cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Microsoft CA RSASSA-PSS Algorithm Issue with ASA

2193
Views
0
Helpful
0
Comments
Contributor

      If you create a Microsoft Root Certificate Authority (CA) with Windows Server 2008 and create a CAPolicy.inf file, you have to remove the AlternateSignatureAlgorithm=1 for the certificate to work with the Cisco ASA 8.4(7).  If the AlternateSignatureAlgorithm=1 is in the CAPolicy.inf file, the root certificate will be created with the algorithm = RSASSA-PSS. If you remove this from the CAPolicy.inf file, the algorithm will be RSA SHA.

I ran into this issue in a Microsoft guide.  The notes does say that AlternateSignatureAlgorithm will not work with Windows XP client computers.  I have also seen that it will not work with Windows 2003 servers. 

When trying to add a CA to the ASA from ASDM, this is the error:

 

 

Thanks,

Alex