<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ryhs,I am having the same in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582198#M204775</link>
    <description>&lt;P&gt;Ryhs,&lt;/P&gt;&lt;P&gt;I am having the same issue with import of a new CA root and intermediate cert. I have read your most recent reply but it seems contradictory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You state "It would appear that RSASSA-PSS does not work with Cisco ASA devices" then go on to say "the certificate was re-created using RSASSA-PSS.........and the certificate loaded onto the ASA"&lt;/P&gt;&lt;P&gt;My root is 4096 and intermediate is 2048. Both show signature algorithm as RSASSA-PSS rather than anything with ECDSA in the field. See attached. Should these certs work or do I need to re-create in another way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Wes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Nov 2014 16:00:11 GMT</pubDate>
    <dc:creator>wesdouglas</dc:creator>
    <dc:date>2014-11-04T16:00:11Z</dc:date>
    <item>
      <title>Cisco ASA CA Certificate import error using ECDSA and SHA-256</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582194#M204771</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am attempting to import&amp;nbsp;a root CA certificate into my ASA 5585X from our internal PKI.&lt;/P&gt;&lt;P&gt;The CA Cert&amp;nbsp;uses the following:&lt;/P&gt;&lt;P&gt;Signature algorithm - ECDSA&lt;/P&gt;&lt;P&gt;Signature hash algorithm - sha256&lt;/P&gt;&lt;P&gt;Public key - ECC (384 Bits)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get the following error when attempting to import the certificate onto the ASA:&lt;/P&gt;&lt;P&gt;% Error in saving certificate: status = FAIL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have run a debug and get the following messages:&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not set ca cert object (0x722)&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: status = 65535: failed to process RA certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to import the CA using ASA Version 9.1.4 and 9.1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help or suggestions would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rhys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:00:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582194#M204771</guid>
      <dc:creator>rhyshobden</dc:creator>
      <dc:date>2019-03-12T05:00:00Z</dc:date>
    </item>
    <item>
      <title>Hi,What is the expiration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582195#M204772</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What is the expiration date on this certificate ?&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2014 01:09:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582195#M204772</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-10-29T01:09:39Z</dc:date>
    </item>
    <item>
      <title>Hi,Certificate details are as</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582196#M204773</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Certificate details are as follows:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ca.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2014 09:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582196#M204773</guid>
      <dc:creator>rhyshobden</dc:creator>
      <dc:date>2014-10-29T09:46:57Z</dc:date>
    </item>
    <item>
      <title>OK, so I have worked with my</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582197#M204774</link>
      <description>&lt;P&gt;OK, so I have worked with my PKI guys on this and this is what we have found:&lt;BR /&gt;&lt;BR /&gt;The first certificate that was generated used&amp;nbsp;RSASSA-PSS, which was standardized in PKCS#1 v2.1 and is generally recommended to be used as an alternative to the older more widespread RSASSA algorithm in PKCS#1 v1.5.&lt;/P&gt;&lt;P&gt;It would appear that RSASSA-PSS does not work with Cisco ASA devices.&lt;/P&gt;&lt;P&gt;This shows as "specifiedECDSA" in the certificate signature algorithm field, where as when the certificate was re-created using RSASSA-PSS the field showed as "sha256ECDSA" and the certificate loaded onto the ASA with no problems&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Rhys.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 08:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582197#M204774</guid>
      <dc:creator>rhyshobden</dc:creator>
      <dc:date>2014-10-31T08:36:07Z</dc:date>
    </item>
    <item>
      <title>Ryhs,I am having the same</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582198#M204775</link>
      <description>&lt;P&gt;Ryhs,&lt;/P&gt;&lt;P&gt;I am having the same issue with import of a new CA root and intermediate cert. I have read your most recent reply but it seems contradictory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You state "It would appear that RSASSA-PSS does not work with Cisco ASA devices" then go on to say "the certificate was re-created using RSASSA-PSS.........and the certificate loaded onto the ASA"&lt;/P&gt;&lt;P&gt;My root is 4096 and intermediate is 2048. Both show signature algorithm as RSASSA-PSS rather than anything with ECDSA in the field. See attached. Should these certs work or do I need to re-create in another way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Wes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2014 16:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582198#M204775</guid>
      <dc:creator>wesdouglas</dc:creator>
      <dc:date>2014-11-04T16:00:11Z</dc:date>
    </item>
    <item>
      <title>Hello,Sorry for the late</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582199#M204776</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Sorry for the late reply.&lt;/P&gt;&lt;P&gt;The certificate was resigned using&amp;nbsp;&lt;SPAN style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;RSASSA algorithm in PKCS#1 v1.5 rather than&amp;nbsp;PKCS#1 v2.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;This was a registry fix on the Windows machine issuing the certificates.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Also, if you are using key lengths 4096 and 2048 you are signing using RSA rather than ECDSA, so I'm not sure if you do have the same issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Rhys&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 10:43:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582199#M204776</guid>
      <dc:creator>rhyshobden</dc:creator>
      <dc:date>2015-02-04T10:43:05Z</dc:date>
    </item>
    <item>
      <title>This is a known issue.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582200#M204777</link>
      <description>&lt;P&gt;This is a known issue. Enhancement request &lt;STRONG&gt;CSCup44159&lt;/STRONG&gt; has been filed to add support for RSASSA-PSS on the ASA. &lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 03:21:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582200#M204777</guid>
      <dc:creator>Atri Basu</dc:creator>
      <dc:date>2015-11-24T03:21:32Z</dc:date>
    </item>
    <item>
      <title>This is a known issue.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582201#M204778</link>
      <description>&lt;P&gt;This is a known issue. Enhancement request &lt;A href="https://tools.cisco.com/bugsearch/bug/CSCup44159/?reffering_site=dumpcr"&gt;&lt;STRONG&gt;CSCup44159&lt;/STRONG&gt;&lt;/A&gt; has been filed to add support for RSASSA-PSS on the ASA.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 03:22:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ca-certificate-import-error-using-ecdsa-and-sha-256/m-p/2582201#M204778</guid>
      <dc:creator>Atri Basu</dc:creator>
      <dc:date>2015-11-24T03:22:37Z</dc:date>
    </item>
  </channel>
</rss>

