07-26-2010 10:58 PM - edited 02-21-2020 04:45 PM
Hello,
Situation:
Could not find any help in the
Has anybody experienced such a behaviour?
Facts:
I wonder if there are Security Settings within the Internet Explorer which cause this error. The ASA web access does not work, too. (It asks for the personal certificate, then it won't continue, telling "This page cannot be displayed" in IE 8)
07-28-2010 10:19 AM
Possibly looks like SSL Handshkae failure, since you cannot connect from the browser also. What client certificate are you presenting to the ASA ? Make sure that the EKU (Enhanced Key Usage) extension in the Client certificate includes the "Client Authentication" capability.
A packet capture for the SSL failure will also help.
Does browser access through any other browser works ? (E.g. Firefox)
08-05-2010 06:36 AM
Did you get an answer for this? I'm seeing a similar issue.
08-05-2010 06:48 AM
Hello Steven,
no, I am sorry. It turned to be a problem if exactly one computer and we decided not to follow this up anymore.
Regards
Holger
08-05-2010 06:51 AM
Steven,
I had an issue first to install the Root certificates on the Windows 7 machines. Instead of using "Select storage automatically" you have to select it manually (Trusted Root Certification Authorities and if this is not enough, a second time into Intermiediate Cert. Auth.)
Maybe this helps for you
Regards
Holger
01-09-2011 09:31 AM
Hi Steve,
Just wondering if you were able to resolve this issue as I am having the same issue ?
I have gotten around the issue by deleting the user in ACS as we use ACS as the radius server. The user is again dynamically created in ACS and the certificate issue disappears, however before deleting the user, I can log in fine from another workstation with my credentials and the issue is not present when logging from a different workstation. There are new anyconnect clients that seem to resolve some certificate issues, but that did not help either. Tried deleting cached and profiles and that did not help either. Deleting the user from ACS is not a good solution.
07-30-2012 08:49 AM
For myself the error was related to Authentication under the Connection Profile.> Advanced
Under the Connection Profile it was configured to Pre-fill Username from Certificate but Use script to select username was configured with -None- so caused the error.
A few years late but hope this helps someone.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide