<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue: Certificate authentication not working in Secure Access Cli in Secure Access Discussions</title>
    <link>https://community.cisco.com/t5/secure-access-discussions/issue-certificate-authentication-not-working-in-secure-access/m-p/5337429#M80</link>
    <description>&lt;P&gt;Dear Community Team,&lt;/P&gt;
&lt;P&gt;Kindly help on this.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1903767"&gt;@Chinmaya-Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Oct 2025 05:57:03 GMT</pubDate>
    <dc:creator>Chinmaya-Naik</dc:creator>
    <dc:date>2025-10-10T05:57:03Z</dc:date>
    <item>
      <title>Issue: Certificate authentication not working in Secure Access Client</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/issue-certificate-authentication-not-working-in-secure-access/m-p/5337173#M79</link>
      <description>&lt;P&gt;User Provisioning and IdP integration is done.&lt;/P&gt;
&lt;P&gt;SAML Authentication is working after integrated IdP&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;GOAL:&lt;/STRONG&gt; Certificate Base Authentication for some machine (windows)&lt;/P&gt;
&lt;P&gt;I created a new VPN Profile in CISCO SSE Portal and in &lt;STRONG&gt;Authenticate with CA certificates &lt;/STRONG&gt;section we uploaded two certificates:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Root CA&lt;/LI&gt;
&lt;LI&gt;Issuing CA&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;We uploaded both because currently the Organization Domain system having these two certificates.&lt;/P&gt;
&lt;P&gt;After uploaded both certificates then we able to see the details on the&amp;nbsp;&lt;STRONG&gt;Certificates&lt;/STRONG&gt; section as below:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issued to:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;lt;XYZ&amp;gt; Root CA&lt;/P&gt;
&lt;P&gt;&amp;lt;XYZ&amp;gt; Issuing CA&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Purpose:&lt;/STRONG&gt; VPN&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issuer:&lt;/STRONG&gt; XYZ Root CA and &amp;lt;XYZ&amp;gt; Issuing CA&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Serial Number:&lt;/STRONG&gt; 221467160578667016xxxxxxxxxx and 7704348077178571089266226439xxxxxx&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Expiration Date&lt;/STRONG&gt;: August , 2034 and January 2034&lt;/P&gt;
&lt;P&gt;When try to connect the AnyConnect client after mentioning the FQDN then getting the below error:&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Certicate Validation Failure&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NOTE: We also place the XML file (VPN Profile) C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Profile.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please let me know the procedure and next steps to resolve the issue and this requirement.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance for your support!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;@&lt;A id="viewUserProfile_856cd3ac57ce7c" class="lia-link-navigation view-profile-link lia-component-users-action-view-user-profile" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1903767" target="_blank" rel="noopener"&gt;Chinmaya-Naik&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 11:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/issue-certificate-authentication-not-working-in-secure-access/m-p/5337173#M79</guid>
      <dc:creator>Chinmaya-Naik</dc:creator>
      <dc:date>2025-10-09T11:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Issue: Certificate authentication not working in Secure Access Cli</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/issue-certificate-authentication-not-working-in-secure-access/m-p/5337429#M80</link>
      <description>&lt;P&gt;Dear Community Team,&lt;/P&gt;
&lt;P&gt;Kindly help on this.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1903767"&gt;@Chinmaya-Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 05:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/issue-certificate-authentication-not-working-in-secure-access/m-p/5337429#M80</guid>
      <dc:creator>Chinmaya-Naik</dc:creator>
      <dc:date>2025-10-10T05:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Issue: Certificate authentication not working in Secure Access Cli</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/issue-certificate-authentication-not-working-in-secure-access/m-p/5338622#M82</link>
      <description>&lt;P&gt;Waiting for the update from community.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 05:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/issue-certificate-authentication-not-working-in-secure-access/m-p/5338622#M82</guid>
      <dc:creator>Chinmaya-Naik</dc:creator>
      <dc:date>2025-10-15T05:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Issue: Certificate authentication not working in Secure Access Cli</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/issue-certificate-authentication-not-working-in-secure-access/m-p/5347656#M111</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;So the root CAs and Intermediate CAs in Secure Access are uploaded under Secure &amp;gt; Certificates &amp;gt; Client authentication?&lt;BR /&gt;If this is fine, which fields to authenticate did you choose in the VPN-Profile Configuration under Authentication?&lt;BR /&gt;And, about what kind of devices are we talking trying to authenticate? Maybe also the wrong certificate is used to authenticate from the Device. You can specify the conditions of the Certificate to choose for authentication in the VPN-Profile config under Cisco Secure Client Configuration &amp;gt; Client certificate Settings.&lt;BR /&gt;&lt;BR /&gt;For e.g. it makes sense to choose Windows &amp;gt; User if we are talking about Windows Devices with enrolled User Certificates.&lt;BR /&gt;Also further under certificate matching and Key Usage the attributes of the Certificate can be choosen.&lt;BR /&gt;&lt;BR /&gt;You can check these points to verify configuration. You can also reproduce the Problem and create a DART-Bundle. In the DART-Bundle you can find a more specific reason why the authentication is failing.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2025 16:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/issue-certificate-authentication-not-working-in-secure-access/m-p/5347656#M111</guid>
      <dc:creator>mupakis</dc:creator>
      <dc:date>2025-11-17T16:00:12Z</dc:date>
    </item>
  </channel>
</rss>

