cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
560
Views
0
Helpful
1
Replies

Can no longer Import Base64 PKCS12 in ASA9.16 Code

Douglas Holmes
Level 1
Level 1

I have been installing certificates on my ASA's using Base64 PKCS12 files since 9.1 code using command line.  Never a problem.  Upon upgrading to 9.16 code, I can no longer enter my Base64 file via command line.  It works in ASDM.  I read and re-read the notes for 9.16, could not find this addressed.  Receive the following error:

 

ERROR: Unable to convert the base 64 encoded pkcs12.
golly(config)#

 

What does work.  Importing in the ASDM.  However this defeats the purpose of a complete configuration using only command line.  Installing the certificate trustpoint in 9.12 and then upgrading to 9.16 code.  Once the Certificate is installed, AnyConnect works like always. 

 

I made an example PKCS12 on an openssl CA that I just setup. 

 

crypto ca import VPN-TRUST pkcs12 13qeadzc!#QEADZC
MIIGzgIBAzCCBpQGCSqGSIb3DQEHAaCCBoUEggaBMIIGfTCCBT8GCSqGSIb3DQEH
BqCCBTAwggUsAgEAMIIFJQYJKoZIhvcNAQcBMBwGCiqGSIb3DQEMAQYwDgQI84XT
bjwAaGkCAggAgIIE+Nxvu0qCj0xCq1lFofrJ//TM66XpYCxwhIsSggXO4zclPviD
FcpdxnevOGGw5ZchdI/o2vh4Au2T7krta52CnuvzDnjE79eqrtXXIY7++9ciXGFh
SjXr6xUK31ByHa7CDsWyHVrWTCOHIWFcOsJZ4kC4TSspWg2sCwab+mQBMz4NqDuF
wfr9NzM83X1DD28XXoXNPfBB37gAsgI1Fnc9izxRtXJJhyxJhV+an9SXWwKHUE8V
Uotf4LmEkxZyVLu+9D4RE5y9QXFalp++n+4n71ldFMLxcCwZ//TgzYEKCaCvP0Em
eM81f7KnFujOhKSpHzXKsMS/M18wyasepUjy02iMlr7nVxbW2XuVcyVUFfUVmu3b
2dgpRhqJNqcVvpVD10QlCqDY52KDVWC2XNkWbwtw6MBbOx5z3oD/O9uDgeHHaFYQ
TR1NWKzjcXaXDZq8hFh60rjQnSnuEM9/3xSU7M3ejbW6j/NUM4WMP1UwfN2afhTe
FJBZA+IwoXuS1Uvj5kWlvTfW6EmyT4z5YeJArYzOfLJHekAfeu39GkH6maXJJrCC
0r7rwVU347/BU1IVdX+AMDH3mriYjM731aE/3H12L4WySEAS1yc1uS5eXHUf6pZw
vTS8qhVVNUnIT+RDUxcWaYEl608vzboAOJXHGxNp2/avwqB7vxbmSM2D+UlEP1iI
NheOEzXyjep3CIDAv8Tctbt/gSAI2/5y8tEESD/oCbe9k+LFONdHGIIYypKUkeT/
wieaXkEhDICugfAZ8YboZ9mkwN9vqH1np5hU7ayKRHSPgLOK5DVHQM0ZbCieu1GN
kfp8ZM3JOtsmGJvLMsvZKbyTIHJUfMRA3bJGbyxeh42ZJEEzZLW4gxaCAjeUxTYK
LCbpq7Z0fU8ytGwhmJGMU8taPx3Y/xlr/Y6/pk6GFrgnpYJ0yuHAEQPavhyoOyN3
RHhg+QXYRQE/7b/oki5cWnkkV52oGNUcfTFWQRUSx9V9WD439sxwcJwxYnlULUYW
H4X2eDzn6hHQfxZK6SOyVL1dkPm0GgxxVnT9tSuAloRrLgYeKzlKnXB/r+u4Y5IX
kfaLdTAd9uizm2R9OCYAfTOfhIChyYyIbymtHD0VXWFmcECUd6+fm378hipdIxHH
sD7V/AZrv0BIroJcge0+m/5Kp8HUCLGAWAIx5eS4O4wItDLetWLrpsx3+Sc/73oJ
5C5+HTqMUonVxiViBQM2eg5wzLeFrlJ+wjakI9RYwXE53tQyYzvYbZj0fqr7Uohd
ACKf/xFjfKXBOjwa/iX92/+eZKEtlUsN+ynMHTkv0Wxv8n6BcrdGiBJ3wzv7lnm0
/BmOZtdRNPk7BMb2TDUTbAF6D+tbBi8zn8swl5emtdB8HL3Msdl/YB44gyGyEqME
vf3DlM/y/XxhhUZpGvW02SgT4TYj5AAy33f9/z/1z75rz6zBjX1bsFc5gn6Td2S7
eZHadEKC46TvyPZ85CFq5cU4QpldDjsjZS8W1Sm0IWb878jC7Ztq70PCeuFH3qpy
nhn0U5ggA9TwXR+snvZ+i1ElCk+ya/gHcoZkrIkydFmCzDNZfBHensx+beO0GrXT
uxSTLZDwU8Q1afjfWfUFyinRkk5dSqwnxKYYJ0dlkOHYlgsO00aHGmXGUCi7P62Y
aqXuUAlrjQo/eh3nnYWbztj0l3GITSlbnrWKiy4GI03DsRrIBDCCATYGCSqGSIb3
DQEHAaCCAScEggEjMIIBHzCCARsGCyqGSIb3DQEMCgECoIHkMIHhMBwGCiqGSIb3
DQEMAQMwDgQIXylewXsQoQgCAggABIHAygVwSAKg6BNpp8AHnbsIPQ05tjzHhRoT
Osnjeqi49BBRqCkzLqtyYtIlIThrFABJFmRhprRYXcq4yXvROSg+Fj3ZJ7DCAybD
ubqeiDvdR4CKHZDCb9xBtU87L2yHVxbaqIKh9ygdspO3isKXQ3UJa6PWupItN8M8
zWXRK37TxG628fN/yJ8KxtR6lUwPCwEkovP/+FldWi2R8+qJpG3ymiE6CAv/LfFu
erHNs1D0vUtmavUi9PsqSdkw7W0HeUWvMSUwIwYJKoZIhvcNAQkVMRYEFBEDIXya
e1zvTnhuEio4y89NueEiMDEwITAJBgUrDgMCGgUABBQ0E5hc/xGHs5YTb21BvXo7
lSwjzgQIzEwMf8eh3ZACAggA
quit

 

I have attached the PKCS12 file that represents the above base64.  Any ideas on what the change might be or how to correct this?  Thanks.

1 Reply 1

Douglas Holmes
Level 1
Level 1

I guess nobody else is having this issue.  I haven't found a solution yet.  Going to open a tac case to see if I can get an answer.