08-08-2015 08:28 PM - edited 03-11-2019 11:24 PM
Hi I created a certificate by ASDM wizard. I got the certificate detail, Please see screenshot in attachment, which says:
"This CA Root certificate is not trusted because it is not in the Trusted Root Certification Authorities store."
My question is how to place the certificate in Trusted Root Certification Authorities store in order for This CA Root certificate is not trusted is trusted ?
Can we say Trustpoint is Trusted Root Certification Authorities store?
Thank you
08-10-2015 09:00 AM
Hi showipospf!
You can go to:
Configuration -> Device Management -> Certificate Management -> CA Certificates
There, you can add the CA Root certificate. This one is usually included in the package sent by the 3rd party Certificate Authority.
- Cesar.
08-10-2015 09:26 AM
In your case the screenshot is from a client. Presumably they are connecting to as ASA (at 12.1.1.1) that uses a self-signed certificate.
So the "Trusted Root Certification Authorities store" here is on the client PC. To avoid that message, the certificate must be imported locally on the PC and you must override the default selection to tell Windows to not simply trust the certificate but to trust the issuer as a certification authority.
The easiest way to do that is to browse to the ASA via https. Use your browser tools to copy the certificate locally to your PC. Right click on that downloaded file and "Install Certificate". the Certificate Import Wizard will popup. Follow the prompts making sure to choose the right store (screenshot below).
Once you're done, you can inspect the updated store if you like by using the certmgr.msc MMC plug-in for certificate management.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide