02-11-2004 03:42 AM
Hi,
We have recently configured an ssl redirect service on the CSS11503. This works great.
The css was then cleared of all configuration including all ssl cert/key associations inorder to test recovery.
The problem we are experiencing is that there is a rsakey file that is shown as existing but cannot be used or deleted.
Can anyone explain this?
Also when the generated digital certificates have been authenticated by Verisign. When trying to download to cisco a vendor code is required which we do not have?
Has anyone had similar problems?
02-11-2004 08:23 AM
did you try the command 'ssl clearfiles' from the llama/debug mode ?
Is it the CSS requesting the vendor code ?
What is the exact sentence ?
Thanks,
Gilles.
02-12-2004 02:19 AM
Gilles
This is the query raised by the customer:-
'On applying for a SSL Certificate from Verisign using a CSR produced on the CSS there is a requirement to provide the SSL server software vender. Neither Cisco nor WebNS appears on the options for the list and Verisign have advised that Cisco should be able to provide a suitable answer to this question'
We have been unable to find the SSL server software vendor
02-12-2004 02:41 AM
Ravi,
There are multiple types supported by the CSS SSL Module and WebNS.
If you select apache, you will get a PEM certificate.
WIN2000 IIS 5 uses PKCS12, and NT IIS4 uses DER
PEM, DER, and PKCS12 is supported by the CSS.
This info can be found at
I generally tell people to select apache, but the others should work. I agree, Cisco should be listed at the Apache website.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide