Certificates SSL ID not chaining of CA

* Any thoughts on what this should have been posted in a different security thread?

I tried this piece so that SSL VPN remote access, understanding PKI and ASA 5500 Series chapter 73 configuration of certificates of the digital Cisco, but still need help.

Here's a basic config that I use to create the CA and ID on ASAs certificates. I use the ASA as the CA server. When I export the SSL trust point it shows not chaining of CA. Since there is no chaining when I load the certification authority in the root store I still have an SSL certificate error.  Instead, I have to load the Trustpoint of SSL certificate. Please take a look and let me know where where my problem is.

CREATE CA

crypto ca server

from SMTP address [email protected] / * /

life ca 3650

certificate of life 3650

CRL life 24

KeySize 2048

KeySize 2048 Server

no passphrase 123456789 stop

CREATE SSL ID TRUSTPOINT

Crypto ca trustpoint Identity_Certificate

LOCAL-CA-SERVER key pair

ID-use ssl-ipsec

no name FQDN

name of the object CN = 192.168.40.1, OR = SSL_ANYCONNECT_VPN <--This would="" be="" my="" headend="">

registration auto

REGISTER TRUSTPOINT

Crypto ca enroll Identity_Certificate

answer NO to include the serial number of the device

DEFINE TRUSTPOINT VPN ON THE EXTERNAL INTERFACE

SSL-trust outside Identity_Certificate point

Initially, I thought it was a problem with the registration oneself in the trustpoint, but I can't seem to understand the steps to complete registration Terminal.

I had stages crypto ca enroll Identity_Certificate and displays the certificate request. At that time there sh crypto ca trustpoint Identity_Certificate is waiting for registration. I can't find the command for the CA that allows registration trustpoint. If I try to export the crypto ca Identity_Cetificate - certificate of identityit says trustpoint are not registered. Of course if I take the registration request and you try to import a ca certificate Identity_Certificate crypto fails because it is not cert.

Triton

Triton,

This is the right forum, and what you watch, it's normal. The local certification authority is not designed to generate a certificate of identity for the SAA itself.  The ASA will have its own identity/SSL certificate, which can be either a self-signed (like you do with registration se - in this case you must import the cert self-signed on clients to avoid warnings from certificate) or a certificate issued by a trusted third party (for example Verisign, Globalsign, etc.).

HTH

Herbert

Tags: Cisco Security

Similar Questions

  • When I open Windows Mail, I now get the security certificate that could not be verified

    I swithched to Verizon and set up my 3 pop forwarding. Everything is in working order, except that now when I go into the windows mail I get an error saying:

    The server to which you are connected using a security certificate that could not be verified.

    The CN of the certificate name does not match the value passed

    Do you want to continue

    Yes No

    What is everything? I called GoDaddy and they said it wasn't their share. Then I talked to Verizon and they said that it is not them but Windos Mail. So what is the answer to get rid of him?

    Thanks for all the tips. I finally thought to it myself. Their teak gave me bad 3 incoming pop attack if it still worked very slow and I had to check the ssl certificate. It works fine now. Thank you all.

  • Import a certificate SSL on SG500X

    I try to use SSL certificates disconnected by the internal CA on all our SG500X and SG500 rocker, the manual is a little vague on the process of importation of the real process, I have generated demand for the switch without specifying a new key (so I guess it used the default value), has presented the request of my CA and downloaded the cert. Because the import option does not allow the import of the cer file, I open with a text editor and copied the cert, including start and end markers, when I submit, in it I get the error: SSL could not import the certificate - conversion of entry to the certificate failed.

    Hello Steve,.

    Here is a step by step guide to import the SSL certificate. I hope this helps.

    http://sbkb.Cisco.com/CiscoSB/UKP.aspx?VW=1&docid=49843175a37149768dc4c331a05dce92_Edit_SSL_Server_Authentication_Settings_on_SG500x_Series_Sta.XML&PID=2&respid=0&SNID=3&DISPID=0&cpage=search

    Nana

  • Certificate SSL VPN

    Hi all

    I have configured the SSL vpn client and the client less ssl vpn, but I am not able to connect cisco vpn client softrware and also browser, because of certificate problem, can you please tell how to create the certificate SSL VPN

    Thanks and greetings

    Rajesh Gowda

    Sign up for a certificate from a public certification authority and use the FQDN to connect to the VPN. Then these warnings should not appear.

  • Client certificate SSL V3.0

    How can I connect to a web service that requires client certificates SSL V3.0 using CFMX?

    I am trying to use a client certificate to connect via CFHTTP a secure Web site and I'm getting a "403.7 - Forbidden: certificate customer required" error. I have correctly installed the Web site cert by following the instructions here:
    http://www.TalkingTree.com/blog/index.cfm?mode=entry & entry = 25AA75A4 - 45a 6-2844 - 7CA3EECD842D B576

    When I access the secure site using IE, I am asked to use the installed client certificate, and then I'm able to view the content secure without no 403 errors.

    After completing the research question, I read in this post that CFMX7.01 does not support the SSL V3.0 protocol:
    http://www.houseoffusion.com/cf_lists/message.cfm/forumid:4 / messageid:229870 / step: 0

    Did someone using client certificates SSL V3.0 with CFMX7.01? Is it a question of Adobe or java problem? Are there alternatives?

    CFX_HTTP5 worked great!

    I wish just called him 'good '. I asked the question about a popular mailing list and got absolutely no response. I also searched Google for a few hours and did not find anything. CFX_HTTP5 did the job and now I can finish what I started instead of saying my client I found a mission critical issue that ColdFusionMX couldn't do.

    Thanks again!

  • Peer SSL could not negotiate a set of acceptable security parameters. (Error code: ssl_error_handshake_failure_alert) How can this be repaired?

    I got this error message when you try to access a site with which I have a contract:
    The secure connection failed

    An error occurred during a connection to eoffer.gsa.gov.

    Peer SSL could not negotiate a set of acceptable security parameters.

    (Error code: ssl_error_handshake_failure_alert)

       *   The page you are trying to view can not be shown because the authenticity of the received data could not be verified.
    
       *   Please contact the web site owners to inform them of this problem. Alternatively, use the command found in the help menu to report this broken site.
    

    This can only really be corrected by the people who run the site. They have misconfigured web servers. Ask them to test in all modern browsers before deploying in the future.

  • Firefox Certificate Manager is not listed in the tab view certificate should be. I have instructions for a certificate that requires him to be selected.

    "Firefox Certificate Manager" is not indicated in the certificate of view selection in the encryption tab Instructions for the installation of a certificate of some say to select the Firefox Certificate Manager. But I just can't.

    This has happened

    Each time Firefox opened

    == I searched the tab

    You can click on the "view certificates" button to open the Firefox Certificate Manager.
    Tools > Options > advanced > encryption: Certificates > view certificates

  • How do I configure the iPad2 to synchronize the iPad-Mailclient with Exchange 2010 via Active Sync using the certificate SSL client and name of user and password?

    Active Sync iPad ssl Client certificate

    How do I configure the iPad2 to synchronize the iPad-Mailclient with Exchange 2010 via Active Sync using the certificate SSL client and name of user and password?

    Hi Ewoki,

    Your question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the TechNet Exchange forum. Please post your question in the Forums TechNet in Exchange Server.

  • Receive the error message "the server that you are connected using a security certificate that could not be verified that the certificate CN name does not match the passed value.

    Prob Winmail.

    Receive the error message "the server that you are connected using a security certificate that could not be verified that the certificate CN name does not match the passed value. Do you want to continue? ». This started happening after that my laptop has been reformatted. I have synced with Gmail winmail and followed the instructions to do this correctly. By pressing the tab 'Yes' allows me to use winmail, but it's a little embarrassing.

    Using a digital signature?  Check the settings under Tools | Options | Security and also tools | Accounts | Mail | Properties | Security.

    Also, see here (http://mail.google.com/support/bin/answer.py?hl=en&answer=86382) and make sure that your settings are correct.

    Steve

  • SSL protocol error.  Certificate is either not valid, or the common name or authority are not recognized. I have

    Hi, I have problems when I tried to open a PDF document with a font of RM generated in the Laundpad, I use a certificate with the common name self-signed ssl https://127.0.0.1:8443 and the URL in the basic configuration is the same. I tried to fix this for a week but I could, and I do not understand How to solve.

    If anyone can help me, please. It is the image when I try to open a PDF file with RM policies. Thank you

    acrobatReadder.jpg

    So the value CN should be without the ": 8443" Bill creating the cert file?

    Below: Ive installed and trusted certificate in personnel and the certification auth trusted root.

    At the opening of the URL: https://192.168.1.35:8443 / / / AdminUI in Firefox, I get the following error:

    @ IE, I get:

    Thanks for looking at this!

  • Adding Exception Certificate SSL in Firefox 4

    I recently installed Firefox 4 beta 11 and now can't access some Web pages provided by my University that use SSL encryption.

    The error message I get (in a pop-up box) is:

    evasys. Urz.Uni-halle.de uses an invalid security certificate.

    The certificate is not approved, because no sender string has been provided.

    (Error code: sec_error_unknown_issuer)

    It has been a known issue that somehow Firefox does not handle the issuer of the certificate chain correctly (this is what the it Department) and the solution so far was to add an exception for this site in Firefox 3.x.x

    It would be nice for me for Firefox 4, too, but I can't find a way to add this exception. As soon as I reject the error message box by clicking 'OK' nothing happens, don't "this connection is not approved" - page (http://support.mozilla.com/en-US/kb/This%20connection%20is%20untrusted#w_certificates-and-identification) is open or anything equivalent.

    Thanks in advance for any help.

    Nothing has changed about adding exceptions in Firefox 4 AFAIK.

    If you can not add an exception, but get a pop-up with the error message, you can go the pref browser.xul.error_pages.enabled on the topic: config page and make sure that the value is set to true (the default).

    You can retrieve the certificate and the control that has issued the certificate.

    • Click on the link at the bottom of the error page: "I understand the risks".

    Let Firefox recover the certificate: "Add Exception"-> "get certificate".

    • Click on the "view..." button. "to inspect the certificate and the Coachman, who is the sender.

    Only leave the brand in the box at the bottom to "permanently store this exception' If you trust this certificate.

    • Click on "Confirm the Security Exception" to enter the site if you still want to go to this site.
  • Error replace the certificate SSL - inventory services with using SSL - please help automation tools

    I uses updated SSL tools to change the SSL to vCenter 5.5 certificate.

    Modification of SINGLE authentication certificate has been successful, but I'm having a problem with the inventory services.

    Error message below.

    ==================================================================

    4 update the inventory Service SSL certificate

    1. update the confidence of the inventory of Single Sign-On Service

    2. update the Service of Trust inventory to vCenter Server

    3 update the inventory Service SSL certificate

    4. back to the old inventory SSL Certificate Service

    5. return to the main menu to update other services

    The service chosen is: 3

    [Wednesday 3 December, 2014 - 13:49:12.88]: services that are delivered to market as part of thi

    operation s are: vCenter Inventory Service.

    Enter the location of the new inventory channel Service SSL: C:\certs\InventorySer

    vice\chain.PEM

    Enter the location of the new private key for the inventory Service: C:\certs\InventoryS

    ervice\rui - orig.key

    Enter the SSO administrator user (default value is: administrator@vsp)

    here.local):

    Enter the SSO administrator password (not displayed):

    [.] The supplied certificate string is valid.

    [Wednesday 3 December, 2014 - 13:49:44.41]: last update of functioning inventory Service SSL cert

    ificatsanitai re has failed:

    [Wednesday 3 December, 2014 - 13:49:44.42]: unable to determine if the inventory Service is registe

    Red with Single Sign-On - errorlevel is 1

    =================================================================

    Problem solved, as the vCenter my share of the same SSO domain environment is necessaio that certificcado the backend SSL is changed.

  • Problem importing Certificate SSL in gateway desktop remotely

    Hello

    Windows 2008 R2

    Our SSL wildcard (by Go Daddy) certificate has expired, I have renewed, went into IIS, created a CSR, apply the CSR, downloaded the version of IIS of GoDaddy. completed CSR in IIS, applied the intermediate certificate, went into MMC and import the certificate into the local computer store.

    BUT... I have problems with the gateway Office remotely.  I can't import the cert generic it.  I'm in management gateway > properties > SSL certificate and take the option "Select an existing certificate" I see the generic cert, I select it and click on apply, it flashes away and then apply it is grayed out, so I click on OK, but says still no cert... status says I need a cert.  So it's like it is not recognizing the cert or is the kind of evil?

    Thought he could be authority, so I tried it with several different admin on the global domain IDs.

    I also went through MMC and imported the cert in the location of the remote office certificates, but who don't seem to have any impact.

    What I am doing wrong?

    Go Daddy suggests cert regeneration, but I don't want to do it again unless I need to.

    Any ideas?

    Thanks in advance!

    After much research, found this https://support.microsoft.com/en-us/kb/959120

    Changed the link for port 443 and it worked!

  • Conflict of Certificate SSL RV082 Cisco for ActiveSync

    I have a Cisco RV082 session before my exchange server. I have the port forwarding for 443 to my exchange server.

    My ActiveSync (iPhone, Droid) users get a connection error when HTTPS is enabled on the Firewall tab using the MS Connection Tester, it appears that the ActiveSync connection picks up the cert of Cisco, installed on the RV082 and not the cert I on the Exchange Server.

    If I turn off HTTPS then it all works.

    That would be fine except that I seem to need HTTPS to my VPN connection enabled to work.

    Help!

    I saw this question on RV0xx V3 devices. The devices are built with more security, but the device will always meet the demands of SSL certificates and not transfer the request even if the port forward is activated. Even when the port which is transferred 443 is not the router will always respond with its own SSL certificate. If you experience this kind of configuration problems. Please if you do not need ensure the management to distance, SSL VPN, or secure disable management LAN HTTPS under the firewall settings. If you need these parameters so please call in and create a case. More business with this number, we create the problem gets noticed and solved. There is no rejection of bug at this time for the same problem, I know. Please call Small Business Support Center at 1-866-606-1866. If the technician you speak with what is not aware of the problem please have a talk with me.

    Thank you

    Cisco Small Business Support Center

    Randy Manthey

    CCNA, CCNA - security

  • Problems installing certificates SSL on a RV325

    IM pretty new to this router interface and I need help to install my external certificates on my RV32x router.

    I created my CSR, it has provided to the authority of SSL.  Both my web certificate (X.509) and my intermediate CA was provided to me.   The router's request. PEM format certs, so I made sure that the format of certificates followed lines of anchor text (BEGIN CERTIFICATE and END CERTIFICATE).

    No matter what I do, any order, format, the combination of keys (X.509 and CA) intermediate - and I went so far as to reissue the certificates and start from the beginning.  I've recreated the CSR, had the power of SSL to send me new keys and tried again the steps (in case I missed something, Miss a step, or SOMETHING...). I even went out to HQ and got another case here, there was a problem there.

    I got errors where it is said that the "key Certification is not valid." "" Check the public key for the date and time... ", etc.  All seem like mistakes that don't relate to the action, I show.

    Someone at - he had that same experience and found a way through it?   I thought I was pretty knowledgeable in this area, but I'm guessing me!  :)  Any help would be greatly appreciated.   It shouldn't really be this difficult!

    Hi Scott,.

    Could you try it by following these steps:

    Before you measures make sure that you have a backup of your original file

    1. open ciscorouter.pem with Notepad + or PSpad.

    2. you can find there is a private key and three certificates in the file.

    3 copy the private key and the first certificate include the begin/end message.

    -----BEGIN PRIVATE KEY-----

    .

    .

    .

    -----END PRIVATE KEY-----

    -BEGIN CERTIFICATE-

    .

    .

    .

    -CERTIFICATE OF END-

    4. Paste the content in step 3 to a new file named Cer_plus_private.pem.

    5. make sure that there is two newlines in the end, then save it. [This is the workaround for]

    This problem].

    6 copy the certificate to the second and the third certificate include the begin/end message.

    -BEGIN CERTIFICATE-

    .

    .

    .

    -CERTIFICATE OF END-

    -BEGIN CERTIFICATE-

    .

    .

    .

    -CERTIFICATE OF END-

    7 paste the content in step 6 to a new file named CA.pem and save it.

    8 import CA.pem and Cer_plus_private.pem in RV32x.--> success.

    Kind regards

    Aditya

Maybe you are looking for