most likely this issue is : 
[1]WSA needed the SSH host key updated 
[2] WSA was using the wrong username for the CTA push
Check Connectivity
Follow these steps to check connectivity:
1. Log in to the CLI of the WSA.
2. Enter the logconfig command.
3. Enter the hostkeyconfig command.
4. Enter the scan command.  (Maybe you need to delete > commit > then Scan)
5. Enter the CTA server hostname: etr.cloudsec.sco.cisco.com
6. Choose All when asked for the SSH protocol type.
7. Enter Y when asked whether the CTA host key should be added.
 
 
it is safer to open a TAC case 
					
				
			
			
				
	Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++     If you find this answer helpful, please rate it as such    ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++