<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: error message when trying to enroll a certificate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/error-message-when-trying-to-enroll-a-certificate/m-p/170151#M436354</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Once you have generated a CSR, did you submit it to a certificate authority (CA Server) to receive your certificate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is the steps of how I install my cert:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Generate Certificate Signing Request:&lt;/P&gt;&lt;P&gt;     Certificate subject - "cn=ACS"&lt;/P&gt;&lt;P&gt;     Private key file - "c:\Cert\ACScert"&lt;/P&gt;&lt;P&gt;     Private key password - "acskey"&lt;/P&gt;&lt;P&gt;     Retype private key password - "acskey"&lt;/P&gt;&lt;P&gt;     Key length - "1024 bits"&lt;/P&gt;&lt;P&gt;     Digest to sign with - "SHA1"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Now a certificate signing request is ready. You can copy/paste it to any&lt;/P&gt;&lt;P&gt;     certification authority enrollment tool (CA Server).&lt;/P&gt;&lt;P&gt;3) After you have enrolled the above certificate with a CA Server, the CA Server&lt;/P&gt;&lt;P&gt;     will return a certificate to you, stored the returned certicate to "c:\Cert"&lt;/P&gt;&lt;P&gt;4) On your ACS, go to "System Configuration" -&amp;gt; "Install ACS Certificate"&lt;/P&gt;&lt;P&gt;5) Select "Use certificate from storage":&lt;/P&gt;&lt;P&gt;     Certificate CN - "ACS"&lt;/P&gt;&lt;P&gt;     Private key file - "c:\Cert\ACScert"&lt;/P&gt;&lt;P&gt;     Private key password - "acskey"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And you are done!!! Once you had installed the certificate, you can used EAP-TLS and PEAP authentication and HTTPS for access to the Cisco Secure ACS HTML interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;     &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Jun 2003 00:45:04 GMT</pubDate>
    <dc:creator>andyhkw72</dc:creator>
    <dc:date>2003-06-20T00:45:04Z</dc:date>
    <item>
      <title>error message when trying to enroll a certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/error-message-when-trying-to-enroll-a-certificate/m-p/170150#M436353</link>
      <description>&lt;P&gt;When I try to install a certificate that I generated using Cisco ACS signing request (CSR) I am getting an error mesage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Can not find certificate with specified common name in the ACS Storage"  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing a step I verified the name and the path of .pem file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Max&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-message-when-trying-to-enroll-a-certificate/m-p/170150#M436353</guid>
      <dc:creator>mtumarinson</dc:creator>
      <dc:date>2019-03-10T14:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: error message when trying to enroll a certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/error-message-when-trying-to-enroll-a-certificate/m-p/170151#M436354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Once you have generated a CSR, did you submit it to a certificate authority (CA Server) to receive your certificate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is the steps of how I install my cert:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Generate Certificate Signing Request:&lt;/P&gt;&lt;P&gt;     Certificate subject - "cn=ACS"&lt;/P&gt;&lt;P&gt;     Private key file - "c:\Cert\ACScert"&lt;/P&gt;&lt;P&gt;     Private key password - "acskey"&lt;/P&gt;&lt;P&gt;     Retype private key password - "acskey"&lt;/P&gt;&lt;P&gt;     Key length - "1024 bits"&lt;/P&gt;&lt;P&gt;     Digest to sign with - "SHA1"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Now a certificate signing request is ready. You can copy/paste it to any&lt;/P&gt;&lt;P&gt;     certification authority enrollment tool (CA Server).&lt;/P&gt;&lt;P&gt;3) After you have enrolled the above certificate with a CA Server, the CA Server&lt;/P&gt;&lt;P&gt;     will return a certificate to you, stored the returned certicate to "c:\Cert"&lt;/P&gt;&lt;P&gt;4) On your ACS, go to "System Configuration" -&amp;gt; "Install ACS Certificate"&lt;/P&gt;&lt;P&gt;5) Select "Use certificate from storage":&lt;/P&gt;&lt;P&gt;     Certificate CN - "ACS"&lt;/P&gt;&lt;P&gt;     Private key file - "c:\Cert\ACScert"&lt;/P&gt;&lt;P&gt;     Private key password - "acskey"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And you are done!!! Once you had installed the certificate, you can used EAP-TLS and PEAP authentication and HTTPS for access to the Cisco Secure ACS HTML interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;     &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2003 00:45:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-message-when-trying-to-enroll-a-certificate/m-p/170151#M436354</guid>
      <dc:creator>andyhkw72</dc:creator>
      <dc:date>2003-06-20T00:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: error message when trying to enroll a certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/error-message-when-trying-to-enroll-a-certificate/m-p/170152#M436355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wondering if you got this working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason that I ask is, having gone to the links included in the above replies and attempted to implement them, I continue to have issues with the ACS being able to utilise the certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have installed Microsoft CA on a stand-alone server.  ACS v3.1 is on another stand-alone server.  We are utilising the Web interface of the CA (i.e. &lt;A class="jive-link-custom" href="http://servername/CertSvr" target="_blank"&gt;http://servername/CertSvr&lt;/A&gt;) to request a certificate.  The request is successful (I ask for a Webserver cert as I understand that is what is required for PEAP implementation) and it asks me to install, which is what I do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then in ACS, under System Configuration\Install ACS Certificate, I locate where the cer file has been placed and then point to it, using the private key file that I input when requesting the cert.  When I submit the cert, it errors with various different messages, icluding:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Certificate File Not Found&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Private key does not match certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and others that I cannot now remember.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help with a step-by-step walk through of what is required to set this up, both on the Microsoft W2K side and ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help!!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2003 12:25:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-message-when-trying-to-enroll-a-certificate/m-p/170152#M436355</guid>
      <dc:creator>marcbutler</dc:creator>
      <dc:date>2003-11-13T12:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: error message when trying to enroll a certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/error-message-when-trying-to-enroll-a-certificate/m-p/170153#M436356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can get some walk through in &lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/cc/pd/sqsw/sq/tech/acstl_wp.htm" target="_blank"&gt;http://www.cisco.com/warp/public/cc/pd/sqsw/sq/tech/acstl_wp.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This white paper is for EAP-TLS but you need section 5.2.2 - AAA Server Certificate Requirements which is the same for PEAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than the points mentioned in this section , you have the step-by-step procedure in the previous correspodence.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need more specific help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ami&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2003 21:42:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-message-when-trying-to-enroll-a-certificate/m-p/170153#M436356</guid>
      <dc:creator>aschiebe</dc:creator>
      <dc:date>2003-11-13T21:42:47Z</dc:date>
    </item>
  </channel>
</rss>

