<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic asa ca enrollment in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ca-enrollment/m-p/764250#M1006840</link>
    <description>&lt;P&gt;I want to authenticate my ipsec vpn client by using certificate. I am using asa5540 as ipsec vpn server. The first step I should do is create an trustpoint and authenticate it to ca. the trustpoint name is knasaca&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I execute the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ca authenticate knasaca&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have encountered the debug output below&lt;/P&gt;&lt;P&gt;crypto_ca_get_ca_certificate(17793220, 169d0a0)&lt;/P&gt;&lt;P&gt;crypto_pki_req(17793220, 11, ...)&lt;/P&gt;&lt;P&gt;Crypto CA thread wakes up!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: Sending CA Certificate Request: &lt;/P&gt;&lt;P&gt;GET /cgi-bin/pkiclient.exe?operation=GetCACert&amp;amp;message=knasaca HTTP/1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: http connection opened&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: content dump count 75----------&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: For function crypto_http_send&lt;/P&gt;&lt;P&gt;GET /cgi-bin/pkiclient.exe?operation=GetCACert&amp;amp;message=knasaca HTTP/1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: For function crypto_http_send&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: content dump-------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: receiving Certificate Authority certificate: status = FAIL, cert length = 0&lt;/P&gt;&lt;P&gt;asavpn(config)# &lt;/P&gt;&lt;P&gt;CRYPTO_PKI: HTTP response header:&lt;/P&gt;&lt;P&gt; HTTP/1.1 404 Object Not Found&lt;/P&gt;&lt;P&gt;Server: Microsoft-IIS/5.0&lt;/P&gt;&lt;P&gt;Date: Thu, 19 Apr 2007 08:14:03 GMT&lt;/P&gt;&lt;P&gt;Content-Length: 4040&lt;/P&gt;&lt;P&gt;Content-Type: text/html&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Content-Type indicates we did not receive a certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: transaction GetCACert completedCrypto CA thread sleeps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what can be the problem.&lt;/P&gt;&lt;P&gt;is there anyone who can send me the prosedure to accomplish fully ca configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;Dogan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:01:43 GMT</pubDate>
    <dc:creator>dogany</dc:creator>
    <dc:date>2019-03-11T10:01:43Z</dc:date>
    <item>
      <title>asa ca enrollment</title>
      <link>https://community.cisco.com/t5/network-security/asa-ca-enrollment/m-p/764250#M1006840</link>
      <description>&lt;P&gt;I want to authenticate my ipsec vpn client by using certificate. I am using asa5540 as ipsec vpn server. The first step I should do is create an trustpoint and authenticate it to ca. the trustpoint name is knasaca&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I execute the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ca authenticate knasaca&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have encountered the debug output below&lt;/P&gt;&lt;P&gt;crypto_ca_get_ca_certificate(17793220, 169d0a0)&lt;/P&gt;&lt;P&gt;crypto_pki_req(17793220, 11, ...)&lt;/P&gt;&lt;P&gt;Crypto CA thread wakes up!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: Sending CA Certificate Request: &lt;/P&gt;&lt;P&gt;GET /cgi-bin/pkiclient.exe?operation=GetCACert&amp;amp;message=knasaca HTTP/1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: http connection opened&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: content dump count 75----------&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: For function crypto_http_send&lt;/P&gt;&lt;P&gt;GET /cgi-bin/pkiclient.exe?operation=GetCACert&amp;amp;message=knasaca HTTP/1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: For function crypto_http_send&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: content dump-------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: receiving Certificate Authority certificate: status = FAIL, cert length = 0&lt;/P&gt;&lt;P&gt;asavpn(config)# &lt;/P&gt;&lt;P&gt;CRYPTO_PKI: HTTP response header:&lt;/P&gt;&lt;P&gt; HTTP/1.1 404 Object Not Found&lt;/P&gt;&lt;P&gt;Server: Microsoft-IIS/5.0&lt;/P&gt;&lt;P&gt;Date: Thu, 19 Apr 2007 08:14:03 GMT&lt;/P&gt;&lt;P&gt;Content-Length: 4040&lt;/P&gt;&lt;P&gt;Content-Type: text/html&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Content-Type indicates we did not receive a certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: transaction GetCACert completedCrypto CA thread sleeps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what can be the problem.&lt;/P&gt;&lt;P&gt;is there anyone who can send me the prosedure to accomplish fully ca configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;Dogan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:01:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ca-enrollment/m-p/764250#M1006840</guid>
      <dc:creator>dogany</dc:creator>
      <dc:date>2019-03-11T10:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: asa ca enrollment</title>
      <link>https://community.cisco.com/t5/network-security/asa-ca-enrollment/m-p/764251#M1006842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This chapter describes how to configure certificates. CAs are responsible for managing certificate requests and issuing digital certificates. A digital certificate contains information that identifies a user or device. Some of this information can include a name, serial number, company, department, or IP address. A digital certificate also contains a copy of the public key for the user or device. A CA can be a trusted third party, such as VeriSign, or a private (in-house) CA that you establish within your organization. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_70/config/certs.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_70/config/certs.htm&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Apr 2007 11:59:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ca-enrollment/m-p/764251#M1006842</guid>
      <dc:creator>gmarogi</dc:creator>
      <dc:date>2007-04-27T11:59:33Z</dc:date>
    </item>
  </channel>
</rss>

