<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS 5.3 Certificate Request in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049484#M158405</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I could generate a certificate request with openssl on an separate linux box. &lt;/P&gt;&lt;P&gt;Then I think to import the signed certificate file I have to go to &lt;/P&gt;&lt;P&gt;System Administration &amp;gt;&amp;nbsp; ... &amp;gt;&amp;nbsp; Configuration &amp;gt;&amp;nbsp; Local Server Certificates &amp;gt;&amp;nbsp; Local Certificates&amp;nbsp; &amp;gt;&amp;nbsp; Create &amp;gt; Bind CA Signed Certificate... , right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But where I can import the private key ?&lt;/P&gt;&lt;P&gt;As far as I understand by using the GUI the private key is created and later bound automatically to the signed cert but it is not directly accessible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Sep 2012 13:18:29 GMT</pubDate>
    <dc:creator>Mike Lehmann</dc:creator>
    <dc:date>2012-09-24T13:18:29Z</dc:date>
    <item>
      <title>Cisco ACS 5.3 Certificate Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049482#M158403</link>
      <description>&lt;P&gt;I try to generate a certificate request in Cisco ACS 5.3 Web GUI via &lt;/P&gt;&lt;P&gt;System Administration &amp;gt;&amp;nbsp; Configuration &amp;gt;&amp;nbsp; Local Server Certificates &amp;gt;&amp;nbsp; Local Certificates &amp;gt; Add &amp;gt; Generate Certificate Signing Request .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DN we have to use is specified by our CA-Administrator to something like &lt;/P&gt;&lt;P&gt;"O=my-company-for IT Service (mcIT),L=Berlin,ST=Berlin,C=DE" .&lt;/P&gt;&lt;P&gt;(spaces, brackets, ... but this is the requirement)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my input in the field Certificate Subject is "CN= myserver.mcit.com,O=my-company-for IT Service (mcIT),L=Berlin,ST=Berlin,C=DE" .&lt;/P&gt;&lt;P&gt;(Key Length=2048, Digest=SHA1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But then I get an error: Certificate Validation Error: "Invalid certificate subject DN name"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I omit ST attribute it creates a request, but due to CA requirements I cannot.&lt;/P&gt;&lt;P&gt;The length of DN is 101.&lt;/P&gt;&lt;P&gt;Event without round brackets "(..)" the error occurs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049482#M158403</guid>
      <dc:creator>Mike Lehmann</dc:creator>
      <dc:date>2019-03-11T02:34:56Z</dc:date>
    </item>
    <item>
      <title>Re:Cisco ACS 5.3 Certificate Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049483#M158404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your best bet is to use openssl to generate a CSR. Once you receive the signed cert import the cert and the intermediate and root certs along with the private key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need help with that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049483#M158404</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-24T13:10:01Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 Certificate Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049484#M158405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I could generate a certificate request with openssl on an separate linux box. &lt;/P&gt;&lt;P&gt;Then I think to import the signed certificate file I have to go to &lt;/P&gt;&lt;P&gt;System Administration &amp;gt;&amp;nbsp; ... &amp;gt;&amp;nbsp; Configuration &amp;gt;&amp;nbsp; Local Server Certificates &amp;gt;&amp;nbsp; Local Certificates&amp;nbsp; &amp;gt;&amp;nbsp; Create &amp;gt; Bind CA Signed Certificate... , right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But where I can import the private key ?&lt;/P&gt;&lt;P&gt;As far as I understand by using the GUI the private key is created and later bound automatically to the signed cert but it is not directly accessible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049484#M158405</guid>
      <dc:creator>Mike Lehmann</dc:creator>
      <dc:date>2012-09-24T13:18:29Z</dc:date>
    </item>
    <item>
      <title>Re:Cisco ACS 5.3 Certificate Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049485#M158406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will have to import the certificate. It will ask for the private key and private key password along with the cert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:40:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049485#M158406</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-24T13:40:04Z</dc:date>
    </item>
    <item>
      <title>Re:Cisco ACS 5.3 Certificate Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049486#M158407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;It's not bind CA certificate . It's the first option which is import seever certificate option&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 20:56:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049486#M158407</guid>
      <dc:creator>hkhrais</dc:creator>
      <dc:date>2012-09-24T20:56:38Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 Certificate Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049487#M158408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately it's not working.&lt;/P&gt;&lt;P&gt;I created a certificate (request and private key) on a linux box with openssl and sent the cert to our CA for signing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I tried to import the signed cert with &lt;/P&gt;&lt;P&gt;System Administration &amp;gt;&amp;nbsp; ... &amp;gt;&amp;nbsp; Configuration &amp;gt;&amp;nbsp; Local Server Certificates &amp;gt;&amp;nbsp; Local Certificates&amp;nbsp; &amp;gt;&amp;nbsp; Create &amp;gt; Import Server Certificate, with my cert.pem and privkey.pem files and the password from request generation.&lt;/P&gt;&lt;P&gt;I get an error "Certification Validation Error: Invalid private key"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Request generation with the GUI wasn't possible - I suspect the ST attribute (without it is possible). &lt;/P&gt;&lt;P&gt;As already mentioned our CA requires a DN like "O=my-company-for IT Service (mcIT),L=Berlin,ST=Berlin,C=DE" &lt;/P&gt;&lt;P&gt;ST is mandatory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody an idea to solve this crux?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;ML&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2012 07:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049487#M158408</guid>
      <dc:creator>Mike Lehmann</dc:creator>
      <dc:date>2012-09-26T07:15:12Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 Certificate Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049488#M158409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same problem, have you solved it ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 08:53:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049488#M158409</guid>
      <dc:creator>Ossama El Abbadi</dc:creator>
      <dc:date>2013-01-17T08:53:39Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 Certificate Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049489#M158410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using "S=" instead of "ST=" worked for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b.r.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 12:58:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-certificate-request/m-p/2049489#M158410</guid>
      <dc:creator>Mike Lehmann</dc:creator>
      <dc:date>2013-01-17T12:58:16Z</dc:date>
    </item>
  </channel>
</rss>

