10-13-2012 10:29 AM - edited 02-21-2020 06:24 PM
Hi, after I have installed AnyConnect VPN client, every time that I connect the client ask to install certificate.
I already installed the certificate in the Trusted Root Certification Authorities with no sucess.
I configured the AnyConnect with LDAP option with memberof option and its working fine, but the certificate message is displayed every time I do login. Any idea how I can install it permanently?
Thanks
Solved! Go to Solution.
10-15-2012 06:46 AM
here is a sample config:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808efbd2.shtml
Don't worry about the fqdn command as you are not using fqdn. Under "subject-name" command, configure CN=
10-14-2012 03:45 AM
What is your certificate CN name, and also how do you connect with the AnyConnect (using IP Address or FQDN)?.
What exactly is the error that you are getting, can you share a screenshot of it?
10-14-2012 05:56 AM
I am using the public IP Address to connect.
Every time that I connect the client ask to install certificate:
I already installed the certificate in the Trusted Root Certification Authorities with no sucess.
Thanks
10-14-2012 01:28 PM
Can you also share the screenshot of the certificate?
If your CN= within the certificate doesn't match the URL that you are trying to connect, you will get that error.
Try connecting using the same name as the CN= within the certificate, then you wouldn't get any of the error anymore.
Or, create the certificate so that the CN= says "CN=
10-15-2012 06:41 AM
I checked in the Trusted Root Certification Authorities, the certificate has the ASA inside IP Address:
How can I create the CN= that says "CN=
Thank you
10-15-2012 06:46 AM
here is a sample config:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808efbd2.shtml
Don't worry about the fqdn command as you are not using fqdn. Under "subject-name" command, configure CN=
10-15-2012 07:32 AM
Jennifer, I configured the CN to the public IP Address as you said, now the certificate is no more asking to install.
Thank you very much:)
10-15-2012 07:19 PM
Great, thanks for the update and good to hear it's all good now.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide