Core issue
This problem occurs due to the presence of Cisco bug ID CSCse14296.
The VPN Client is not able to connect to Cisco ASA 7.2(1) if the root certificate authority (CA) has two subordinate CAs. The ASA identity certificate and the VPN Client identity certificate are issued from two different subordinate CAs. However both have the same root CA.
Resolution
For a workaround, perform either one of these two methods:
- Enroll the ASA on the trustpoint. (This is difficult in some cases.)
- Upgrade the ASA software to version 7.2.1.9.