cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7159
Views
21
Helpful
11
Replies

FMC "Fail to configure CA certificate"

Hello, 

 

I have FTD 2110 and anyconnect VPN. 

I have to renew the certificate for the VPN.

I have successfully added the new cert in the below path 

Add Certificate Enrollment στα Objects -> PKI -> Cert Enrollment.

But when go to assign the cert to the device (Devices -> Certificates) i get the below error Fail to configure CA certificate

 

Any ideas?

 

Thanks and regards, 

Konstantinos

1 Accepted Solution

Accepted Solutions

The solution was to add to the certificate the whole certification path. Then it worked.
Regards,
Konstantinos

View solution in original post

11 Replies 11

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

Most probably you have not imported the full certificate chain, including the CA and any intermidiate CA’s certificates.

 

Regards,

Cristian Matei.

Hello Cristian,

Indeed the chain was not present.
I installed the root and intermediate in the External Certs. It did not work though it showed the same error.
I installed them in the Trusted as well, but the same.
When I did the cert enrollment the file had .pfx is that ok?

Regards,
Konstantinos

Convert it to PEM.

And the enrollment type?

The solution was to add to the certificate the whole certification path. Then it worked.
Regards,
Konstantinos

Hi Konstantinos,

 

What is the process to add to the certificate the whole certification path? I'm attempting to do the same thing but I'm still getting the "Fail to configure CA certificate" status.

 

Thanks,

Glen

Hello Glen,

Well, I used the program xca.
I imported the three certificates (root, intermediate and the mentioned one) and the private key and exported them as one. I think it needs .p12 suffix.

Regards,
Konstantinos

Konstantinos,

 

Thank you very much. I was able to create a single pfx file with the whole chain and got it working.

 

Thanks again,

Glen

Konstantinos,

Thank you much for this solution.  After a bit of struggling, this was the solution for me.  For whatever reason, simply importing the root/intermediate CAs into the "Trusted CAs" objects just would not do it.  I also did not have luck using the private key + CAs together using the "manual" function.
Using XCA, I imported all three certs, as well as the private key.  After that I did export -> PKCS#12 chain (.p12).  I then imported that cert file (with pass phrase) into the FMC and it properly imported without CA errors.

Thank you. You solve my FMC problem. there is two PFX file type in XCA. PKCS #12 (.pfx) and PKCS #12 chain (.pfx)
I export as PKCS #12 Chain (.pfx).

atsukane
Level 1
Level 1

@mohsen.houshyar. (sorry to pick you but since you're the last person to post in this thread...)

Quick question regarding the private key part, where did you get that from? Did you generate it on XCA as well? 

When enrolling a new certificate on FMC, there's a Key tab but I did not do anyting there and it's got "<default-RDA_key>".

thanks,

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card