03-30-2017 12:48 PM - edited 02-21-2020 09:13 PM
03-30-2017 10:47 PM
Why don't you create the identity certificate on one of your machines, export it and the private key to a file, and then import the file in one go.
Then you don't need to generate the CSR on the ASA and interface that with your CA.
03-31-2017 04:19 AM
Hi Philip,
Thank you for making out time to respond to my question.
We tried to do that but was unsuccessful as we have 2 ASA.
When we try to take this approach that you mentioned, an error came up (error: high availability)
Thank you
03-31-2017 11:54 AM
What version software are you running on your ASAs?
03-31-2017 12:21 PM
I believe that its ASDM 7.6(2)150
03-31-2017 12:22 PM
What about the ASAs?
03-31-2017 12:42 PM
9.4(3)12
thank you
04-02-2017 01:04 PM
Sorry I forgot to ask, what model ASA are you using?
04-03-2017 06:15 AM
We are using the 5525 Model.
Thank you
04-03-2017 12:16 PM
I've imported certificates a lot of times, and never had an issue. So I am suspicious of the software version you are using.
asa944-5-smp-k8.bin is a gold star release for your platform. Would you be able to upgrade tot that?
https://software.cisco.com/download/release.html?mdfid=284143129&catid=268438162&softwareid=280775065&release=9.4.4%20Interim&relind=AVAILABLE&rellifecycle=&reltype=latest
04-03-2017 12:26 PM
That is possible but it will be a long process that i will hate to go through if its not the cause of the issue.
Things like change request and scheduling a downtime to do this are some of the things that will make the process long.
Do you have any document or something to show what step by step approach that you used to accomplish the ones that you did so that we can mirror that.
Thank you
04-03-2017 09:38 AM
Is this A MS CA?
if so then what kind of certificate template are you using to sign your CSR?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide