEP URL request should be as follows:
http://<scep-server-host>:<scep-server-port>/<jurisdiction-id>/pkiclient.exe
This will be corrected in future releases of the documentation.