10-17-2014 05:45 AM - edited 02-21-2020 07:53 PM
Whenever I connect to my ASA using Anyconnect client, attached warning message always appear and there is no option to Trust it or import certificate so that it should not appear next time.
Anyone please help to make the option visible to trust certificate or make this warning go away.
I tried Anyconnect 3.1.05152 and the latest also.
Solved! Go to Solution.
11-11-2022 10:38 PM
Hey Community,
I'm using the anyconnect agent for authentication and posture, I had to renew the certificates on my node and did that via exporting a CSR and signed him with our sub-CA.
Unfortunately, all endpoints in the company show a "Security warning: Untrusted server certificate", I used an FQDN for the CSR and it seems to be ok but still, endpoints are not trusted with the new certificates.
any recommendation?
11-11-2022 11:32 PM
denis@cybecs.com if you look closely at the error it states "certificate is not identified for this purpose" - this means you've used the wrong certificate template on your CA to sign the certificate, which doesn't have the correct key usages.
11-11-2022 11:48 PM
Thank you very much, Rob, can you guide me on which template I should use?
11-12-2022 12:03 AM
denis@cybecs.com not sure which CA you are using, but if Microsoft Certificate Authority - try the "Web Server" template, or another with Client/Server Authentication EKU (Extended Key Usage).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide