09-03-2021 07:59 AM
Hello everybody,
our customer has a ASA (OS rel. 9.8(43)2) and the AnyConnect client 4.9 on their
PCs.
Recently the SSL certificate expired and they got the AnyConnect notification window
about the 'Untrsted Server Certificate' and could connect after clickeing on 'Connect Anyway'.
Now there is a new self signed SSL certificate and they get the AnyConnect notification window
about the 'Untrsted Server Certificate' again with the option 'Always trust the server
and import the certificate' but when they use this option the connection was not
established.
My questions are:
1. How to import a new self signed SSL certificate on a AnyConnect client PC the right way?
2. Where is the right loaction an the PC to store the new SSL certificate so this
can be found by the AnyConnect client?
3. Where should I find this on the Windows mmc in certmgr? There are many categories ...
Thanks a lot for your hints.
Greetings!
Bye
R.
Solved! Go to Solution.
09-03-2021 08:21 AM
Run certmgr.msc will open the Current Users certificate store, then expand Personal > Certificates and import the certificate there.
You will obviously have to do this for every user or use Windows As use a GPO to distribute to all users/computers.
Ideally you'd get a certificate issued by a public CA or if you have an internal CA use that.
09-07-2021 02:41 AM
Hi Rob,
thanks for the hints!
When I use the option in the AnyConnect client to accept the new
self signed certificate it will be stored in the 'Other People' section
in certmgr.
Thanks a lot!
09-03-2021 08:21 AM
Run certmgr.msc will open the Current Users certificate store, then expand Personal > Certificates and import the certificate there.
You will obviously have to do this for every user or use Windows As use a GPO to distribute to all users/computers.
Ideally you'd get a certificate issued by a public CA or if you have an internal CA use that.
09-07-2021 02:41 AM
Hi Rob,
thanks for the hints!
When I use the option in the AnyConnect client to accept the new
self signed certificate it will be stored in the 'Other People' section
in certmgr.
Thanks a lot!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide