05-19-2021 02:11 AM - edited 07-05-2021 01:19 PM
Hi,
I have a 240AC device which is erroring when I try to check the software version.
Then error message is: Connection failed: 60. peer certificate cannot be authenticated with given CA certificate.
This worked initially, but not sure why this have changed.
Thank you in advance
05-19-2021 04:26 AM
- Exactly which command did you try ?
M.
05-19-2021 04:50 AM
Marce hi,
This is via the Web interface.
05-19-2021 05:55 AM
Have you tried a different browser or an older version of the browser?
Things that could have changed over time:
- browser security settings got stricter - this is happening all the time (so viewing pages which use self-signed certs becomes more difficult)
- device cert expired
05-19-2021 07:44 AM
I tried using different browsers, but still recieved the same error message.
05-19-2021 10:13 AM
- Could you post a screenshot ?
M.
05-20-2021 01:23 AM
05-20-2021 03:28 AM
This looks the same as https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv54258 / https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvm03931 although that is for Firepower. The point is that the Cisco website has changed their root certificate authority and the old device firmware doesn't recognise it. I doubt that there is an option to upload new root CAs on these devices so until there is a new version of firmware with a fix you'll have to do it manually:
Ideally open a TAC case to make sure they are aware of the problem on this product (they might already have a bug for it but I didn't find one) to make sure it does get fixed in the next release.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide