<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSLM: Configuring multi-tier certificates issues in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/5373596#M51586</link>
    <description>&lt;P&gt;It looks like your multi-tier setup is mostly correct, but the error usually points to a mismatch between the intermediate cert and the trustpoint configuration or the enrollment method. Double-check that the intermediate cert matches the exact subject and issuer expected by the DIRECTORY-Intermediate trustpoint. Step-by-step guides for similar SSL module multi-tier setups have been shared and recommended on &lt;A href="https://alostoratv.app/" target="_self"&gt;https://alostoratv.app/&lt;/A&gt; , which could help clarify the proper ordering and authentication procedure.&lt;/P&gt;</description>
    <pubDate>Sun, 01 Mar 2026 10:55:53 GMT</pubDate>
    <dc:creator>merigens63</dc:creator>
    <dc:date>2026-03-01T10:55:53Z</dc:date>
    <item>
      <title>SSLM: Configuring multi-tier certificates issues</title>
      <link>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501807#M30917</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wanted to know what was the preferred or Cisco accepted way to install / configure multi-tier certificates on the SSL module?&amp;nbsp; When reading the config guide, it discusses in detail how to handle a single tier cert (i.e just a root ca cert), however there is no real example for handling multi-tier certs (i.e. a root ca cert and an intermediate cert)..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an example, we've always installed a multi tier cert the following way:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Setup the main trustpoint which contains the subject name&lt;/P&gt;&lt;P&gt;crypto pki trustpoint DIRECTORY&lt;BR /&gt;&amp;nbsp; enrollment terminal&lt;BR /&gt;&amp;nbsp; fqdn directory.monash.edu.au&lt;BR /&gt;&amp;nbsp; subject-name C=AU, ST=Victoria, L=Clayton, O=Monash University, OU=ITS, CN=directory.monash.edu.au&lt;BR /&gt;&amp;nbsp; revocation-check none&lt;BR /&gt;&amp;nbsp; rsakeypair DIRECTORY&lt;BR /&gt; !&lt;/P&gt;&lt;P&gt;! Setup a trustpoint for the Root certificate&lt;BR /&gt; crypto pki trustpoint DIRECTORY-Root&lt;BR /&gt;&amp;nbsp; enrollment terminal pem&lt;BR /&gt;&amp;nbsp; revocation-check none&lt;BR /&gt;&amp;nbsp; crl optional&lt;BR /&gt; !&lt;BR /&gt; ! Setup a trustpoint for the Intermediate certificate&lt;BR /&gt; crypto pki trustpoint DIRECTORY-Intermediate&lt;BR /&gt;&amp;nbsp; enrollment terminal&lt;BR /&gt;&amp;nbsp; revocation-check none&lt;BR /&gt;&amp;nbsp; crl optional&lt;BR /&gt; !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Enroll the trustpoint DIRECTORY for the CSR&lt;/P&gt;&lt;P&gt;! Obtain signed cert from CA (Thawte)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Authenticate DIRECTORY-Intermediate using the intermediate cert&lt;/P&gt;&lt;P&gt;crypto pki authenticate DIRECTORY-Intermediate&lt;/P&gt;&lt;P&gt;&amp;lt;paste intermediate cert&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Authenticate DIRECTORY-Root using the root cert&lt;/P&gt;&lt;P&gt;crypto pki authenticate HYBRID-Root&lt;/P&gt;&lt;P&gt;&amp;lt;paste root cert&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Authenticate DIRECTORY using the root cert&lt;/P&gt;&lt;P&gt;crypto pki authenticate DIRECTORY&lt;/P&gt;&lt;P&gt;&amp;lt;paste root cert&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Import signed cert against DIRECTORY&lt;/P&gt;&lt;P&gt;crypto pki import DIRECTORY cert&lt;/P&gt;&lt;P&gt;&amp;lt;paste signed cert&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has always worked fine, until recently we've noticed on one of our SSL modules, that we get the following error when authenticating the intermediate cert against DIRECTORY-Intermediate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Trustpoint 'DIRECTORY-Intermediate' is a subordinate CA.&lt;BR /&gt; Authentication failed - could not validate certificate% Error in saving certificate: status = FAIL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence i can't continue to install the rest of the chain.&amp;nbsp; Am going to chase this up via TAC, however i wanted to post this here just to know whether there is anything that immediately sticks out to people, as far as the procedure we follow or anything else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Sheldon&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2010 02:08:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501807#M30917</guid>
      <dc:creator>sgonsalv</dc:creator>
      <dc:date>2010-08-18T02:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSLM: Configuring multi-tier certificates issues</title>
      <link>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501808#M30918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sheldon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if you've seen this document but it covers an example of installing a multi-tiered&lt;/P&gt;&lt;P&gt;cert install on the SSLM:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a008037d1c8.shtml"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a008037d1c8.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe go through this step-by-step and if you run into any problems then open&lt;/P&gt;&lt;P&gt;a TAC case for assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;-Chip&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 22:42:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501808#M30918</guid>
      <dc:creator>cschneid</dc:creator>
      <dc:date>2010-08-20T22:42:51Z</dc:date>
    </item>
    <item>
      <title>SSLM: Configuring multi-tier certificates issues</title>
      <link>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501809#M30919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Sheldon, if you forget "revocation-check none" within the root trustpoint the validation failed even the root Cert is valid. In debug (for IOS PKI) crypto pki validation you can see &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct&amp;nbsp; 4 07:35:13.496: CRYPTO_PKI: Checking certificate revocation&lt;BR /&gt;Oct&amp;nbsp; 4 07:35:13.496: CRYPTO_PKI: Matching CRL not found&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the validation failed with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication failed - could not validate certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;br Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 07:42:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501809#M30919</guid>
      <dc:creator>mjuch</dc:creator>
      <dc:date>2012-10-04T07:42:51Z</dc:date>
    </item>
    <item>
      <title>SSLM: Configuring multi-tier certificates issues</title>
      <link>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501810#M30920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Sridhar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found this link which explains &lt;/P&gt;&lt;P&gt;" &lt;SPAN style="font-size: 10pt;"&gt;Authenticating the Three Certificate Authorities (One Root And Two Subordinate Certificate Authorities)":&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ssl/2.1/configuration/guide/config.html#wp1201447"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ssl/2.1/configuration/guide/config.html#wp1201447&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;is this what you were looking for ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Rajesh.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 11:38:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501810#M30920</guid>
      <dc:creator>rajsures</dc:creator>
      <dc:date>2013-10-22T11:38:42Z</dc:date>
    </item>
    <item>
      <title>SSLM: Configuring multi-tier certificates issues</title>
      <link>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501811#M30921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the link Suresh, the section "&lt;/P&gt;&lt;P&gt;Example of Importing PEM Files for Three Levels of Certificate Authority" does cover the mulitiple CA installation, but when I followed this, I did root CA installation, the cert got authenticated. I created trustpoint for first intermediate CA and then tried authenticating it threw me an error saying this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt;Trustpoint "XXXXXXXX' is a subordinate CA.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Authentication failed - could not validate certificate% Error in saving certificate: status = FAIL&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;I have masked trustpoint name with XXX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Still not understanding how to authenticate the CAs including the root.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Sridhar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 15:23:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/1501811#M30921</guid>
      <dc:creator>sridharlatcw</dc:creator>
      <dc:date>2013-10-25T15:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSLM: Configuring multi-tier certificates issues</title>
      <link>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/5318740#M51534</link>
      <description>&lt;P&gt;It is &lt;STRONG&gt;very important the order&lt;/STRONG&gt; of &lt;STRONG&gt;Chain cert&lt;/STRONG&gt;&amp;nbsp; (RootCA-&amp;gt;SubCA-&amp;gt;Cert):&lt;/P&gt;
&lt;P&gt;crypto pki authenticate DNAC-CA&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;&lt;STRONG&gt;RootCA&lt;/STRONG&gt;&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;&lt;STRONG&gt;SubCA&lt;/STRONG&gt;&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;&lt;STRONG&gt;Cert&lt;/STRONG&gt;&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;quit&lt;/P&gt;
&lt;P&gt;Certificate has the following attributes:&lt;BR /&gt;Fingerprint MD5: "omitted"&lt;BR /&gt;Fingerprint SHA1: "omitted"&lt;/P&gt;
&lt;P&gt;% Do you accept this certificate? [yes/no]: &lt;STRONG&gt;yes&lt;/STRONG&gt;&lt;BR /&gt;Trustpoint CA certificate accepted.&lt;BR /&gt;% Certificate successfully imported&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 05:55:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/5318740#M51534</guid>
      <dc:creator>marinogr</dc:creator>
      <dc:date>2025-08-08T05:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSLM: Configuring multi-tier certificates issues</title>
      <link>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/5350941#M51555</link>
      <description>&lt;P&gt;That’s a solid walkthrough of multi-tier certs! While you troubleshoot the SSL module, I’ve been exploring some secure setups and testing features over at &lt;A href="https://golo777.com.pk/" target="_self"&gt;Golo777&lt;/A&gt; their platform handles certificates and secure connections really smoothly.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Nov 2025 12:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/5350941#M51555</guid>
      <dc:creator>jackjame6es</dc:creator>
      <dc:date>2025-11-30T12:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSLM: Configuring multi-tier certificates issues</title>
      <link>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/5373596#M51586</link>
      <description>&lt;P&gt;It looks like your multi-tier setup is mostly correct, but the error usually points to a mismatch between the intermediate cert and the trustpoint configuration or the enrollment method. Double-check that the intermediate cert matches the exact subject and issuer expected by the DIRECTORY-Intermediate trustpoint. Step-by-step guides for similar SSL module multi-tier setups have been shared and recommended on &lt;A href="https://alostoratv.app/" target="_self"&gt;https://alostoratv.app/&lt;/A&gt; , which could help clarify the proper ordering and authentication procedure.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2026 10:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sslm-configuring-multi-tier-certificates-issues/m-p/5373596#M51586</guid>
      <dc:creator>merigens63</dc:creator>
      <dc:date>2026-03-01T10:55:53Z</dc:date>
    </item>
  </channel>
</rss>

