cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1546
Views
5
Helpful
6
Replies

ECDSA Certificate upload for HTTPS proxy.

VKi67464
Level 1
Level 1

Dear All!

 

I've upgraded to 12.0.1-334

 

https://www.cisco.com/c/dam/en/us/td/docs/security/wsa/wsa_12-0/WSA_12-0_Release_Notes.pdf says:

ECDSA Certificate upload - The appliance now supports the uploading of ECDSA certificate for HTTPS proxy.

 

But when I try to upload it, the appliance says:

Error — Certificates with ecdsa-with-SHA384 signature algorithm are not allowed

 

Any thoughts? Isn't this supported yet then?

 

Thanks

6 Replies 6

opryluts
Cisco Employee
Cisco Employee

Hi,

 

Just to better understand the steps you took... How did you generate/upload the cert?

I tested it in the lab and got the same

I'll investigate it...

 

Do you see the same issue for other SHA algos? Or only SHA384

our prod CA is SHA384, I did not test it with others as I just updated the WSA but I'll test it if I have some time to install a test CA

 

*I've generated the cert from the downloaded request and tried to upload a new cert in PEM with the key. both times same error message

Thanks for the details.

I raised CSCvv04912 for it. As a workaround, you can try using SHA<=256

Please vote/mark solved if you find it helpful

VKi67464
Level 1
Level 1

12.5.1-035 is affected too.

12.5.1-043 - still not working.

14.0.1-040 - still not working

14.0.2-012 - still not working

CSCvv04912 has been marked as duplicate to CSCvv04912

CSCvv04912 has been closed as "fixed" yet as my previous post shows, it's still not.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: