10-27-2020 06:49 AM - edited 10-28-2020 06:51 AM
Hello,
I'm relatively new to managing Cisco ASA units having worked with other vendor security products. I'm working on something I thought would be relatively simple but I'm unable to install/import a GoDaddy issued certificate via the ASDM. I was able to generate the CSR and create the certificate without issue.
The error message I am receiving is attached.
I'm sure the key part of this issue is the "configure 'no ca-check' command in the trust point configuration but I haven't been able to find the necessary instructions to accomplish this.
Any and all help is appreciated.
Solved! Go to Solution.
10-28-2020 11:21 AM - edited 10-28-2020 11:34 AM
Please go into that trust point from CLI, and issue the command no ca-check, or untick the Enable CA flag in basic constraints extension checkbox on ASDM window when you add the cert, and try again.
10-28-2020 03:33 AM
There is no attached screenshot with the error.
10-28-2020 06:39 AM
10-28-2020 08:49 AM
Did you import the full chain of GoDaddy certs on the firewall? including the root CA certs?
10-28-2020 09:01 AM
I imported the GoDaddy cert just now and that worked fine. There were three files provided to me in the ZIP file I downloaded from GoDaddy. I attempted to import the other two and now I'm receiving this error message which is slightly different.
Note that the files are the same file name with a different file extension. One is a .CRT and the other is a .PEM file.
10-28-2020 11:21 AM - edited 10-28-2020 11:34 AM
Please go into that trust point from CLI, and issue the command no ca-check, or untick the Enable CA flag in basic constraints extension checkbox on ASDM window when you add the cert, and try again.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide