158Solution1. Use undo crl check enable to disable CRL checking.2. Make sure the format of the imported file is proper.Failed to import a local certificateSymptomA local certificate cannot be imported.Analysis• The PKI domain has no CA certificate, and the certificate file to be imported does not contain theCA certificate chain.• CRL checking is enabled, but CRLs do not exist locally or CRLs cannot be obtained.• The specified format does not match the actual format of the imported file.• The device and the certificate do not have the local key pair.• The certificate has been revoked.• The certificate is out of the validity period.• The system time is wrong.Solution1. Obtain or import the CA certificate.2. Use undo crl check enable to disable CRL checking, or obtain the proper CRLs.3. Make sure the format of the imported file is proper.4. Make sure the certificate file contain the private key.5. Make sure the certificate is not revoked.6. Make sure the certificate is valid.7. Configure correct system time for the device.Failed to export certificatesSymptomCertificates cannot be exported.Analysis• The PKI domain does not have local certificates when you export all certificates in PKCS12 format.• The specified export path does not exist.• The specified export path is illegal.• The public key of the local certificate to be exported does not match the public key in the key pairof the PKI domain.• The disk space is full.Solution1. Obtain or request local certificates.