Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Cisco: NSP

ASA wild card cert...

 

 

Cisco nsp RSS feed   Index | Next | Previous | View Threaded


svoll.voip at gmail

Jul 5, 2012, 8:37 AM

Post #1 of 4 (443 views)
Permalink
ASA wild card cert...

I have exported from one ASA and would like to move to a second ASA our
Wild card cert. It looks like the export / import went well. I can even
see in IE that the cert is my *.domain.com but I'm still getting a Cert
Error. "This Certificate cannot be verified up to a trusted certification
authority" What did I miss?

Thanks

Scott

ASA 8.4.4
_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


rwest at zyedge

Jul 5, 2012, 8:55 AM

Post #2 of 4 (411 views)
Permalink
Re: ASA wild card cert... [In reply to]

Did you get the entire chain as part of your export, sounds like you're missing an intermediate cert? Do you see a difference between the ASA's when issue 'show crypto ca certificate'?

-ryan

-----Original Message-----
From: cisco-nsp-bounces [at] puck [mailto:cisco-nsp-bounces [at] puck] On Behalf Of Scott Voll
Sent: Thursday, July 05, 2012 11:38 AM
To: cisco-nsp [at] puck
Subject: [c-nsp] ASA wild card cert...

I have exported from one ASA and would like to move to a second ASA our Wild card cert. It looks like the export / import went well. I can even see in IE that the cert is my *.domain.com but I'm still getting a Cert
Error. "This Certificate cannot be verified up to a trusted certification
authority" What did I miss?

Thanks

Scott

ASA 8.4.4
_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


svoll.voip at gmail

Jul 5, 2012, 10:19 AM

Post #3 of 4 (406 views)
Permalink
Re: ASA wild card cert... [In reply to]

Thanks..... Perfect command. I was able to find the wrong Cert and fix it.

you rock Ryan.

Scott

On Thu, Jul 5, 2012 at 8:55 AM, Ryan West <rwest [at] zyedge> wrote:

> Did you get the entire chain as part of your export, sounds like you're
> missing an intermediate cert? Do you see a difference between the ASA's
> when issue 'show crypto ca certificate'?
>
> -ryan
>
> -----Original Message-----
> From: cisco-nsp-bounces [at] puck [mailto:
> cisco-nsp-bounces [at] puck] On Behalf Of Scott Voll
> Sent: Thursday, July 05, 2012 11:38 AM
> To: cisco-nsp [at] puck
> Subject: [c-nsp] ASA wild card cert...
>
> I have exported from one ASA and would like to move to a second ASA our
> Wild card cert. It looks like the export / import went well. I can even
> see in IE that the cert is my *.domain.com but I'm still getting a Cert
> Error. "This Certificate cannot be verified up to a trusted certification
> authority" What did I miss?
>
> Thanks
>
> Scott
>
> ASA 8.4.4
> _______________________________________________
> cisco-nsp mailing list cisco-nsp [at] puck
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>
_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


scott at granados-llc

Jul 5, 2012, 10:27 AM

Post #4 of 4 (404 views)
Permalink
Re: ASA wild card cert... [In reply to]

I Second that, Ryan has helped me get unwedged on many ASA issues. (including one similar to yours) Much appreciated!

On Jul 5, 2012, at 1:19 PM, Scott Voll wrote:

> Thanks..... Perfect command. I was able to find the wrong Cert and fix it.
>
> you rock Ryan.
>
> Scott
>
> On Thu, Jul 5, 2012 at 8:55 AM, Ryan West <rwest [at] zyedge> wrote:
>
>> Did you get the entire chain as part of your export, sounds like you're
>> missing an intermediate cert? Do you see a difference between the ASA's
>> when issue 'show crypto ca certificate'?
>>
>> -ryan
>>
>> -----Original Message-----
>> From: cisco-nsp-bounces [at] puck [mailto:
>> cisco-nsp-bounces [at] puck] On Behalf Of Scott Voll
>> Sent: Thursday, July 05, 2012 11:38 AM
>> To: cisco-nsp [at] puck
>> Subject: [c-nsp] ASA wild card cert...
>>
>> I have exported from one ASA and would like to move to a second ASA our
>> Wild card cert. It looks like the export / import went well. I can even
>> see in IE that the cert is my *.domain.com but I'm still getting a Cert
>> Error. "This Certificate cannot be verified up to a trusted certification
>> authority" What did I miss?
>>
>> Thanks
>>
>> Scott
>>
>> ASA 8.4.4
>> _______________________________________________
>> cisco-nsp mailing list cisco-nsp [at] puck
>> https://puck.nether.net/mailman/listinfo/cisco-nsp
>> archive at http://puck.nether.net/pipermail/cisco-nsp/
>>
> _______________________________________________
> cisco-nsp mailing list cisco-nsp [at] puck
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/


_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Cisco nsp RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.