cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4760
Views
0
Helpful
3
Replies

Cisco Anyconnect and Aladdin eToken

gaigl
Level 3
Level 3

Hello,

I want to authenticate Clients on an ASA5510 (8.4.(2))with a Certificate on a Aladdin eToken.

If I connect with the Browser (IE) everything works fine, the eToken Software asks for the Certificate and the Passwort and downloads the client-profile. AnyConnect-Connection is established.

If I connect directly with the AnyConnect Client (ver 3.0.4235) no Cerificate will be used and so there is an Errormessage "No valid certificates available for authentication"

Client is Win7, but the same Problem on WinXP with full admin-rights

It seems that the Anyconnect-Client can't find the Certificate-Store.

Any Idea?

Thank You.

it's not only with Aladdin eToken, same Problem with Standard Microsoft Software Certificate (.pfx) installed in local Cert-Store

1 Accepted Solution

Accepted Solutions

sjbdallas
Level 1
Level 1
3 Replies 3

sjbdallas
Level 1
Level 1

Did you configure the section of the XML profile doc to reference the certificate?

http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect20/administrative/guide/admin7.html#wpmkr999934

Hello Steven,

thank you for the hint, but a Question: are we in this section talking about the client-certificate for authentication or the ASA SSL-certificate?

in this section I've configured under "Distinguished Name" the CN of the SSL-certificate (at the bottom of the site).

I can see at the top under "Extended Key Usage" a Checkbox for ClientAuth, but I thought, this would only affect the SSL-certificate.

OK, now it works, it's the Client-Certificate

Thank you very much