Troubleshooting Tips

This section describes issues to consider when testing or troubleshooting the configuration for the Cloudpath extension.

Error Messages

If a user receives a message "This device requires management controlled extension <extension name>", typically this means that the device does not have the extension installed.

Server CA

If the network does not accept the CA certificate, check that the Issued to section for the Server CA includes both the root and intermediate CA.

Access to URL

If the user unable to reach the enrollment URL, be sure that the client enrollment URL begins with HTTPS://.

Length of Private Key

While older versions of the Chromium OS did not enforce the minimum key length of 1024, the newer releases appear to enforce this change. However, it appears that this change does not support a 4096-bit key.

If you see an error that says "Error: The operation failed for an operation-specific reason.", view the page source on the page4download.html and locate the keylength/alg info. If it lists the following:

<input type='hidden' id='cpnKeyLength' value='4096'/>
<input type='hidden' id='cpnAlgorithm' value='SHA-512'/>

The fix for this issue is to navigate to the certificate template in the Cloudpath Admin UI and change the private key length to 2048 and the algorithm to SHA-256.