cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1040
Views
0
Helpful
3
Replies

ASDM Certificate Installation with no CSR shown in ASDM

babylon5
Level 1
Level 1

My ASA is going to be used as a VPN concentrator. I need to have an ID certificate applied to an interface.

I created the Trustpoint. I generated a CSR. I sent the CSR to our ID Cert provider.

When I went back to the ASA the pending Trustpoint information (under Configuration > Device Management > Certificate Management > Identity Certificates) that would have allowed me to install the certificate is no longer there.

How do I import this valid certificate and associate it with the proper Trustpoint.

Thanks,

Will

1 Accepted Solution

Accepted Solutions

Craig Lorentzen
Cisco Employee
Cisco Employee

Hello babylon5,

You will want to recreate the trustpoint, using the same information used previously.  The most important thing being that you select the same rsakeypair that you selected/created the first time.  As long as the RSA keypair matches things should be fine.

Then Authenticate the trustpoint with the certificate signer...and finally install your new certificate.

If you do not remember the original RSA key, you should be able to request that they sign another CSR in place of the one you just used so that you can get the proper public key.

-Craig

View solution in original post

3 Replies 3

Craig Lorentzen
Cisco Employee
Cisco Employee

Hello babylon5,

You will want to recreate the trustpoint, using the same information used previously.  The most important thing being that you select the same rsakeypair that you selected/created the first time.  As long as the RSA keypair matches things should be fine.

Then Authenticate the trustpoint with the certificate signer...and finally install your new certificate.

If you do not remember the original RSA key, you should be able to request that they sign another CSR in place of the one you just used so that you can get the proper public key.

-Craig

That is what I was afraid of. I have done that before, but I had hoped there was a better way.

Thanks,

Will

Thank you Craig, It works for me :)