Cisco Certified Support Technician (CCST) NetworkingAutomation and ProgrammabilityHard
A network administrator is troubleshooting an issue where a new automation script fails to connect to a network device's API. The script is attempting to establish a secure connection using HTTPS, but it consistently receives an SSL/TLS certificate error. Which of the following is the MOST likely cause of this error?
- AThe network firewall is blocking TCP port 80.
- BThe script is sending an incorrect JSON payload format.
- CThe API endpoint uses an unsupported HTTP method.
- DThe device's clock is significantly out of sync, causing certificate validation issues.
Show answer & explanationAnswer & explanation
Correct answer: D. The device's clock is significantly out of sync, causing certificate validation issues.
SSL/TLS certificate errors, especially 'certificate not yet valid' or 'certificate expired', are frequently caused by a significant time drift on either the client or server device. Certificates have validity periods, and if the device's clock is outside this period, validation will fail. Other options are less likely to cause a specific SSL/TLS certificate error.
Why the other options are wrong
- A. Blocking TCP port 80 would prevent HTTP connections, but HTTPS uses TCP port 443; blocking port 80 would not directly cause an SSL/TLS certificate error on an HTTPS connection.
- B. An incorrect JSON payload would result in a 400 Bad Request or similar error, not an SSL/TLS certificate error.
- C. An incorrect HTTP method would likely result in a 405 Method Not Allowed error, not a certificate error.
SSL/TLS Certificate Validation Errors
Issues arising during the process of verifying the authenticity and validity of an SSL/TLS certificate, often preventing a secure connection from being established.
- Can be caused by expired/invalid certificates
- Mismatched hostnames are a common cause
- Incorrect system time can lead to validation failures
Memory trick: Secure connections need Valid Times, Valid Names, and Trusted Roots.