<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX and Microsoft CA certificate Server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-and-microsoft-ca-certificate-server/m-p/3427#M674812</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I found the solution for this problem. It was fairly simple. for you who have the Windows 2000 in spanish, the cetsetup.exe works only with the english version of windows Nt 2000.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Apr 2001 13:01:13 GMT</pubDate>
    <dc:creator>jcazila</dc:creator>
    <dc:date>2001-04-04T13:01:13Z</dc:date>
    <item>
      <title>PIX and Microsoft CA certificate Server</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-microsoft-ca-certificate-server/m-p/3424#M674809</link>
      <description>&lt;P&gt;I am trying to configure microsoft CA Certificate Server with the PIX, and I am unable to obtain the CA or RA certificate, so, the certificate request fails.&lt;/P&gt;&lt;P&gt;I have followed the instructions I found in the Instutor site, but it doesn't work for me. &lt;/P&gt;&lt;P&gt;First, I installed the CA in standalone mode, and gave a certificate to it.&lt;/P&gt;&lt;P&gt;Later I took the cepsetup.exe from the Windows 2000 resource toolkit and intalled SCEP support for Microsoft CA. I was requested to enter the information for a RA certificate, so I did. After reseting, of course, I typed the following commands from the pix:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clock set "current time, the same as in the CA"&lt;/P&gt;&lt;P&gt;ip domain-name example.com&lt;/P&gt;&lt;P&gt;ip hostname pix&lt;/P&gt;&lt;P&gt;ca generate rsa key 512&lt;/P&gt;&lt;P&gt;ca identity alexnap 10.0.0.2:/certsrv/mscep/mscep.dll&lt;/P&gt;&lt;P&gt;ca configure alexnap ra 1 5 crloptional&lt;/P&gt;&lt;P&gt;and NOW.....&lt;/P&gt;&lt;P&gt;when I type ca authenticate alexnap I obtanin the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sanjose(config)# ca authenticate alexnap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C&lt;/P&gt;&lt;P&gt; IC trhryeadp tsol eCeAp st!hread wakes up!&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: http connection opened&lt;/P&gt;&lt;P&gt;PKI: key process suspended and continued&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: WARNING: A certificate chain could not be constructed while selecting&lt;/P&gt;&lt;P&gt;certificate status&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: Can not get name ava count&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not decode router sub name.&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: Can not get name ava count&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not decode router sub name.&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: Can not get name ava count&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not decode router sub name.&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: WARNING: A certificate chain could not be constructed while selecting&lt;/P&gt;&lt;P&gt;certificate status&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: Can not get name ava count&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not decode router sub name.&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: Can not get name ava count&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not decode router sub name.&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: Can not get name ava count&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not decode router sub name.&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: status = 0: failed to get ca name from cert&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not set ra public key&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: status = 0: failed to get ca name from cert&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not set ra public key&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: transaction GetCACert completed&lt;/P&gt;&lt;P&gt;Certificate has the following attributes:&lt;/P&gt;&lt;P&gt;Fingerprint: 8698efea 67ec44a8 5c3abb18 a3b3da54&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: status = 0: failed to get ca name from cert&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not set ra public key&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: status = 0: failed to get ca name from cert&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: can not set ra public key&lt;/P&gt;&lt;P&gt;Crypto CA thread sleeps!&lt;/P&gt;&lt;P&gt;CI thread wakes &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INDICATING ME THAT THE RA AND CA PUBLIC KEYS COULD NOT BE SET.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOW WHEN I REQUEST A CERTIFICATE..........I OBTAIN THE FOLLOWING MESSAGE FROM THE DEBUG CRYPTO CA..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sanjose(config)# CA ENROLL ALEXNAP CISCO&lt;/P&gt;&lt;P&gt;%&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C%r Sytaprtto  cCeAr titfihcraetaed enroll mweankt ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;% Thee subject names  in utphe ce!rtificate will be: sanjose.softneteurope.com&lt;/P&gt;&lt;P&gt;CI thread sleeps!&lt;/P&gt;&lt;P&gt;CI thread wakes up!% Certificate request sent to Certificate Authority&lt;/P&gt;&lt;P&gt;% The certificate request fingerprint will be displayed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sanjose(config)#&lt;/P&gt;&lt;P&gt;sanjose(config)#&lt;/P&gt;&lt;P&gt;sanjose(config)#&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: transaction PKCSReq completed&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: status:&lt;/P&gt;&lt;P&gt;Crypto CA thread sleeps!&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: status = 0: failed to select RA encrypt cert&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: status = 65535: failed to set up peer auth context&lt;/P&gt;&lt;P&gt;CRYPTO_PKI: status = 65535: fail to send out pkcsreq&lt;/P&gt;&lt;P&gt;CRYPTO__PKI: All sockets are closed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WHAT IS GOING ON HERE, ANY HELP, OR SHOULD WE CHANGE THE CA OR SHOULD WE CONSTRUCT THE VPN WITH WINDOWS 2000 ( A SHAME)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:47:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-microsoft-ca-certificate-server/m-p/3424#M674809</guid>
      <dc:creator>jcazila</dc:creator>
      <dc:date>2020-02-21T05:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and Microsoft CA certificate Server</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-microsoft-ca-certificate-server/m-p/3425#M674810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One thing you should try if you can is to put the Microsoft Cert outside the firewall.&lt;/P&gt;&lt;P&gt;Two is on this line:&lt;/P&gt;&lt;P&gt;ca identity alexnap 10.0.0.2:/certsrv/mscep/mscep.dll&lt;/P&gt;&lt;P&gt;put a forward slash after the mscep.dll example:&lt;/P&gt;&lt;P&gt;ca identity alexnap 10.0.0.2:/certsrv/mscep/mscep.dll/&lt;/P&gt;&lt;P&gt;Because I had the similar issue myself. Hope that helps&lt;/P&gt;&lt;P&gt;Tony Cooper&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Feb 2001 02:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-microsoft-ca-certificate-server/m-p/3425#M674810</guid>
      <dc:creator>tony</dc:creator>
      <dc:date>2001-02-24T02:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and Microsoft CA certificate Server</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-microsoft-ca-certificate-server/m-p/3426#M674811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you tony, very kind of you but, it didn't work for me. May be there is s problem with versions. My mscep.dll is 5.131.2155.1. do you have a diferent (more recent version?). In fact, reading the releases for VPN client version 1.1, I found that VPN 1.1 will work only with version 5.131.2199.1, aas long as I remember. could you send me the version you have, so I could try with it?.&lt;/P&gt;&lt;P&gt;thank you again,&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;alexnap&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2001 15:02:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-microsoft-ca-certificate-server/m-p/3426#M674811</guid>
      <dc:creator>jcazila</dc:creator>
      <dc:date>2001-02-28T15:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and Microsoft CA certificate Server</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-microsoft-ca-certificate-server/m-p/3427#M674812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I found the solution for this problem. It was fairly simple. for you who have the Windows 2000 in spanish, the cetsetup.exe works only with the english version of windows Nt 2000.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2001 13:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-microsoft-ca-certificate-server/m-p/3427#M674812</guid>
      <dc:creator>jcazila</dc:creator>
      <dc:date>2001-04-04T13:01:13Z</dc:date>
    </item>
  </channel>
</rss>

