cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1179
Views
0
Helpful
3
Replies

Replacing Self-Signed Cert Issue

Xividar
Level 1
Level 1

Hi Guys,

I am trying to replace my Self-Signed DNAC certificate, and use one from my PKI. I am following this link - I am getting to the last step, but my Private Key is being rejected "Private Key Validation Failed" - I am little unsure as to why this is failing. I am using a Windows CA. Any help would be apprecaited.

Screenshot 2021-02-01 at 13.26.06.png

 

Thanks.

3 Replies 3

Mike.Cifelli
VIP Alumni
VIP Alumni

What version of DNAC are you running?  This is a new one that I have not seen yet.  I had a certificate import/replacement error as well a little while back, see: Replacing DNAC Certificate Error - Cisco Community

Not sure if that will help your situation, but worth a shot to check the box.  Lastly, I would suggest engaging TAC (incase of a bug), and possibly re-doing the process from scratch to see if the outcome is different.  HTH!

Hi Mike,

2.1.2.5 here, thank you, I will check that link - if not, it might well be a TAC call

Thanks.

densto
Level 1
Level 1

Hi Xividar,

Did you add your ROOT Ca certificate in DNA Trust POOL?

https://yourdna-server/dna/systemSettings/settings?settings-item=trustpool

also did you add all ip addresses and host names including VIP to SAN for all nodes when you generated CSR?

Thanks

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: