×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

VPN Client is unable to connect to Cisco Adaptive Security Appliance (ASA) 5540 version 7.2(1) using certificates and the "no suitable trustpoint found to validate certificates" error message displays

Document

Wed, 07/22/2009 - 19:47
Jun 22nd, 2009
User Badges:
  • Gold, 750 points or more

Core issue

This problem occurs due to the presence of Cisco bug ID CSCse14296.


The VPN Client is not able to connect to Cisco ASA 7.2(1) if the root certificate authority (CA) has two subordinate CAs. The ASA identity certificate and the VPN Client identity certificate are issued from two different subordinate CAs. However both have the same root CA.


Resolution

For a workaround, perform either one of these two methods:


  • Enroll the ASA on the trustpoint. (This is difficult in some cases.)

  • Upgrade the ASA software to version 7.2.1.9.
Loading.

Actions

This Document

Related Content