Crypto Match (CRP) test

This test checks that the X509 certificates that the Agent uses are valid.

The five possible results are:

CRP – OK

No troubleshooting necessary.

CRP – Untested

This result is returned when a functional area cannot be tested because of a previous failure that prevents further testing. For example, if the Agent cannot be reached, then no other tests are possible.

What can I do if a test is not run during a CRP test?

First resolve all tests that failed, and then run the Communication Test again.

CRP – Unexpected error

This result indicates that the test encountered an unexpected error.

What can I do if I get an unexpected error during a CRP test?

First resolve all tests that failed, and then run the Communication Test again. If the unexpected error recurs, check to see if any additional details in the error message indicate the problem. If the error cannot be resolved, contact Hewlett Packard Enterprise Customer Support.

CRP – Agent certificate mismatch

This result indicates that the certificate that the Agent is using (agent.p12) does not match the certificate that is registered with Server Automation for that Agent. Also, a server hosting a Slice Component bundle with the wrong time zone specified could cause a large number of servers with a CRP error during a communications test.

What can I do if I get a certificate CN mismatch during a CRP test?

If the mismatch is determined to be due to a time zone mismatch, synchronize the time zone specifications for the servers. If the error is due to a certificate mismatch, use the Recert Agent Custom Extension to issue a new certificate to the Agent.

CRP – SSL negotiation failure

This result indicates that the Agent is not accepting SSL connections from the SA core. (The SA core is the entire collection of servers and services that provide Server Automation services.) The likely cause of this error is that one or more files in the Agent crypto directory are missing or are invalid.

What can I do if I get an SSL negotiation failure during an CRP test?

Run the Server Recert custom extension in the “set allow recert flag only” mode on the server, and then Run the Server Agent Installer with the “-c” switch.

Reinstalling the Agent with the “-c” option (“c” stands for “clean”) removes all certs on the server and also removes the MID file, which forces the Agent to retrieve a new MID from the Data Access Engine.

See Run server communication tests for more information about how to install a Server Agent using the “-c” switch.

After you reinstall the Agent, run the test again to check if the Agent is now reachable.