<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5505 CSR problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-csr-problem/m-p/1057560#M894402</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;got this working - i was half way there. when the original csr (from the asa) was rejected by globalsign i generated a csr using openssl:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;openSSL&amp;gt;req -new -newkey rsa:2048 -nodes -keyout mykey.pem -out myreq.pem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i received the cert from globalsign i combined it with my key:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;openssl&amp;gt;pkcs12 -export -in CA.pem -inkey mykey.pem -out CA.p12 -clcerts -passin pass:&lt;PASSWORD&gt; -passout pass:&lt;PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then went to ASA and Configuration-&amp;gt;Device Management-&amp;gt;Certificate Management-&amp;gt;Identity Certificates. selected Add and 'import identity certificate form file' - used output file from last openssl statement with password and cert imported ok&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Oct 2008 14:46:45 GMT</pubDate>
    <dc:creator>andrewswanson</dc:creator>
    <dc:date>2008-10-29T14:46:45Z</dc:date>
    <item>
      <title>ASA 5505 CSR problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-csr-problem/m-p/1057559#M894398</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;i'm trying to generate a csr on an ASA 5505 (ASDM 6.1(1) ASA v8.0(3)) for our new SSL VPN service. i followed the documentation at &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808b3cff.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808b3cff.shtml&lt;/A&gt; and submitted the csr to our 3rd party vendor Globalsign.&lt;/P&gt;&lt;P&gt;a few days later the request was rejected due "to the inclusion of an unstructuredName element within the subject of the CSR."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i generate the csr (either from cli or asdm), the resultant csr contains&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unstructuredName=IA5STRING:&amp;lt;my_fqdn&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where my_fqdn is the name i used in the CN field.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i tried generating a csr for the asa with openssl and submitted that to globalsign which was successful but get the error "Certificate does not contain general purpose public key" when i try to install it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas or pointers appreciated.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-csr-problem/m-p/1057559#M894398</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-03-11T14:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 CSR problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-csr-problem/m-p/1057560#M894402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;got this working - i was half way there. when the original csr (from the asa) was rejected by globalsign i generated a csr using openssl:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;openSSL&amp;gt;req -new -newkey rsa:2048 -nodes -keyout mykey.pem -out myreq.pem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i received the cert from globalsign i combined it with my key:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;openssl&amp;gt;pkcs12 -export -in CA.pem -inkey mykey.pem -out CA.p12 -clcerts -passin pass:&lt;PASSWORD&gt; -passout pass:&lt;PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then went to ASA and Configuration-&amp;gt;Device Management-&amp;gt;Certificate Management-&amp;gt;Identity Certificates. selected Add and 'import identity certificate form file' - used output file from last openssl statement with password and cert imported ok&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2008 14:46:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-csr-problem/m-p/1057560#M894402</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2008-10-29T14:46:45Z</dc:date>
    </item>
  </channel>
</rss>

