cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4827
Views
0
Helpful
1
Replies

ASA-3-716160: Failed to create SAML authentication request. reason: Failed to load private key

DIANNE DUNLAP
Level 1
Level 1

I've installed a CA (not self-signed) cert on ASA running 9.9(2) using SAML for authentication.  The negotiation between the Anyconnect client (PC and Mac) work ok till the point where there's an Anyconnect error "Failed to generate SAML AuthnRequest".  This is at the point where the ASA should be sending the request to the iDP.  

 

Debug webvpn saml 255 shows:

%ASA-3-716160: Failed to create SAML authentication request. reason: Failed to load private key..

Jan 21 21:15:48 [SAML] build_authnrequest: Failed to load private key.

Jan 21 21:15:48

[SAML] build_authnrequest:

SAML AUTH: authentication pending

 

Both the identity and CA certs loaded ok and there's no indication as to what key cannot be loaded.

The ASA-3-716160 error message is nowhere in Cisco documentation and not found on a Google search, i.e. this is apparently the first time the message has been seen.

1 Reply 1