Microsoft Windows
Sun Solaris
Check Point Firewall
Unable to request Certificate for a Check Point Firewall through PKCS10 request in RSA Certificate Manager.
When submitting a PKCS10 request from Check Point Firewall through the enrollment page, the following error appears after clicking the Submit button:
!PKCS10Parse(): [XrcDECODINGFAILURE] unable to complete decoding operation. XudaParsePKCS10Request(): [XrcDECODINGFAILURE: unable to complete decoding operation]
When generating the request in Check Point Firewall, there is an option to include alternative name information.
ex: IP address. You select the checkbox and the option you require. This information is put in as part of the subject Alternative Name.
When using an ASN.1 Editor to view the request, the Subject Alternative Name portion appears as follows:
243 31 22: SET {
245 30 20: SEQUENCE {
247 30 18: SEQUENCE {
249 06 3: OBJECT IDENTIFIER subjectAltName (2 5 29 17)
254 01 1: BOOLEAN FALSE <----------------------
257 04 8: OCTET STRING
: 30 06 87 04 3E B0 3F 28
The line that includes BOOLEAN FALSE should not be included in that part of the request as it is an invalid format. This causes the decoding failure.
Related Articles
How to log a request for enhancement (RFE) for RSA Identity Governance & Lifecycle 295Number of Views Exclusion in workflow approval node not working if Out Of Office is set for an approver in RSA Identity Governance & Lifec… 52Number of Views Change Request Revert Workflow stuck in Canceling state in RSA Identity Governance and Lifecycle 90Number of Views Events and incidents mark as deleted automatically 17Number of Views How to perform Validation checks when building Request Forms in RSA Identity Governance & Lifecycle 59Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle Unable to attach a replica instance due to a configuration error when enabling replication for the RADIUS server for RSA A… Oracle 12c TEMP_UNDO_ENABLED parameter for managing GTT UNDO activity in RSA Identity Governance & Lifecycle RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server