02-03-2021 06:17 AM
Hello,
I am trying to onboard an ASA device in CDO.
I get the error
Certificate could not be retrieved for IPADDRESS:PORT
To which certificate it refers to?
How could I change it?
Solved! Go to Solution.
02-03-2021 06:39 AM - edited 02-03-2021 06:43 AM
Are you permitting http access from the CDO networks to the outside interface?
Example (the address below are the EU CDO servers):
http 35.157.12.126 255.255.255.255 outside http 35.157.12.15 255.255.255.255 outside http server enable 8443
02-03-2021 06:23 AM
It's referring to the certificate in use by ASDM for mgmt is used.
In my experience the ASA's self-signed certificate or a public signed certificate works, but a certificate issued by an internal CA (i.e. Windows CA) does not work.
02-03-2021 06:26 AM
Ok But I use the ethernet port 1/1 that has a public IP to connect to CDO.
I do not use the management port
What should I do?
02-03-2021 06:39 AM - edited 02-03-2021 06:43 AM
Are you permitting http access from the CDO networks to the outside interface?
Example (the address below are the EU CDO servers):
http 35.157.12.126 255.255.255.255 outside http 35.157.12.15 255.255.255.255 outside http server enable 8443
02-03-2021 06:58 AM
I had put these ones
52.25.109.29, 52.34.234.2, 52.36.70.147
I added the ones you mentioned but still I get the same
02-03-2021 07:18 AM
The certificate in ASA exists by default or I have to create it somehow?
02-03-2021 07:25 AM
Yes, it should have a self-signed certificate.
Do you have a trustpoint enabled on the outside interface?
Have you enable the certificate on the correct port and configured in CDO using the correct port (as configured on the ASA)?
ssl trust-point TP OUTSIDE
Run a packet capture and confirm traffic is being received.
02-03-2021 08:31 AM
Thanks for the help @Rob Ingram
It seems the issue was with the access on HTTP management.
I allowed everything temporarily and it worked.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide