08-02-2012 10:53 AM
Hello,
I'm changing SSL VPN from aaa authentication to both aaa and certs, Server 08 CA, 8.2 ASA 5510, ssl client 2.5.1025 and Windows 7 users. My question is what should be the template of the id cert that I receive from CA.
Thanks,
Solved! Go to Solution.
08-02-2012 12:07 PM
Hamood,
You can use a web server template for the certificate for the ASA.
Thanks,
Tarik Admani
*Please rate helpful posts*
08-02-2012 11:04 AM
Hamood,
You can use the user template, here is a guide that shows you how to configure scep and it shows the template that the ASA generates for its anyconnect clients. This example shows that you can use the same client cert for both vpn and wireless network authentication.
BYOD guide -
Template configuration -
Thanks,
Tarik Admani
*Please rate helpful posts*
08-02-2012 11:49 AM
Thanks Tarik,
The link shows the template for the client. I will need that cert to be pushed to the Windows 7 clients via GPO etc. What should be the template for the cert that I need on the ASA?
Thanks.
08-02-2012 12:07 PM
Hamood,
You can use a web server template for the certificate for the ASA.
Thanks,
Tarik Admani
*Please rate helpful posts*
08-03-2012 07:52 AM
Thanks Tarik,
So I modified the User template and pushed a cert created by the new template to a Win XP client. My ASA has a web server template cert from the same 2008 CA, but I can not connect, I get Certificate Validation error. On the anyconnect log I see it goes through all the certs in the machine store and then says that no valid cert was found. Also the log has entries saying it received unrecognized content type and Global_Error_Unexpected. I will regenerate and reinstall all the certificates, may be upgrade the anyconnect image and try again.
08-03-2012 09:00 AM
Hamood,
If you pushed the cert through to GPO then it may have placed it in the user account store. Please use mmc to see if you can install this cert in the machine store and test again.
Thanks,
Tarik Admani
*Please rate helpful posts*
08-03-2012 09:42 AM
It did get pushed into the user store. I imported it into the machine store. Still got validation error.
Thanks.
08-03-2012 09:54 AM
Hamood,
Do you have "ssl certificate-authentication interface interface-name port port-number"
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s8.html#wp1514061
Thanks,
Tarik Admani
*Please rate helpful posts*
08-03-2012 10:21 AM
Thank you for helping me Tarik,
I do have that command configured on the outside int, port 443.
08-03-2012 01:45 PM
Can you post your running configuration? We're you able to authenticate using password before?
Sent from Cisco Technical Support iPad App
08-03-2012 02:53 PM
08-03-2012 03:27 PM
See if you can download the profile editor and follow these steps:
Are you an admin on the computer? See if forcing certificate store override allows you to connect. Also can you post a screenshot of the error and a screenshot of the certificate details.
If the above step doesnt work then collect a dart bundle so we can see what is going on.
Thanks,
Tarik Admani
*Please rate helpful posts*
08-06-2012 03:08 PM
08-06-2012 05:41 PM
Hemood,
Can you try to manually request a user cert from the CA and then install that and the private key on the laptop? Give that a try and let me know what happens.
Thanks,
Tarik Admani
*Please rate helpful posts*
08-07-2012 07:51 AM
Hi Tarik,
That worked. I requested a certificate from the CA web interface manually and installed it on the laptop.
Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide