<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PKCS #12 Import failed in Controllers</title>
    <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607219#M2535</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any update on this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Aug 2017 14:00:01 GMT</pubDate>
    <dc:creator>Alex Pfeil</dc:creator>
    <dc:date>2017-08-31T14:00:01Z</dc:date>
    <item>
      <title>PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607210#M2526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to deploy iWAN through APIC-EM iWAN app. While deploying hub site, I am getting following error -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Nov 29 21:51:37.156: CRYPTO_PKI: status = 0x747(E_EOS : end of i/o stream): Imported PKCS12 file failure &lt;/P&gt;&lt;P style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;*Nov 29 21:51:37.156: %PKI-6-PKCS12IMPORT_FAIL: PKCS #12 Import Failed.&lt;/P&gt;&lt;P style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Please advise&lt;/P&gt;&lt;P style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Thanks,&lt;/P&gt;&lt;P style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Vish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2019 12:33:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607210#M2526</guid>
      <dc:creator>vishal-patil</dc:creator>
      <dc:date>2019-03-01T12:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607211#M2527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;some one else had a similar issue in this thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/72808" style="font-size: 10pt;" title="https://communities.cisco.com/thread/72808"&gt;https://communities.cisco.com/thread/72808&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2016 20:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607211#M2527</guid>
      <dc:creator>aradford</dc:creator>
      <dc:date>2016-11-29T20:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607212#M2528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the device details here? What platform? What release of APIC-EM is in use? Which iWAN workflow is this - the hub provisioning or branch provisioning? Details like these would help us understand and troubleshoot better.&lt;/P&gt;&lt;P&gt;Having said that, please refer to the link Adam has given to figure out if there's any routing that's causing this in your set-up.&lt;/P&gt;&lt;P&gt;Additionally, there's a known issue on device side where &lt;SPAN style="font-size: 10pt;"&gt;if the certificate is more than 4K bytes of size, then PKCS import will fail. So please check the size of your cert.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2016 21:07:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607212#M2528</guid>
      <dc:creator>cchitnis</dc:creator>
      <dc:date>2016-11-29T21:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607213#M2529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. did debug crypto messages/transaction. Looks like the devices are contacting APIC-EM by its external IP somehow while importing certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;SPAN&gt;*Nov 29 22:09:06.707: CRYPTO_PKI: Copying pkcs12 from &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://xx.xx.xx.xx/api/v1/trust-point/pkcs12/7bf507b5-4566-4b55-a440-d0cfcbc7a298/3c4nlc88u5tq266glql3bfq36p" rel="nofollow" target="_blank"&gt;http://xx.xx.xx.xx/api/v1/trust-point/pkcs12/7bf507b5-4566-4b55-a440-d0cfcbc7a298/3c4nlc88u5tq266glql3bfq36p&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;xx- should be internal IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Hopefully I will be able to fix this&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #39393b; font-family: Consolas; font-size: 14px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Vish&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2016 21:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607213#M2529</guid>
      <dc:creator>vishal-patil</dc:creator>
      <dc:date>2016-11-29T21:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607214#M2530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info (especially certificate size. will take a note of that)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Visha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2016 21:12:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607214#M2530</guid>
      <dc:creator>vishal-patil</dc:creator>
      <dc:date>2016-11-29T21:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607215#M2531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Visha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding public/private address for PKI cert import - does that mean with EM 1.3 we can not use iWAN app provisioning over INET (in which case we have no choice but to NAT the controller)? In my case, it is a dual-router LTE branch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Igor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2016 13:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607215#M2531</guid>
      <dc:creator>Igor Manassypov</dc:creator>
      <dc:date>2016-12-23T13:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607216#M2532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Limitation on cert size is specific to subCA deployment. If you don't have subCA deployment, you are fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2016 19:30:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607216#M2532</guid>
      <dc:creator>cchitnis</dc:creator>
      <dc:date>2016-12-23T19:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607217#M2533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;[Edited 01/23/2017: Pre release 1.4, NAT'ed controller support for iWAN is for greenfield sites only. In release 1.4, we are extending that support to brownfield sites as well]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AFAIK, we do support NAT'ed controller. As long as there's a connectivity from your branch to the controller, the PKCS12 import should be fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2016 19:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607217#M2533</guid>
      <dc:creator>cchitnis</dc:creator>
      <dc:date>2016-12-23T19:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607218#M2534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;APIC-EM behind NAT (NAT'ed controller) support for brownfield branch sites to be released in 1.4 release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2017 01:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607218#M2534</guid>
      <dc:creator>cchitnis</dc:creator>
      <dc:date>2017-01-24T01:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: PKCS #12 Import failed</title>
      <link>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607219#M2535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any update on this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Aug 2017 14:00:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/pkcs-12-import-failed/m-p/3607219#M2535</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2017-08-31T14:00:01Z</dc:date>
    </item>
  </channel>
</rss>

