01-25-2014 06:17 AM - edited 03-11-2019 08:35 PM
Hello everybody,
I am having an issue with using my own CA.
I have the certificates from the CA and sub-CA at hand in all kinds of formats (.der, .pem, .p12)
As mentioned in Cisco Documentation I now have to authenticate the trustpoint with
crypto ca authenticate MAINCA
where the trustpoint-name is the same as the one from creating a trustpoint just a little earlier.
The process is, however, aborted with:
% Error in saving certificate: status = FAIL
I started a debug as well - but I don't get it
CRYPTO_PKI: can not set ca cert object (0x701)
CRYPTO_PKI: status = 65535: failed to process RA certificate
CRYPTO_PKI: Cleaned PKI cache successfully
CRYPTO_PKI: Starting to build the PKI cache
CRYPTO_PKI: Failed to retrieve router cert
CRYPTO_PKI: Failed to cache certificate chain for the trustpoint MAINCA or none available
CRYPTO_PKI: Failed to retrieve trusted issuers list or no trustpoint configured
Can somebody clear the sky, please?
01-26-2014 11:31 PM
AFAIK the ASA does not handle CA hierarchy. You can use the sub-CA in your trustpoint. You may create another trustpoint for the root CA but it's not necessary.
03-26-2014 10:30 AM
I'm having the same issue.
Did you find a way to load your Certs?
Were they using SHA256 by any chance?
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide