<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Certificate Installation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/identity-certificate-installation/m-p/2155084#M357088</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The CA root is installed and authenticated.&amp;nbsp; I have now installed the Identity certificate, and am wondering if it is required that the trustpoint for the identity certificate and the CA certificate need to be the same.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Feb 2013 09:29:39 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2013-02-06T09:29:39Z</dc:date>
    <item>
      <title>Identity Certificate Installation</title>
      <link>https://community.cisco.com/t5/network-security/identity-certificate-installation/m-p/2155082#M357086</link>
      <description>&lt;P&gt;I am a little uncertain if I am required to do anything else.&amp;nbsp; Or perhaps I am misunderstanding and the Identity cert doesn't need the same trustpoint as the CA cert?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I get a FAIL message when I run the crypto ca authenticate command for my certificate.&amp;nbsp; It is installed.&amp;nbsp; It is a Verisign certificate.&amp;nbsp; I have a Verisign Root certificate Trustpoint CERT that is also installed on the ASA, but as you see it has a different trustpoint name, does this matter or is it just significant to that particular certificate?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am trying to renew an ID certificate.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA(config)# crypto ca authenticate CERT2&lt;BR /&gt;Enter the base 64 encoded CA certificate.&lt;BR /&gt;End with the word "quit" on a line by itself&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&amp;lt;snip&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;quit&lt;/P&gt;&lt;P&gt;INFO: Certificate has the following attributes:&lt;BR /&gt;Fingerprint:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;snip&amp;gt;&lt;BR /&gt;Do you accept this certificate? [yes/no]: y&lt;/P&gt;&lt;P&gt;Trustpoint CERT2 is a subordinate CA and holds a non self-signed certificate.&lt;/P&gt;&lt;P&gt;Trustpoint CERT2 is a subordinate CA.&lt;BR /&gt;but certificate is not a CA certificate.&lt;BR /&gt;Manual verification required&lt;/P&gt;&lt;P&gt;Trustpoint CA certificate accepted.&lt;BR /&gt;ERROR: Certificate already exists in the trustpoint CERT2&lt;BR /&gt;% Error in saving certificate: status = FAIL&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:56:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-certificate-installation/m-p/2155082#M357086</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2019-03-12T00:56:31Z</dc:date>
    </item>
    <item>
      <title>Identity Certificate Installation</title>
      <link>https://community.cisco.com/t5/network-security/identity-certificate-installation/m-p/2155083#M357087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't fully understand your issue, but&lt;/P&gt;&lt;P&gt;To install identity certificate you should have trustpoint, authenticated with CA, wich directly issued your identity certificate. It doesn't matter for asa if your CA is root or subordinate 'cause it doesn't check the whole chaind by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Create a trustpoint.&lt;/P&gt;&lt;P&gt;2. Authenticate this trustpoint with some CA certificate (root or subordinate), using &lt;EM&gt;crypto ca authenticate&lt;/EM&gt; command. This is cert of CA, wich will issue your identity certificate.&lt;/P&gt;&lt;P&gt;3. (optional) Issue request for identity certificate (wich i assume you've already done) using &lt;EM&gt;crypto ca enroll &lt;/EM&gt;command.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Install identity certificate using &lt;EM&gt;crypto ca import &lt;/EM&gt;command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you're trying to do in the output above is adding another CA certificate for trustpoint. Is that what you want to do? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 17:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-certificate-installation/m-p/2155083#M357087</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-02-05T17:30:21Z</dc:date>
    </item>
    <item>
      <title>Identity Certificate Installation</title>
      <link>https://community.cisco.com/t5/network-security/identity-certificate-installation/m-p/2155084#M357088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The CA root is installed and authenticated.&amp;nbsp; I have now installed the Identity certificate, and am wondering if it is required that the trustpoint for the identity certificate and the CA certificate need to be the same.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 09:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-certificate-installation/m-p/2155084#M357088</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-02-06T09:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Certificate Installation</title>
      <link>https://community.cisco.com/t5/network-security/identity-certificate-installation/m-p/2155085#M357089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of course they should be the same. If you try to install identity certificate for trustpoint, that is not authenticated with CA cert (wich issued that identity certificate), the operation will fail, cause chain won't build.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 10:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-certificate-installation/m-p/2155085#M357089</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-02-06T10:08:46Z</dc:date>
    </item>
  </channel>
</rss>

