<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft subordinate CA w/ Cisco router / PIX 501 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154919#M716125</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would it be possible to send me one?  I think my issue could be related to the setup of the CA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Feb 2003 20:30:14 GMT</pubDate>
    <dc:creator>adrian.watmough</dc:creator>
    <dc:date>2003-02-07T20:30:14Z</dc:date>
    <item>
      <title>Microsoft subordinate CA w/ Cisco router / PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154914#M716058</link>
      <description>&lt;P&gt;I am trying to get digital certificates to work on my Cisco 2621XM router.  I also&lt;/P&gt;&lt;P&gt;need to set them up on three PIX 501 firewalls but haven't gotten that far yet.  I&lt;/P&gt;&lt;P&gt;do not have access to the root CA but could bring it back online if I had to.  I&lt;/P&gt;&lt;P&gt;have a Microsoft standalone subordinate CA which I want to use to issue all&lt;/P&gt;&lt;P&gt;certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this be done, both with the router and the firewalls?  If so, which version&lt;/P&gt;&lt;P&gt;of the IOS do I need?  I have installed the SCEP add-on to the CA.  I cannot get&lt;/P&gt;&lt;P&gt;this to work and am beginning to wonder if it is even possible.  If this does &lt;/P&gt;&lt;P&gt;work, how can I get it to work?  I have combed all of the documents Cisco has&lt;/P&gt;&lt;P&gt;on the subject and have gotten nowhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance would be greatly appreciated.  Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154914#M716058</guid>
      <dc:creator>jennette_o</dc:creator>
      <dc:date>2020-02-21T06:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft subordinate CA w/ Cisco router / PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154915#M716065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ya it works.  Depending on what features you "need" will determine what version of IOS and pix you'll need.  It also makes a difference on how the server is set up.  Here's a link on setting up pix and routers with certificates.  &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/707/lan_to_lan_ipsec_pix_rtr_cert.html" target="_blank"&gt;http://www.cisco.com/warp/public/707/lan_to_lan_ipsec_pix_rtr_cert.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming of course your certificate server is configured correctly, which is always a problem.   I can send you a doc that I made and used hundreds of times to configure certs on pix and routers as well as setting up the server.  With enough steps to troubleshoot it as well.  But its not been updated for some of the new working features which you may/maynot need because at the time they didnt work.  If you have problems, make sure you post your cert debugs as well as the steps you took to obtain them on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kurtis Durrett&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Dec 2002 21:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154915#M716065</guid>
      <dc:creator>kdurrett</dc:creator>
      <dc:date>2002-12-05T21:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft subordinate CA w/ Cisco router / PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154916#M716070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That link was to one of the many documents I have printed out and couldn't get to work &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do get a certificate -- sort of.  After all the hex data finishes scrolling, I get these debugging messages, each repeated several times:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error: Certificate, private key or CRL was not found while selecting certificate chain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WARNING: A certificate chain could not be constructed while selecting certificate status&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error: Code 0x0000 while selecting self signed certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can not get name ava count&lt;/P&gt;&lt;P&gt;Can not decode router sub name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After repeating these messages several times, it finally gives up and fails to get the certificate.  I think the end status code is 324.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't guarantee my CA is set up correctly, since I'm pretty new to it.  In accordance with MS guidelines, I altered the AIA and CDP paths to have a distribution point on my online CA.  This is an accessible HTTP location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The time on my router is correct.  I have "enrollment mode ra" set.  I've tried it with "crl optional" but no difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you could send me your document I wouldn't mind taking a look at it.  Email address is &lt;A href="mailto:jennette_o@yahoo.com"&gt;jennette_o@yahoo.com&lt;/A&gt;.  Thanks much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Dec 2002 21:46:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154916#M716070</guid>
      <dc:creator>jennette_o</dc:creator>
      <dc:date>2002-12-05T21:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft subordinate CA w/ Cisco router / PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154917#M716085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is very typical problem. Please look first at the certificate server. If you use microsoft certificate server you should aproove any certificate that is issued. This is not done authomatically, so you should do you by hand on the MMC console. Anyway - if the certificate server says that the certificate is valid and enroled (sended to the client) don't worry. This is also typical issue. Probably you are running in Cisco IOS bug. So you should open a case in TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Dec 2002 23:35:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154917#M716085</guid>
      <dc:creator>ddelchev</dc:creator>
      <dc:date>2002-12-05T23:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft subordinate CA w/ Cisco router / PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154918#M716101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jennnette,&lt;/P&gt;&lt;P&gt;I sent you that document, let me know how it goes or if you have any questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kurtis Durrett&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2002 18:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154918#M716101</guid>
      <dc:creator>kdurrett</dc:creator>
      <dc:date>2002-12-06T18:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft subordinate CA w/ Cisco router / PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154919#M716125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would it be possible to send me one?  I think my issue could be related to the setup of the CA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2003 20:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-subordinate-ca-w-cisco-router-pix-501/m-p/154919#M716125</guid>
      <dc:creator>adrian.watmough</dc:creator>
      <dc:date>2003-02-07T20:30:14Z</dc:date>
    </item>
  </channel>
</rss>

