Core issue
This parse error is displayed if the VPN concentrator does not have a root Certificate Authority (CA) certificate installed.
Resolution
Regardless of whether Simple Certificate Enrollment Protocol (SCEP) or manual enrollment is used, the VPN concentrator must have a root CA installed if third-party certificates are used. In order to obtain and install the Secure Socket Layer (SSL) certificates, perform this procedure:
- Obtain and install the root CA certificate.
- Create an enrollment request for one or more identity certificates.
- Request an identity certificate from the same CA that issued the root CA certificate.
- Install the identity certificate on the VPN concentrator.
- Enable Certificate Revocation List (CRL) checking and caching.
- Enable Certificates.
Ideally, this procedure resolves the issue. Refer to Certificate Management for additional help on certificate enrollment.