cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
693
Views
0
Helpful
6
Replies

Import user installed certificate in 7925G

alaugros2
Level 1
Level 1

Hello,

 

I am trying to import a user installed certificate into my 7925G cisco IP Phone.

 

I used the following procedure page 98 : http://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/cuipph/7925g/7_0/english/deployment/guide/7925dply.pdf

 

I created a CSR and imported the certificate of the CA server that is signing the request into my cisco phone (I also tried to make it by importing the server certificate of the root CA). But when I import the certificate signed by the CA in the 7925G, I get the following error : "User certificate installation failed"

 

Do you know what does this message mean ?

 

My user installed certificate is :

  • .der encoded
  • Signed with SHA-1
  • 2048 key size
  • In certificate detail tab, I do not see any entry for CRL or Certificate renewal 
  • Client Authentication is listed in the Enhanced Key Usage
  • The date and time is correctly configured in my Cisco Phone

Thank you for your help !

Regards,

Arthur

 

6 Replies 6

alaugros2
Level 1
Level 1

I attached the log file of my Cisco 7925G. When I try to import the signed certificate, I get the following logs :

2016-05-23 14:14:58:0160 HERMIT user.info www[179]: Cert verification success
2016-05-23 14:14:58:0170 HERMIT user.info www[179]: Private key and certificate verification success
2016-05-23 14:14:58:0300 HERMIT user.info www[179]: UpdateUsrCertCN : /bin/cp -f  /flash0/sec/usr/misc/user_cert_cn /voice/user_cert_cn return 256
2016-05-23 14:14:58:0310 HERMIT user.warn kernel: random open
2016-05-23 14:14:58:0320 HERMIT user.warn kernel: random open
2016-05-23 14:14:58:0530 HERMIT user.debug secd: Sent 1628 bytes to local server,pCon=166
2016-05-23 14:14:58:0530 HERMIT user.debug secd: SendToServer--->
2016-05-23 14:14:58:0530 HERMIT user.debug secd: SSLServerReadHandler <---
2016-05-23 14:14:58:0540 HERMIT user.debug secd: appLoop: rd ok, fd 11 (sslcon)
2016-05-23 14:14:58:0540 HERMIT user.debug secd: setFds: chk rd, fd 12 (localserver)
2016-05-23 14:14:58:0540 HERMIT user.debug secd: setFds: chk rd, fd 11 (sslcon)
2016-05-23 14:14:58:0550 HERMIT user.debug secd: setFds: chk rd, fd 10 (sslserver)
2016-05-23 14:14:58:0550 HERMIT user.debug secd: setFds: chk rd, fd 7 (prxy)
2016-05-23 14:14:58:0550 HERMIT user.debug secd: setFds: chk rd, fd 6 (reqS)
2016-05-23 14:14:58:0650 HERMIT user.err www[179]: PKCS12 ExportKeyAndCertsToPKCS12 st=750
2016-05-23 14:14:58:0660 HERMIT user.err www[179]: Importing signed certificate failed
2016-05-23 14:14:58:0660 HERMIT user.debug www[179]: WPRedirectToHttps(): localPort=443, localIp=192.168.1.100, url=/StatusMessage?19,4
2016-05-23 14:14:58:0660 HERMIT user.debug www[179]: Response: HTTP/1.1 303 See Other^M
2016-05-23 14:14:58:0670 HERMIT user.debug www[195]: StcpSendSy, Conne = 0, Length: 137
2016-05-23 14:14:58:0670 HERMIT user.debug secd: setFds: chk rd, fd 5 (cmd)
2016-05-23 14:14:58:0680 HERMIT user.debug secd: setFds: monitor, rd 6 wr 0

Thanks

Arthur

Same problem here. Any luck?

I have a similar problem, only with the manufacturer's root certificateIMG_0308.jpeg

eyalraba
Cisco Employee
Cisco Employee

I see the following error:

2016-05-23 14:14:58:0650 HERMIT user.err www[179]: PKCS12 ExportKeyAndCertsToPKCS12 st=750
2016-05-23 14:14:58:0660 HERMIT user.err www[179]: Importing signed certificate failed

 

Are you using Linux based CA or Windows based CA to sign the certificate?

I use CA on Windows

What version, it might be a compatibility issue. suspecting CSCth16415 : Bug Search Tool (cisco.com)

Can you try and use Windows 2003 CA.