QuestionQ8

Troubleshoot a Nutanix Multicloud Environment

Per organizational requirements, an administrator has uploaded a signed SSL certificate to Prism to support Common Access Card (CAC) authentication.

After the certificate uploads successfully, it appears valid, but CAC authentication does not work.

What could be a cause of this issue?

  • A Signature Algorithm is incorrect
  • B There is no Certificate Revocation Let (CRL) configured
  • C RSA key size is incorrect
  • D Online Certificate Status Protocol (OCSP) is not enabled
Explanation

CAC authentication relies on Prism validating the presented client certificate against the trusted signing chain and, when CRL-based revocation checking is used, checking its revocation status through a configured Certificate Revocation List (CRL). Without that CRL, revocation validation can fail and prevent CAC authentication although the certificate otherwise appears valid.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!