cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
42081
Views
16
Helpful
18
Replies

Cisco AnyConnect::How to hide "Security Warning : Untrusted Certificate"

ROHIT SHARMA
Level 1
Level 1

Whenever I connect to my ASA using Anyconnect client, attached warning message always appear and there is no option to Trust it or import certificate so that it should not appear next time.

Anyone please help to make the option visible to trust certificate or make this warning go away.

I tried Anyconnect 3.1.05152 and the latest also.

18 Replies 18

Hey Community,

I'm using the anyconnect agent for authentication and posture, I had to renew the certificates on my node and did that via exporting a CSR and signed him with our sub-CA.

Unfortunately, all endpoints in the company show a "Security warning: Untrusted server certificate", I used an FQDN for the CSR and it seems to be ok but still, endpoints are not trusted with the new certificates.

any recommendation? 

WhatsApp Image 2022-11-10 at 19.50.11.jpeg

denis@cybecs.com if you look closely at the error it states "certificate is not identified for this purpose" - this means you've used the wrong certificate template on your CA to sign the certificate, which doesn't have the correct key usages.

Thank you very much, Rob, can you guide me on which template I should use? 

denis@cybecs.com not sure which CA you are using, but if Microsoft Certificate Authority - try the "Web Server" template, or another with Client/Server Authentication EKU (Extended Key Usage).