07-14-2015 02:50 PM
Hi all
Today i have a serious problem because i renewed my ssl certificate for a vpn service
I have the same ssl cert for two firewalls: ASA 5515-x Version 8.6(1)2 and ASA 5505 Version 8.2(2)
The new certificate is in PKCS12 format (certificate.cer + privkey.key + pfx-password) = certificate.pfx
The pfx file was imported and applied successful in the asa 5515-x without problems but not in the asa 5505, when y tried to import the .pfx file the asa 5505 show the follow error: "ERROR: Import PKCS12 operation failed"
I think that could be a incompatibility of the 5505 firewall with the signature algorithm sha256RSA of the new certificate file because the old certificate was a sha1RSA signature algorithm
I need know if somebody known how i can fix this issue.
Thanks friends!!
Solved! Go to Solution.
07-14-2015 09:44 PM
You need to have active contract associated with your cco login to download software from cisco website
HTH
Abaji.
07-14-2015 09:30 PM
Hi,
If you know the issue is due ti sha256RSA signature algorithm, you need to upgrade the ASA5505 to 8.2.4.X
HTH
Abaji.
07-14-2015 09:41 PM
Thanks, according with read article i need update from my current version 8.2.2 to 8.2.3.9 for get support for sha256RSA, the question is if the upgrade for the firmware is free or i have to buy the firmware from cisco support?
Thanks!!!
07-14-2015 09:44 PM
You need to have active contract associated with your cco login to download software from cisco website
HTH
Abaji.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide