03-31-2020 02:02 AM
Hello,
I have FTD 2110 and anyconnect VPN.
I have to renew the certificate for the VPN.
I have successfully added the new cert in the below path
Add Certificate Enrollment στα Objects -> PKI -> Cert Enrollment.
But when go to assign the cert to the device (Devices -> Certificates) i get the below error Fail to configure CA certificate
Any ideas?
Thanks and regards,
Konstantinos
Solved! Go to Solution.
04-01-2020 01:54 AM
03-31-2020 02:55 AM
Hi,
Most probably you have not imported the full certificate chain, including the CA and any intermidiate CA’s certificates.
Regards,
Cristian Matei.
03-31-2020 04:33 AM
03-31-2020 04:44 AM
Convert it to PEM.
03-31-2020 05:50 AM
04-01-2020 01:54 AM
04-07-2020 08:48 AM
Hi Konstantinos,
What is the process to add to the certificate the whole certification path? I'm attempting to do the same thing but I'm still getting the "Fail to configure CA certificate" status.
Thanks,
Glen
04-07-2020 10:20 AM
04-08-2020 07:51 PM
Konstantinos,
Thank you very much. I was able to create a single pfx file with the whole chain and got it working.
Thanks again,
Glen
09-22-2020 08:04 AM - edited 09-22-2020 08:05 AM
Konstantinos,
Thank you much for this solution. After a bit of struggling, this was the solution for me. For whatever reason, simply importing the root/intermediate CAs into the "Trusted CAs" objects just would not do it. I also did not have luck using the private key + CAs together using the "manual" function.
Using XCA, I imported all three certs, as well as the private key. After that I did export -> PKCS#12 chain (.p12). I then imported that cert file (with pass phrase) into the FMC and it properly imported without CA errors.
09-04-2022 11:33 PM - edited 09-04-2022 11:33 PM
Thank you. You solve my FMC problem. there is two PFX file type in XCA. PKCS #12 (.pfx) and PKCS #12 chain (.pfx)
I export as PKCS #12 Chain (.pfx).
12-11-2023 04:00 AM - edited 12-11-2023 08:15 AM
@mohsen.houshyar. (sorry to pick you but since you're the last person to post in this thread...)
Quick question regarding the private key part, where did you get that from? Did you generate it on XCA as well?
When enrolling a new certificate on FMC, there's a Key tab but I did not do anyting there and it's got "<default-RDA_key>".
thanks,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide