This problem occurs due to the presence of Cisco bug ID CSCse14296.
The VPN Client is not able to connect to Cisco ASA 7.2(1) if the root certificate authority (CA) has two subordinate CAs. The ASA identity certificate and the VPN Client identity certificate are issued from two different subordinate CAs. However both have the same root CA.
For a workaround, perform either one of these two methods:
Enroll the ASA on the trustpoint. (This is difficult in some cases.)