08-13-2011 11:35 PM - edited 02-21-2020 05:31 PM
hi,
im using my cisco 2801 as sslvpn router, lately i have encouter this error
"a certificate problem has been encountered . A VPN connection will not be established"
im using the below version:
RTR01#show webvpn install status svc
SSLVPN Package SSL-VPN-Client version installed:
CISCO STC win2k+
2,5,2019
ios:
c2801-adventerprisek9-mz.124-24.T.bin
certificate config:
crypto pki trustpoint TP-self-signed-895184870
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-895184870
revocation-check none
rsakeypair TP-self-signed-895184870
!
!
crypto pki certificate chain TP-self-signed-895184870
certificate self-signed 01
30820249 308201B2 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 38393531 38343837 30301E17 0D313130 38313430 36303734
305A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3839 35313834
38373030 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100
BD1462D7 E34B7CCD D8187639 11CDD1BC 6048C846 3A3CF5D3 9A917323 2C336029
117D5756 79C5FB81 4ECFBF99 01428192 76D8BC03 E2A46BD1 4A65556A B7E668E9
06CF1903 F7D06809 139E165B 5791146A 2ACA28C3 98DB5A00 74892756 1B9ACD45
06CD20DA A43DCF8C A609601D F8D8104B C6738DA9 B39FAE71 6BA6BAE7 93E775AF
02030100 01A37330 71300F06 03551D13 0101FF04 05300301 01FF301E 0603551D
11041730 1582134D 434D5254 5230312E 686F6D65 69702E6E 6574301F 0603551D
23041830 16801497 62C23E12 D4E91CED 2E7A1BBE 9A9C5C96 43CB7830 1D060355
1D0E0416 04149762 C23E12D4 E91CED2E 7A1BBE9A 9C5C9643 CB78300D 06092A86
4886F70D 01010405 00038181 008E270B F1D4ECD9 9E03EF72 F0A33F0B 1DB46504
E5627031 CE766636 382631DC 3F42B776 D45208EC B966AABD 5D5477B3 F0FDBE02
0A02D69E 12ADF7C4 A3164AE7 A1F8D0D8 8FC9B82A D57D22C4 DFB171BB CB9ADB88
DA57B62B 2B138B75 77265E02 A01748F7 0F8E31F2 168821D8 6A13F3B3 E7727B8D
7BF69B67 90E87A1D 5F019BB0 C9
quit
debug output
Aug 14 06:26:39.838: CRYPTO_PKI: Identity selected (TP-self-signed-895184870) for session 10034
Aug 14 06:26:39.838: CRYPTO_PKI: unlocked trustpoint TP-self-signed-895184870, refcount is 0
Aug 14 06:26:41.606: WV: sslvpn process rcvd context queue event
Aug 14 06:26:41.610: WV: sslvpn process rcvd context queue event
Aug 14 06:26:41.854: WV: sslvpn process rcvd context queue event
Aug 14 06:26:41.854: WV: Entering APPL with Context: 0x69AD87B8,
Data buffer(buffer: 0x697D28E8, data: 0xEF2A0AF8, len: 714,
offset: 0, domain: 0)
Aug 14 06:26:41.854: WV: http request: /test.html with cookie: Cookie: webvpn=00@2011859458@00000@3522291568@3460200441@sslvpnadmin; webvpnc="p:t&bu:/CACHE/webvpn/stc/&iu:1/&sh:EBD974755830BECA35CD46BB1E0FA8379678E9D4&"; webvpnlang=1; tree_bkmkTree_state=3
Aug 14 06:26:41.854: WV: [Q]Client side Chunk data written..
buffer=0x697D2088 total_len=1009 bytes=1009 tcb=0x6724B698
Aug 14 06:26:41.854: WV: Client side Chunk data written..
buffer=0x697D20A8 total_len=134 bytes=134 tcb=0x6724B698
Aug 14 06:26:41.858: WV: sslvpn process rcvd context queue event
Aug 14 06:27:43.253: CRYPTO_PKI: Identity selected (TP-self-signed-895184870) for session 10035
Aug 14 06:27:43.257: CRYPTO_PKI: unlocked trustpoint TP-self-signed-895184870, refcount is 0
Aug 14 06:27:45.089: WV: sslvpn process rcvd context queue event
Aug 14 06:27:45.093: WV: sslvpn process rcvd context queue event
Aug 14 06:27:45.257: WV: sslvpn process rcvd context queue event
Aug 14 06:27:45.257: WV: Entering APPL with Context: 0x69AD94A8,
Data buffer(buffer: 0x697D28E8, data: 0xEF2368D8, len: 714,
offset: 0, domain: 0)
Aug 14 06:27:45.257: WV: http request: /test.html with cookie: Cookie: webvpn=00@2011859458@00000@3522291568@3460200441@sslvpnadmin; webvpnc="p:t&bu:/CACHE/webvpn/stc/&iu:1/&sh:EBD974755830BECA35CD46BB1E0FA8379678E9D4&"; webvpnlang=1; tree_bkmkTree_state=3
08-14-2011 12:37 AM
now i updated the pkg to
2.53046
and im facing different error:
the certificate on the secure gateway is invalid. a vpn connection will not be established
kindly advice.
08-14-2011 09:12 AM
now i can connect using pkg
2.3.2016 it seem 2.5 version and up i cant connect reciveing the errors above
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide