Could not import the Wildcard on SAA certificate

Hi all

I'm trying to implement a GoDaddy Wildcard (*. mydomain.mytld) cert for a number of clubs, among which there is our ASA. I put away the old certs and did some housekeeping on their trustpoints, etc., with the result pretty much own config. (I'm on 8.3).

I needed to register for the cert in a different area (Exchange 2010) and I exported the cert in cisco-pasteable format REB to make it ready for deployment ahead on the ASA. Here's what I've done (with cry ca debugging on), causing a failure to import the wildcard certificate. Can anyone shed light on what I'm doing wrong? What I was doing was essentially installation TP for root and intermediate and then import the actual device cert.

The installation program two trustpoints for RootCA and intermediate TP:

gate0 (config) # crypto ca trustpoint gdroot
gate0(config-ca-Trustpoint) # Terminal registration
gate0(config-ca-Trustpoint) # revo no
---------

gate0 (config) # crypto ca trustpoint gdinter
gate0(config-ca-Trustpoint) # register terminal
domain name full mydomain.tld gate0(config-ca-Trustpoint) #.

----------------

These authenticate:

authenticate the cry ca gate0 (config) # gdroot
Enter the base-64 encoded certificate authority.
End with the word "quit" on a line by itself
-BEGIN CERTIFICATE-

-CERTIFICATE OF END-
quit smoking

INFO: Certificate has the following attributes:
Fingerprints: [snip]
Do you accept this certificate? [Yes/No]: Yes

Certificate of the CA Trustpoint accepted.

% Certificate imported successfully
CRYPTO_PKI: Recording of Cert not found, return E_NOT_FOUND
View the contents of the current certificate:
1 certificate:
SERIES: 00
ISSUER: OU = Go Daddy class 2 Certification Authority, o = Go Daddy Group\, Inc., c = US
CRYPTO_PKI: crypto_process_ra_certs (trust_point = gdroot)

authenticate the cry ca gate0 (config) # gdinter
Enter the base-64 encoded certificate authority.
End with the word "quit" on a line by itself
-BEGIN CERTIFICATE-
-CERTIFICATE OF END-
quit smoking

INFO: Certificate has the following attributes:
Fingerprints: [snip]
Do you accept this certificate? [Yes/No]: Yes

Trustpoint "gdinter" is a subordinate certification authority and is a non self-signed certificate.

Certificate of the CA Trustpoint accepted.

% Certificate imported successfully
gate0 (config) # CRYPTO_PKI: Cert record not found, return E_NOT_FOUND
CRYPTO_PKI: No appropriate trustpoints not found to validate the serial number of certificate: 0301, object name: serialNumber = 07969287, cn = Go Daddy Secure Certification Authority, or =http://certificates.godaddy.com/repository, o is GoDaddy.com------, Inc., l is Scottsdale, st = Arizona, c = US, name of the issuer: OU = Go Daddy class 2 Certification Authority, o = Go Daddy Group\, Inc., c = US.

CRYPTO_PKI: Recording of Cert not found, return E_NOT_FOUND
View the contents of the current certificate:
1 certificate:
SERIES: 0301
ISSUER: OU = Go Daddy class 2 Certification Authority, o = Go Daddy Group\, Inc., c = US
Certificate 2:
SERIES: 00
ISSUER: OU = Go Daddy class 2 Certification Authority, o = Go Daddy Group\, Inc., c = US
CRYPTO_PKI: crypto_process_ra_certs (trust_point = gdinter)

Import the "peripheral": wildcard cert

Crypto ca import gdinter RECs
ATTENTION: Registration certificate is configured with a complete domain name
that differs from the fqdn of the system. If this certificate will be
used for VPN authentication, this can cause connection problems.

You want to continue with this registration? [Yes/No]: Yes

% The FQDN in the certificate name will be: mydomain.tld

Enter the base 64 encoded certificate.
End with the word "quit" on a line by itself

-BEGIN CERTIFICATE-
-CERTIFICATE OF END-
quit smoking

ERROR: Cannot analyse or check the imported certificate
CRYPTO_PKI: cannot define ca cert object (0 x 722)
CRYPTO_PKI: status = 65535: could not get the key of the cert usage

You can see a problem due to not have generated the CSR on the SAA (with ASA's private key) because you use a character generic cert.

There is a here document which explains how to get around that.

Tags: Cisco Security

Similar Questions

  • Could not import the music downloaded from iTunes for Windows Movie Maker.

    Could not import the music downloaded from iTunes for Windows Movie Maker.  He plays in Windows Live Movie Maker and plays on my computer.  Cannot find the codec. Tried the solution to this same question and in help.

    Hello
     
    Some audio and video file formats are not supported in Windows Movie Maker and cannot be imported. However, if you have a video or audio file that is not taken care of, you can use a non-Microsoft video editing software to convert the file into a format supported by Windows Movie Maker, and then import the video file or an audio resulting in Windows Movie Maker. Some files also require you to install a codec before you can use the files in Windows Movie Maker.
    Note: The use of third-party software, including hardware drivers can cause serious problems that may prevent your computer from starting properly. Microsoft cannot guarantee that problems resulting from the use of third-party software can be solved. Software using third party is at your own risk.
     
    Import video, photos and audio on Windows Movie Maker
    A problem of importing files into Windows Movie Maker
     
    Windows Movie Maker uses. WAV file formats and Apple's iTunes use it. AAC format.
    You can also try saving iTunes songs in the. WAV format instead of Mp3 format and check.
    For more information, see the link:
    Hope this information is useful.
  • Could not import the RAW with LR4

    I have done the trial LR4... before LR3 and 1.  Could not import raw with 4 files.  MSG comes up saying, "After files were imported not because they cannot be read."  The reason I try it is because Canon 5 d Mk III and I was told HAD to get it for the treatment of the raw with this device.  Fine imports by iphoto.  I must admit, though, as a dunce, this morning, I put in a new CF card and forgot to format... but I don't think it's because I tried a few weeks previously and had same problem with a card which has BEEN formatted.  I had with iphoto, but they import them in a file on my desktop and then import from the desktop.  Tried this time, but the import column does not appear same office option.  And when I try the end of iphoto, and it arrives at its destination, I'm going under applications, and Adobe photoshop LR 4 is grey so I can't click on it to send pictures... Help!  (PLEEEZZZ!)  Thank you!

    Oh, BTW, I downloaded DNG Converter, but have no idea how it works, don't see a help file with it, and Yes, the version of LR 4 I'm trying is 4.3.

    King Tut mummy

    Post edited by: mother of King Tut\

    Quote 'Suite of files were not imported because they cannot be read.

    Make sure you have all the permissions read and write for all locations that you are trying to import the files. (for example if you try to import/copy files to a drive/folder where you have only read access, you will get this message) I think you see this message it is because before LR can read files is they must first be written/copied to the destination.

    Make sure you have full read/write access to all drives/folders, you work with.

  • Could not import the certificate - you can solve it here

    Hi all

    seems that I'm having a similar problem:

    Re: Error - failed to import the certificate - you can fix this here

    My gap phone signature keys worked a few months - now my key says iOS:

    "Error - failed to import the certificate - you can fix this here" when I Isaiah to compile app

    I find this part a bit confused so please use no baby...

    -I went to https://developer.apple.com/account/ios/certificate/distribution

    and it looks like my prod. CERT and mobile profile available are both still active

    -J' tried to re - download these that have been saved on my computer when I them - go back to the generation gap phone - and he accepted them with my pass

    - then I opened a new I just did-, but has the same problem when I try to build a production application = "error - failed to import the certificate - you can fix that here."

    Q: what should I do to fix this?

    R: remove the CERT in my keychain and their construction everything again from scratch?

    B: should I remove the ACTIVE apple certs and profile mobile available?

    C: something simpler to solve this problem?

    Thanks in advance - Dave

    Should be fixed now.  It seems that you have found a server in our collection that was generations before it was supplied.  Sorry for the inconvenience.

  • Could not import the Reader Extensions certificate

    I use the virtual appliance to assess LiveCycle and I can't import the certificate of Reader Extensions.  I'm sailing Trust Store Management > certificates, type an Alias, go to the trial .pfx file I downloaded and click Import.  Then a message pops up saying "invalid certificate".  Any ideas on what is the problem?

    The credentials of Reader Extensions are a .pfx file (with a file containing the credentials password .txt accompaniment).  Check signing authorities document can be .cer then please make sure that in the section "Type of trust store", the 'Reader Extensions Credential' box is checked before you import it.

    You are trying to import settings-> Trust Store Management-> local credentials right?

  • Could not import the 5S for macbook pro

    Since the last update of my 5s, two days ago I can no longer import pictures for macbook pro.

    "Pictures in the film"the ___ iphone cannot be imported because the device is locked with a password"but it is not."  Can and would someone please help. "Thanks I also:" iTunes could not connect to the iphone '-iPhone "because an invalid response was received from the device.

    On the phone, try pressing these buttons at the same time for at least ten seconds, until the Apple logo appear: the sleep/wake button and the Home button. On Mac, it just reboot and then try again.

  • Could not import the .fla files

    Good evening friends,

    I can't import the files flash adobe flash professional cs6. The message I get is:

    "One or more files could not be imported because the problem occurred during the import"

    I need quick help.

    Thank you in advance.

    Ersin

    Fortunately, that said asymmetric is not correct, as well not be what you were asking about.

    You can open any FLA of CS5.5 or later, in any version, CS5.5, or later. At this time they did the files be future-proof. New feature does not work and could lead to problems, but the file should open ok.

    But back to what you asked, you would never import a FLA, then don't means you that you try to import a SWF file? They are sovereign, there's a number of Flash Pro version where the ability to import SWF has been removed. Not sure if including CS6. Nowadays you can import SWF files, but you wouldn't get the ActionScript code.

    If the SWF file is set to be protected, then that would also lead to errors. You are much better if you can find the original Florida

  • Could not import the XT10 (RAF) RAW files in Lightroom 5.7.1

    To the right,.


    I recently purchased Fuji XT10 camera (released in may 2015), after the shooting in RAW for a reason that the RAF files could not be imported to Lightroom 5. I updated my Lightroom 5 to the more up-to-date version 5.7.1. but still will not change a thing. I am reluctant to convert to DNG because Internet said RAF files retain better details/data to DNG.

    Someone will have a solution to this please, or if someone has the same problem?

    Thank you very much for your help!


    All the best,


    Josh

    Hello

    This camera (X-T-10, correct me if wrong) requires 6.1 Lightroom and Camera raw 9.1 devices supported by Camera Raw

    Please proceed to Lightroom 6 or DNG Converter allows you to convert your images to DNG

    Concerning

    ~ Assani

  • Could not import the Clipboard because an unexpected end of file was encountered.

    This one is particularly annoying.  I use Creative Suite 2, Photoshop

    with Windows XP Pro.  I have the latest updates.

    When I open Photoshop, I constantly have the message "couldn't".

    import the Clipboard being an unexpected end of file

    met. "I hit [OK] and the message reappears in about 5 sec.

    I ran so much Photoshop as the first point of access on the computer (front for)

    all that is in the Clipboard) and I manually deleted the

    Clipboard.

    I have also reinstalled the CS2.

    Help, please...

    Operating instructions that can help you:

    (1) open Photoshop.

    (2) hold down 'Alt', 'Control' and 'Shift' at the same time as the launch of the program.

    (3) select the option to remove all of the current settings. All preferences and settings that you have changed will be returned to their default initial value.

    (4) close all applications and access your Photoshop plug-in folder. The location of this will depend on the version of Windows you are using. If you use a 32-bit edition, you'll find to "C:/Program Files/Adobe/Adobe Photoshop CS5 or CS4/Plug-Ins. If you use a 64-bit edition, you'll find in "C:/Program Files (x 86) / Adobe/Adobe Photoshop CS5 CS4/Plug-Ins or" or "C:/Program Files/Adobe/Adobe Photoshop CS5 or CS4/Plug-Ins.

    (5) select plug-ins not published by Adobe and follow the instructions to remove.

    (6) visit the Photoshop update page to find and apply updates for the version you are using.

    (7) relaunch Photoshop and try it.

    As alternatives could be presented...

    the http://www.filerepairforum.com/forum/adobe/adobe-aa/photoshop/1486-error-message-in-psd-fi - ask questions and read the various cases of corruption of file .psd

    https://www.repairtoolbox.com/photoshoprepair.html Photoshop repair kit - one of the tools provided restoration of .psd files corrupt

  • Could not import the platform of error

    Hello

    I started the 3.1.0 agent HQ (the version with the included JRE) on a RedHat Linux 9 server and runs the automatic detection of the console of the server process. He discovered the new server as it should, but when I clicked on the button "Add to inventory", I got an error (see below).

    Impossible to import the platform: RuntimeException. nested exception is: org.hyperic.hq.common.SystemException: javax.ejb.TransactionRolledbackLocalException: error creating data IA platform: servers of type "FileServer" could not be created on the "Home network" type platforms CausedByException is: creation of data IA platform error: type servers 'FileServer' cannot be created on platforms of type "home network".

    Why is this happening?

    Thank you
    Brian

    I think there may be a misunderstanding here.  When you say that you "ran the autodiscovery process", which means exactly?  You shouldn't have to do anything else that start the agent on the platform, and then set up your dashboard HQ.  The platform will appear in the queue of the self-inventory and you can then import the platform and all discovered resources.  This type platform sounds like it should be "Solaris" and not "network host.  HQ thinks that it is a network host, leads me to believe that you tried to create a platform manually instead of using the discovery platform created to start the agent.

    Try the following steps:
    1 stop the agent on the affected platform.
    2. remove any resource platform linked to this inventory of HQ
    3. delete the "data" of the installation of the Agent HQ directory
    4. start the Agent from HQ (you will need to provide the login information from server again)
    5. connect to Headquarters as the superuser and look in the auto - inventory of your dashboard portlet.  The platform should appear there.
    6. Select the platform and click on the button to import it into your inventory HQ

    It should work, if not answered and I will work with you to get your server.log and agent.log and troubleshoot more.

  • Could not import the Photoshop PSD

    It's weird. Try to import a PSD file. Message body cs6 error is "we were unable to open the file on the disk."

    The file is a fixed image that came to me as a JPG. I've read it in Photoshop cs6, cropped it, because the canvas 1920 x 1080 (to match the size of the sequence of the organism), tinkered and ended by running the action of course broadcast on this subject Luminance. Then I saved it in the body as a project folder *. PSD file. As I did hundreds of times now with dozens of projects.

    Attends agency cs6. Find the file using media browser. File... Import media browser gives me a window with the error message "We cannot open the file on the disk." Preview the Source monitor fails.

    What makes this even more frustrating, it is that the organization can find and open the file that I worked on just before this one. Same conditions, same process, same repertoire, same protections on files (I checked that). Two files seem to be exactly the same except for the file name and the content of the file. Everything else is also identical to that I can do. And none of my hard drives are even half full, so it shouldn't be a question of space.

    So if the organization can read one, why can't he read the other? And what I can do to get the Organization to behave correctly and read the file? Files do not appear to be corrupt - Photoshop can read them both very well. In any case, I've recreated the problem from the source repeatedly *.jpg file now so I think I can exclude from Photoshop file corruption on. Perhaps.

    I ruined my brain for 90 minutes trying to understand what has changed between the first file that works and one that doesn't. I came up empty. I worked on one, then the other, then imported the first on body (which worked), and then imported from the other in the body (which failed). Exact same source (both files were attachments on e-mail even *.jpg), same workflow, saved in the same directory. ARGHHHH!

    I did most of the 'usual suspects '. I left off Photoshop both body and restarted. I saved the file problem in other formats (same error no matter what format). So, I turned to Teh Google, that does not turn a large part that relates. Could not find anything in the Adobe Help documentation. So everyone here tell me what is happening?

    --

    Bruce Watson

    Few things to check - is the color of the RGB PSD Mode. It cannot be CMYK, or some other.

    I had problems with dynamic objects, because sometimes, they import all right, but not always.

    Layers of tiny (a few pixels x pixels) were causing problems.

    Adjustment layers have been known to cause problems.

    Normal layers, so long not tiny, always worked perfectly for me.

    Anything else that comes to my mind, but good luck.

    Hunt

  • Could not import the DataProvider

    If I open a new file in Flash (AS3) in Flash CS3 Professional and try to import the DataProvider (import fl.data.DataProvider;), I consistantly receive a compile error (1172: definition fl.data:DataProvider could not be found). Does anyone know what is the problem?

    Definitions of components AS3 source, by default, not are not in the
    classpath of your Florida they are available in the
    \Configuration\Component Source\ActionScript 3.0
    folder of your Flash CS3 installation directory, however the components
    themselves rely on versions precompiled classes in the so-called
    as the ComponentShim. These assets are in your library, when you add
    a component in your library or the screen to the Panel components. His
    Located within the component assets > _private folder. Without this asset
    in your library, you will not have access to the component classes. What if
    you want to refer to a component dynamically, it will have to be added to
    your library before you publish your SWF file. The ComponentShim contains only
    the kernel LIKE classes, not the real components that rely also on the other
    graphics and movie clips that should be in your library before a
    components can be used in your SWF file

    "PalacaJoe" wrote in message
    News:f2a9m7$LKM$1@forums. Macromedia.com...
    > If I open a new file in Flash (AS3) in Flash CS3 Professional and try to
    > Import
    > DataProvider (import fl.data.DataProvider;), I invariably receive a
    > compiler
    > error (1172: definition fl.data:DataProvider could not be found). Does
    > someone at - it
    > know what's the problem?
    >

  • Could not import the bookmarks file large

    I recently bought another computer on Windows. I installed Firefox and tried to import my bookmarks (html) file. I could only import files into my favorites and nothing else. Then I open my file of bookmarks in Firefox and bookmarks I want are still there. The bookmarks file is 15.8 mb in size. Do I need to split this file and, if so, how could I do?

    Thank you!

    If you still have the old computer, you can try backup .json (using the backup instead of export). With the new system, restore the .json file.

  • Could not import the mp4 (not corrpution) files in pictures

    When I try to import the mp4 files captured with a Samsung Galaxy S2 in pictures, I get the error: "None of these files can be imported into your photo library.". But I can import screenshots of mp4 files with a Huawei Mate 7 in pictures (and two phones jpg files). None of the files are corrupt, I can play them perfectly with any player capable of mp4. I run the latest versions of Photos and El Capitan.

    Any idea what the problem could be the announcement how to solve?

    Thank you very much

    lotlorien

    Hello

    This remains true to the 2016-05-12 with OS X 10.11.4 and photographs. 1,5.

    Anyone any idea how to solve this problem? Perhaps there is a simple way of editing .mp4 files and they I can import them?

    Thank you

    lotlorien

  • Could not import the DLL

    Hi all

    I am using the libsie API to open files .sie of SoMat (there is only a plugin for this data format for LabVIEW and tiara, but it does not work). I have previously imported from the dll using the wizard import with great success, but I don't ' know my way around c or c ++ so am a little confused on this one. When I try to import the attached dll (you will need to display the extension of .doc to .dll) by using the attached header file appear no calls. They are there in the header file. I wonder why that is. This is a header for the evil formattted file or is there another question?

    I have attached a copy of the zip file that I downloaded on the HBM website. There is a demo .sie in this file if you want to watch. It seems to be a fairly complete documentation on the API Web site.

    Any help or pointers gratefully received.

    Phil

    It doesn't matter what language was used to create the DLL, as long as it exports a C compatible (which does).

    If you make a copy of the header file and delete SIE_DECLARE(), leaving everything inside the brackets unchanged, of each function declaration, I think that you will be able to import at least some of the functions. I don't know how well the import utility will handle the pointer data types, you may need to modify each node in library function call to set manually after the import.

Maybe you are looking for