Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
You may experience some slow load times, errors, and slight inconsistencies. We ask for your patience as we finalize the launch. Thank you.

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX certificate issue

I'm trying to connect a PIX FW and a VPN 3015 with the use of certificates.

I followed the instructions found in TAC, but at a given moment there's a command that configures your CA server to get the certificates, and it's here that it goes wrong.

--> ca identity abcd <--

The given path and dll are not found on my W2 CA server: mscep/mscep.dll !

Any idea what went wrong or do I need to point to another file on our W2K CA server ?

  • Other Security Subjects

Re: PIX certificate issue

You have to install an addon application on your Micarosoft CA server. I believe it is called MS-SCEP. You can look at Microsoft's site for that


New Member

Re: PIX certificate issue

Let me know if you dont find it. I remember it took a bit of looking on MS's site to get it.

If you plan to Revoke your Certs, There are some issue in getting the CRL to work properly.

You need to have the 6.3 (1) code and you need to leave off the LDAP address on the ca identity command.

I've spent months with Cisco trying to get revoked Certs to work properly. Let me know if you need some assistance.


New Member

Re: PIX certificate issue

Hi Scott,

I've been wrangling with the MS CRLs too. Once I've cleaned up the URLs in the CDP attribute of the root CA cert, what else should I be aware of? I don't have an LDAP ip assigned in the ca identity line.

Do you have a successful formula or checklist for this config? I want to be able to reproduce this setup a number of times and want to make sure all the gotchas are taken care of in the documentation. Then I will post the result on the cisco site via one of their techs so that others don't go through as much pain as we have....



New Member

Re: PIX certificate issue

You have to install mscep utility (cepsetup.exe), you can find it on Microsoft Add-On CD. This utility install RA on CA, after that you can make enrollment.