{"id":2024,"date":"2014-03-11T15:33:18","date_gmt":"2014-03-11T15:33:18","guid":{"rendered":"http:\/\/mccltd.net\/blog\/?p=2024"},"modified":"2014-07-22T19:29:03","modified_gmt":"2014-07-22T18:29:03","slug":"installing-a-signed-x-509-ssl-certificate-into-asa-via-the-cli","status":"publish","type":"post","link":"http:\/\/darenmatthews.com\/blog\/?p=2024","title":{"rendered":"Installing a Signed X.509 SSL Certificate into ASA via the CLI"},"content":{"rendered":"<p>Having already generated the RSA key-pair on the ASA with &#8220;crypto key generate rsa mod 2048&#8221;) create a trustpoint for the VPN users, generated an SSL cetificate and CSR and have received the signed X.509 certificate and CA and intermediate SSL certificates, the certificate and CA certs will need to be installked onto the Cisco ASA.\u00a0 This procedure describes the method using the CLI.<!--more--><\/p>\n<p><span style=\"text-decoration: underline;\"><strong>STEP 1<\/strong> <\/span><br \/>\nAbout signing:<br \/>\nEnrollment (getting your SSL certificate signed) can be &#8220;self&#8221;, &#8220;scep&#8221; etc. or &#8220;terminal&#8221; (manual enrollment).<\/p>\n<blockquote><p>crypto ca trustpoint VPN_TRUSTPOINT1<br \/>\nenrollment terminal<br \/>\nfqdn ciscoasa.darenmatthews.com<br \/>\nemail netadmin@darenmatthews.com<br \/>\nsubject-name CN=ciscoasa.darenmatthews.com,OU=UK IT Operations,O=MCCLTD Inc,C=US,St=MO,EA=netadmin@darenmatthews.com<br \/>\nip-address 195.88.229.125<br \/>\nkeypair DST-UK-KEYPAIR1<br \/>\ncrl configure<\/p><\/blockquote>\n<p><span style=\"text-decoration: underline;\"><strong>STEP 2<\/strong><\/span><br \/>\nGet the Intermediate Certificates provided by the CA and associate those certificates with the trustpoint. (Essentially we are going to tell the ASA that we trust these signing authorities based on the certificates that they give us. These intermediate certificates were also provided by our CA. They are simply flat text file containing a PEM (ASCII) encoded version of the Intermediate identity certificates.<\/p>\n<blockquote><p>ciscoasa(config)# crypto ca authenticate VPN_TRUSTPOINT1<br \/>\nEnter the base 64 encoded CA certificate.<br \/>\nEnd with the word &#8220;quit&#8221; on a line by itself<br \/>\n&#8212;&#8211;BEGIN CERTIFICATE&#8212;&#8211;<br \/>\nMIIEQDCCAyigAwIBAgILBAAAAAABI75RcWkwDQYJKoZIhvcNAQEFBQAwOzEYMBYG<br \/>\nA1UEChMPQ3liZXJ0cnVzdCwgSW5jMR8wHQYDVQQDExZDeWJlcnRydXN0IEdsb2Jh<br \/>\n+wGfcVAvZyZZjz5hIEdCoyF8YAOFlmsib1HB7E891oWrEhPKNt8dTQ55ngFiqAXV<br \/>\nHMOvmh8Xwo1F0+Lt4Gyn2NnVDRiPl0xRYe2l8yfF2rrkypjti4od7fVmdjcGzhdy<br \/>\nGVbahTfSVw11IJJ2qR52c0wzGDB4hiLXArs6WYY+vNd5ngX7LGkKivlYS0fmcsWp<br \/>\nMuPXh26KHFXRFtRfg9nuRIbUJhfslH49YtZOXKBdhiNmmKoP<br \/>\n&#8212;&#8211;END CERTIFICATE&#8212;&#8211;<br \/>\n&#8212;&#8211;BEGIN CERTIFICATE&#8212;&#8211;<br \/>\nMIIECDCCAvCgAwIBAgIEByczJTANBgkqvkiG9w0BAQUFADBaMQswCQYDVQQGEwJJ<br \/>\nRTESMBAGA1UEChMJQmFsdGltb3JlMRMwEQYDVQQLEwpDeWJlclRydXN0MSIwIAYD<br \/>\nbqjnuSmToOTuh0lx3ne3Xz1UpqoGzUvg2KvLsQ80qiTYdDnFwQTPX2TJkgrrqh0f<br \/>\n5nF32+sVXvGYDnhZ72qv4U9\/OAar5O9EvaUHvQ==<br \/>\n&#8212;&#8211;END CERTIFICATE&#8212;&#8211;<br \/>\n&#8212;&#8211;BEGIN CERTIFICATE&#8212;&#8211;<br \/>\nMIIDdzCCAl+gAwIBAgIEAgAAuTANBgkqhkiG9w0BAQUFADBaMQswCQYDVQQGEwJJ<br \/>\nRTESMBAGA1UEChMJQmFsdGltb3JlMRMwEQYDVQQLEwpDeWJlclRydXN0MSIwIAYD<br \/>\nVQQDExlCYWx0aW1vcmUgQ3liZXJUcnVzdCBSb290MB4XDTAwMDUxMjE4NDYwMFoX<br \/>\nDTI1MDUxMjIzNTkwMFowWjELMAkGA1UEBhMCSUUxEjAQBgvVBAoTCUJhbHRpbW9y<br \/>\nZTETMBEGA1UECxMKQ3liZXJUcnVzdDEiMCAGA1UEAxMZQmFsdGltb3JlIEN5YmVy<br \/>\nVHJ1c3QgUm9vdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKMEuyKr<br \/>\nmD1X6CZymrV51Cni4eiVgLGw41uOKymaZN+hXe2wCQVt2yguzmKiYv60iNoS6zjr<br \/>\nIZ3AQSsBUnuId9Mcj8e6uYi1agnnc+gRQKfRzMpijS3ljwumUNKoUMMo6vWrJYeK<br \/>\nmpYcqWe4PwzV9\/lSEy\/CG9VwcPCPwBLKBsua4dnKM3p31vjsufFoREJIE9LAwqSu<br \/>\nXmD+tqYF\/LTdB1kC1FkYmGP1pWPgkAx9XbIGevOF6uvUA65ehD5f\/xXtabz5OTZy<br \/>\ndc93Uk3zyZAsuT3lySNTPx8kmCFcB5kpvcY67Oduhjprl3RjM71oGDHweI12v\/ye<br \/>\njl0qhqdNkNwnGjkCAwEAAaNFMEMwHQYDVR0OBBYEFOWdWTCCR1jMrPoIVDaGezq1<br \/>\nBE3wMBIGA1UdEwEB\/wQIMAYBAf8CAQMwDgYDVR0PAQH\/BAQDAgEGMA0GCSqGSIb3<br \/>\nDQEBBQUAA4IBAQCFDF2O5G9RaEIFoN27TyclhAO992T9Ldcw46QQF+vaKSm2eT92<br \/>\n9hkTI7gQCvlYpNRhcL0EYWoSihfVCr3FvDB81ukMJY2GQE\/szKN+OMY3EU\/t3Wgx<br \/>\njkzSswF07r51XgdIGn9w\/xZchMB5hbgF\/X++ZRGjD8ACtPhSNzkE1akxehi\/oCr0<br \/>\nEpn3o0WC4zxe9Z2etciefC7IpJ5OCBRLbf1wbWsaY71k5h+3zvDyny67G7fyUIhz<br \/>\nksLi4xaNmjICq44Y3ekQEe5+NauQrz4wlHrQMz2nZQ\/1\/I6eYs9HRCwBXbsdtTLS<br \/>\nR9I4LtD+gdwyah617jzV\/OeBHRnDJELqYzmp<br \/>\n&#8212;&#8211;END CERTIFICATE&#8212;&#8211;<br \/>\nquit<\/p>\n<p>INFO: Certificate has the following attributes:<br \/>\nFingerprint:\u00a0\u00a0\u00a0\u00a0 64fc5f79 945af76a decf4fd4 a1a79496<br \/>\nDo you accept this certificate? [yes\/no]: yes<\/p>\n<p>Trustpoint &#8216;VPN_TRUSTPOINT1&#8217; is a subordinate CA and holds a non self-signed certificate.<\/p>\n<p>Trustpoint CA certificate accepted.<\/p>\n<p>% Certificate successfully imported<br \/>\nciscoasa(config)#<\/p><\/blockquote>\n<p><span style=\"text-decoration: underline;\"><strong>STEP 3<\/strong><\/span><br \/>\nThe CA has issued a (signed) certificate tied to the private key. This will be another\u00a0 text file that is copied into the ASA:<\/p>\n<blockquote><p>ciscoasa(config)# crypto ca import VPN_TRUSTPOINT1 certificate<\/p>\n<p>% The fully-qualified domain name in the certificate will be: ciscoasa.darenmatthews.com<\/p>\n<p>% The IP address in the certificate is 195.67.229.127<\/p>\n<p>Enter the base 64 encoded certificate.<br \/>\nEnd with the word &#8220;quit&#8221; on a line by itself<\/p>\n<p>&#8212;&#8211;BEGIN CERTIFICATE&#8212;&#8211;<br \/>\nMIIFWDCCBECgAwIBAgIOAgAAAAABRJNGQiwwWVMwDQYJKoZIhvcNAQEFBQAwUTEk<br \/>\nMCIGA1UEChMbVmVyaXpvbiBDeWJlcnRydXN0IFNlY3VyaXR5MSkwJwYDVQQDEyBD<br \/>\neWJlcnRydXN0IFN1cmVTZXJ2ZXIgRVYgT0NTUCBDQTAeFw0xNDAzMDUxNzI0MjFa<br \/>\nFw0xNjAzMDUxNzI0MjFaMIHoMQswCQYDVQQGEwJVUzELMAkGA1UECBMCTU8xFDAS<br \/>\nBgNVBAcTC0thbnNhcyBDaXR5MRkwFwYDVQQJExA0OTAwIE1haW4gU3RyZWV0MRMw<br \/>\nEQYLKwYBBAGCNzwCAQMTAlVTMRMwEQYLKwYBBAGCNzwCAQITAkRFMRgwFgYDVQQK<br \/>\nEw9EU1QgU3lzdGVtcyBJbmMxGzAZBgNVBA8TElYxLjQsIENsYXVzZSA4LjUuMjEQ<br \/>\nMA4GA1UEBRMHMjAwMzQxMTEoMCYGA1UEAxMfdWtjbXZwbjEuZHN0Z2xvYmFsc29s<br \/>\ndXRpb25zLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALodDIAe<br \/>\nOaU4xhKgd6rCmk4E5LuKxBaGuPvj5Q3bvhMrCu4l1Ju\/cabhrsvkuDgisGMkLXZj<br \/>\nxMVWl3+9oB+gCTH5fhaa6QqprGhK9gA6b3Lbm1PkN69JDEZDfQ+z2JohaXeVZ2Rc<br \/>\npq7VtuFUy0FT7qWdoIm8CbX9iYyEuTYNyYUVsCfhb60Ho04PA+0IE+X6OI\/Et1\/E<br \/>\nJr8kx\/EZEK8EYRblK+DdFqcaNB7tEanP+CFXQqg\/uXtw\/FjzM3KmswPYBoyH9jn4<br \/>\nbXsk\/EqeFr83FcnHGlN4qaNDoDySUzg3jnMF5j1q1MKqDlXIgblAQ2c3\/WvKIx1C<br \/>\npA8v\/eaSO2SqWdMCAwEAAaOCAZQwggGQMB8GA1UdIwQYMBaAFPOUqGamehSGioTg<br \/>\n9Rzb+QsU0FQFMD4GCCsGAQUFBwEBBDIwMDAuBggrBgEFBQcwAYYiaHR0cDovL2Vl<br \/>\nLW9jc3Aub21uaXJvb3QuY29tL2V2c3NsLzA1BgNVHR8ELjAsMCqgKKAmhiRodHRw<br \/>\nOi8vY3JsLm9tbmlyb290LmNvbS9jdGV2b2NzcC5jcmwwHQYDVR0OBBYEFF+or6XX<br \/>\n7NXinRCY6gDUImBos02FMAwGA1UdEwEB\/wQCMAAwDgYDVR0PAQH\/BAQDAgWgMFAG<br \/>\nA1UdIARJMEcwRQYKKwYBBAGxPgFkATA3MDUGCCsGAQUFBwIBFilodHRwOi8vY3li<br \/>\nZXJ0cnVzdC5vbW5pcm9vdC5jb20vcmVwb3NpdG9yeTAdBgNVHSUEFjAUBggrBgEF<br \/>\nBQcDAQYIKwYBBQUHAwIwSAYDVR0RBEEwP4IfdWtjbXZwbjEuZHN0Z2xvYmFsc29s<br \/>\ndXRpb25zLmNvbYEcdWtuaXRAZHN0Z2xvYmFsc29sdXRpb25zLmNvbTANBgkqhkiG<br \/>\n9w0BAQUFAAOCAQEADpCmX29ekegFpL2wTVdn1BQNgu08vzNMqGA8iWtm1unKGi9G<br \/>\nTmn7moERCusvOg8aAVI6PNJbaqIqEso1r8CtpA1VMEJX41sfXypngBYFOFJ4q7zI<br \/>\nFzUNZMaTIL+gZ5qSlaF9F5Jn5+dfW6EJteeMdI9omRvjP0\/C8IGTrO8jC3Ni0oGd<br \/>\nYkppdfjNKjWQZ4uQFx1i1MctTJd7eGq\/8QhKq5zP4jQjPgG8Bq0EDfjhdsEQB9Gt<br \/>\nFMYgidyCt6UqC09DriG7wQ+ShqQeASWRpQ2mz2JZVZWF1MD+dAIE5eM0X1TqjziF<br \/>\nO9uU9La9yMFVJqiS9O\/QuZAvd+QocnF0UeA3jw==<br \/>\n&#8212;&#8211;END CERTIFICATE&#8212;&#8211;<br \/>\nquit<br \/>\nINFO: Certificate successfully imported<br \/>\nciscoasa(config)#<\/p><\/blockquote>\n<p><span style=\"text-decoration: underline;\"><strong>STEP 4<\/strong><\/span><br \/>\nSet trustpoint to outside interface:<\/p>\n<blockquote><p>ciscoasa(config)# ssl trust-point VPN_TRUSTPOINT1 outside<br \/>\nciscoasa(config)#<\/p><\/blockquote>\n<p><span style=\"text-decoration: underline;\"><strong>STEP 5<\/strong><\/span><br \/>\nBACKUP THE KEYS:<\/p>\n<blockquote><p>ciscoasa(config)# crypto ca export VPN_TRUSTPOINT1 pkcs12 ciscoasa#<\/p>\n<p>Exported pkcs12 follows:<br \/>\n&#8212;&#8211;BEGIN PKCS12&#8212;&#8211;<br \/>\nMIIUNwIBAzCCE\/EGCSqGSIb3DQEHAaCCE+IEghPeMIIT2jCCE9YGCSqGSIb3DQEH<br \/>\nBqCCE8cwghPDAgEAMIITvAYJKoZIhvcNAQcBMBsGCiqGSIb3DQEMAQMwDQQIhVNd<br \/>\nqYh8l4YCAQGAghOQT4atx9GN3QU6Y1l7Wy90X97GsTPC32wPvar0jnAgoN9EXMTo<br \/>\n6LqtmAqD5KJk\/nSTdcEbF+pJ4jD9VgcvDCnVJTFL+YWcqwKV36g4qTrEAVcyyoRA<br \/>\nElj2xgVgHca3SA04YaGoLMAQuCsD0wcwjI8gMXMtoPH6sAeaQpDsfYvfp8PxdRPf<br \/>\nQizLUuTDMQnWB1tNPCJGT+yk5GVcAjNyQKU6\/WgyTWGSs\/hnpoTFupguT9TP6nx1<br \/>\n8BSo7uYQyuQobauxdha00QI7SB+yCS5xIluNdGw8MqIyWdwHh5fB66gZ2sFlsHil<br \/>\nrGv0X27ChtWoOgqetplHuEwhZniK1gq\/+AcBOO1tNuBso2\/0V0n8osk\/Fygd0HI9<br \/>\n1UIe7ym3Gev+XcgxJo0+xMPRNAdUnOrXmgBBR0OT4\/pk6lempDdsYuB2lYEMZmtQ<br \/>\n6dl7l4D13yFCfLN\/QSHHEyTWxJJcbrO0XEeoTZdjA+2o\/idESxF5Ikzo6+YX6Rpf<br \/>\nqqJPZajpJ6TTd19HeMGIpDRHbfYcl0zewsNlO8XkOss83XEQa1UVdaeRJnNmES9W<br \/>\nO0uM0Q7EpYSthJJuGGBQr5BkmFGpjcfMWKvbUNunupyP0I8oysogIIp7EEW7AzXR<br \/>\ngRENzUl9IBRO\/+2ah050icQ8wLIXL1fW3P7P880BzGg2dWLgqHZ7po3dim2UsH6L<br \/>\n8pP\/MZJVofqGa4+1gETWuCPDD8IMTxI1xQoEQGO7SX8GDTIfcCNntmsMU3dR8w7A<br \/>\ndxnvF92UCYCQeU4wOJnfjKjniXm5z147nhu3\/0HG5II8\/ynF1Jr6NHaotXkpYJ\/t<br \/>\nvdIHRS2jh\/p90ifkF5\/\/54pqTv9M2gcUy7YFNV6+7wUYhWtUVvQQl2mvHeax05QP<br \/>\nPmpFhlPKo5iqUJMZbup3t+Cu33eLUy2hgeyMU6ndSeBiGj4AnuTVp9oinUdx8WhK<br \/>\nl6H1I2xsEwszgRNgsE2FRHAmwVp5S8nBC9ghOFOue9fWLxFU895Ab8a6L\/\/Ysqgi<br \/>\nG5O+oC+7sSMrpE6+98HJh\/GLDZiypP+XV2O3pLRoOo2bFOCSAC4inB7oH4LKEYuX<br \/>\nI\/A0howy4XrwV1wq86U2JkLdvjrayKn3V4iux3KUsrzlPqg480P2rKpFIzst3LkY<br \/>\nvDD8HsAPu0Er54MdNGjenKahmZ01kMRc+qOO92XSAizp3wbguFYiIALwjUIGQ82d<br \/>\nl1wqeEkO+7gwd9uChGtmTrW8fRDFiiooBuULOunyiOfRm++NhLyKpoOcfwUg52ZR<br \/>\nEtiCF7hMa4+An12DNDDFAV7TVsAn4i2AH8JxsymLp\/1Pe+6Y3ceJgLvOsezmB0tN<br \/>\nN0pROpr3Qm\/\/e3FeXzTpI75CmR+unUYz6mvehfW74tHGb05Z8hNWsJlXN7LxdiDU<br \/>\nQkJ8AIBJAPbLgtswe4KeBxCdr3mIF5+LboxF1Wezup1bS8lKlaD4ZPRWAbZsdm15<br \/>\nModGH0KIO9A40t7ba1dfTKbCipmas16uzTCuhcfrFeoon\/mEoApeYkm+s+8kLrm+<br \/>\nMpLO3xVlNALlNzEfmfllUTjLnqo70n3potyy82NHLfNKJ5O6qPe\/y1hdk4zZOiOY<br \/>\nA5fhmzHx5Ao2h5W+K3qNx9LzJG7TUwD38qWB673Q1qCEql74BVha+tYvA+GitYJ+<br \/>\nrGk4deHzXinNtEUjcuCPwlFO97VldnffrjQgsc50hrAt9lJP\/Vp63\/F03NxI6kTf<br \/>\nCOnD2VenD3djmOnQXfX3DuEw1oW5Zjs7oqOc7ddT+450JTMzjC3TxRb34AmMpirN<br \/>\n+UVecHDWPsitbrb3QSoVcdNP331efBd4EszEyMp5B9cDZCn0gRlILrHm4gG3mZPg<br \/>\njSkzmp5gmydKU7i\/vGLNxTi+Iq1R1keqtrXxngdlQ2kh230Wya+2CBt74y+x3EK4<br \/>\nrCSfJBpRk+iCYNYIxSssVbak4C8siVAG9RJBfcLlDCRDfDBNwxgQ1rcSePmDzM6P<br \/>\n\/m1TigW4H9SqHGLbOueILAWaxPXZ6ySKWais6wV92B3thKGBpglCre6Ooqk60AOy<br \/>\n2Q2v1vO1JKBkaPf4i8Oj0fzSzUKI5oARriSeM7ZrijnQMiNe9bJhhaVEdyIc\/\/9V<br \/>\nt\/t3G9FgJxO\/j\/vM5h+wmJ9z6cZmS2pG1lSWJkIspsAxMqWZg6OkdIrbYZ84LwSZ<br \/>\nz0LDzWUgX5D7gsUYh3fLTma9J5N7DVynY73YC45fbs5pi5SaEgbbIocOeHbssvG+<br \/>\nf3coDrrPSkgSHNv2JikZUXP0XIDDDaPSRmkCEktx8hxpwVLWklLSlhUToXX3WAHo<br \/>\nZ6AfXb3g3STh0Sii9D4dfpAcfG9hPBrU29BjBUBl6Sy8kyqCZfFpQnSrDD\/mUQ2c<br \/>\nDkzojF0HukCfGE6pV2kdQpmWDoqEQrBBjDRkDRYg8n51BLvVA70k4fsP6lgOPgQN<br \/>\nMGXuL7CMypQYvYGZ4lb2K6riYSqEJW72TSXY0G9PyaDFeRnS\/9ANDUU7XprIzq2v<br \/>\n4wnqh1bPwIxadDi7EIWhG2YjpFabZgnBb6w3GdZPAD3hQFPsW2ZQb1YZY5\/my0mJ<br \/>\nJLY6kBzScTxzbPMhz5F6NCvm9hJU6fPEB9JrDFCEvMipQyIJQPVqubdySxwObJM8<br \/>\na\/hpcuCVZ5w4PsZ4lUq9o70ev6JIPBE8wfFI8iOn7vJvSikWuWEQ+7hF7Lli7Pp2<br \/>\niu\/MotMb4DdynGWz\/TRkobDgLp2ZT4+ydYeDS5Vj4NdXEOYXWAUcpKfHkjz98hrC<br \/>\nNSbOmeZq5se++mXsQRqRB\/9\/rzDU2LilNuvuIhJOkc+bfrDOm7uyYmP9SIehEg4H<br \/>\n6uPhvdlWpy\/Q3jmwTQAReNFzbPmC4tNB+DD2w\/lYE0FAnp22vum0VsQmf\/FH4JmY<br \/>\nXtnytzpGUvw6fLqmu\/rgg8wUHFCS82HG8N90WC0ge+pUGhFDHMcPUxr4\/9AgqgrR<br \/>\noZbPXiqATEVo0hhAuNL1zIUzPYjjRUzArN62il3++gh73hnov69ry9ZifdxvvN4o<br \/>\nHqjMKDvVzNRI0XUNyKiihh0RjJ+e3YU2yq4lPyzg7lfCr\/i8n2oZU5sWf5PvNvMB<br \/>\ntC2lg+eSRME7mbC9ooQCbg3aCPv9\/ll0cQAZmNyF7vCGJMCe4+jVDVzI+GOzq4+Z<br \/>\nomiye\/imWSYkzgy5LSGoDetb9at\/MUh3nCZtCEO96fBKBNZ19vDS7TPnAbG8RVzz<br \/>\nKO2Daq0DoR17IXLpf4ZnDohdYaeMJs9gq+PG3lXKGgCR\/2WVs4btwhjLdAWPndHe<br \/>\n6hmAfFZVj0olYXgipDwHktYQzhHHlAhfxCwMriaEJAEWK45fkoElrVRngXAuE8II<br \/>\npqfkCjL1SzbP+K7rnHywwCww+Kntxt6PglFqdc1\/8WcqLUr5hQWVVbaIHPRiA\/2r<br \/>\n4SfyK70R7dYJosYrjnWkLN76nXHt8FIxvmey2AbTh3BaHNA3+Dd2xxCzBZDWOCtp<br \/>\nKPxUW6LitD4TBZNhbtwmW1cWLzJdWJs13MTBgtJe5bz9o7FQkM5JMM7S9oG5Tkhm<br \/>\ng2je94krKQq0fUSFgwIJ3MwwK1xWvQGpTPYA1jb2xBWrEs6vUkvda4J8A8iRW55N<br \/>\n8TorJRuv6qYu+0+IkPLiDTunjzX1QyiHys1PC8gNG28se6DcckHTwaalsZvS22+z<br \/>\nbhRq4qVEXRSvGwiv6htr\/0qsYX3coSQlTaeT+Qn3kUHU93MRS1G2idZ+k7Co+Lc5<br \/>\n93aQX+u70oYSVMx8gWocbTfSgSEAyzo+57aj1tvnk8xvGZC+CpB837yyEsmOn3w2<br \/>\nmPWPn9qy5p1Heag60kOdKAB+HPDXLd6dwBgSG1+mOiHWJn2qRrMJ7Q30bZkafKdt<br \/>\n\/sy8hKd0gHroqbKjOVddA2dDEKQ9TCMKpXAcKZaGMu\/61dFpvUfeKRVVJ1pkC+mZ<br \/>\n0sTb9S5gWKWDzbzK+6mgoAgrrWDRt7qFm4Ni+DnZpA9RhqQXgLvGycF7qEGcz5f3<br \/>\nYeah1dhbe+8kZGweu7wP5l5UPblp\/fiCXio4Nx+4G9PrDpjgWn8D0mYfG7x+Z3UH<br \/>\nUYK6MUE8JR4yENrETvP8vgklkona\/JkgW\/oPtz4PDd6KAMBe59MmqDRvjqTJvCrr<br \/>\ncKrHt\/1pjEGi0zTC\/KWcAmRFjLP9ZQFov2RDGJitMBVe+WMsVxPDl+inquWmzJRZ<br \/>\nqwzyzGrt46R1Cq+U7vqCUJVfQ\/QpIEty7TI+yDJkKrJneDHRn0Cbi7ALk23QdIen<br \/>\nFl5\/Wm+0xjg8ycyCZSeUngHrqWEMKl01R+URpz7RReQK3ULd5oOPYnH9lLeV0BOi<br \/>\nlxIp3z1Y2aTOPcViV5ia5Bzwwymd8W7xbkaAfsVlcULS6vc5Xtj7lnx1v\/IBEVgQ<br \/>\nF3j8e9JIuRyBFDBmCM5ZGeqow6QU+0\/V8j8rgoMJlGXtXYU4Mq5b7k6joqshWPI2<br \/>\nw\/Q5B5ZXrLEN8EStu1wXJpvhHAxjDO87pIUVbDzQdZNe14uVlbKlptdCb66Vm7R6<br \/>\n3+5mQH2ZFWUtAdenlFVS87KDw8H6PuDg1gc+jI2mEUnu0c4hSGPbwpKOioanInM0<br \/>\nBcNfc9R6fjLzAzOh7pI0QYKOTm7gXz7ej9gMm\/e5tZVRQ30V3D5A0Uj95cq6gEj\/<br \/>\ndFo8PS1tL7k9r9qsXwR0CCszpjnSNX53VbpSpqBimqfqd51yVsRugEEw2d216Or3<br \/>\n0ObBXoewJXBl7pKj04tjjPiaK6\/UBnkwH\/\/DJ4THqHXwss6PCZB\/LRmASjqmHcoL<br \/>\nXHvam0v70kTJ0k114A\/udqvUq0ByaJusQsmwtdy97NTqDYCNYH07brAWiij61T2M<br \/>\nJtXnazxyUDspp2KlI2bWigupNu2RyHk0bOjxSF4fb+lJeK\/uZBrtLdF9ih6FqCqb<br \/>\ny\/fKsutUUPM0WrsPfU7qbvg5+kY4popqpWCdUGwkx5RoITi1teo9DmLuhiudaJH\/<br \/>\nRMwTtK7Rw3jqStOgFwH+B5BsplFAXMRHJyp8ZyOAT\/JD8eyl32VhAYW7ZTPj67uP<br \/>\nGtMtv1jiwCRrwPxmsVgl0UCekY4BF5VNhS5rkl8HDEc3tNQpe+vy0ew3ksYM2Y74<br \/>\nxpE5vPobdUWkuoiPYg\/B7HuozcnoXDpOVedIG2\/ps\/1p4VYAI4LCnu5tHELfJwB6<br \/>\nW55AXiCmtEsujtzhUe8oMbn0MO4hlk+rXR5fGI3xn1ik85z\/8XmIOukXsfSqcO9z<br \/>\nUuMmMdWi9n+UspxMYdxm6LE5OSncfhklbLj5n26vMMMHQ7VzEt5rGDV9bGS9X8Uv<br \/>\ngZvj5di1gI7yhZReLqH3y7HzqPGdng\/PC3ltV3Pn2NujSq7yUXFuyo0cac8RoMIa<br \/>\nRwtQB7thj2F4d+XOzp8GLNvVdUPJUehSSReu+yeXPL5XC0GKnB8q7lCYWYy6PNlI<br \/>\nvdUqOYnnmtJKCTTjfXaYzlj5Xi45YkKAQFhiJ\/B9sP7UQ8Do54jy416W1XtxaqFt<br \/>\n0Rd2gkHbZMjnL2\/Vuf2wm8Zop2yxKEbtZNmCG76VABxkGB14z1B5x4v+kJIFB7ts<br \/>\nQek6Tts2HESkqDwJ7Ebr3Bnqzctupj2hnxVqVMSGczd+OABWxs9xyp\/3JjsscZeG<br \/>\nA5Jog+XTP7l+DPnnFw85G2M+lmq4mkR7uGqAI8ujFvp0WTAjPe0hCoaQth3UzaMh<br \/>\nKj4umqssCtu3Katq3ZT9U7JSHzd7kysUg2EFmIPEA1t24zVUBRq3JRiVNVqp+7Ck<br \/>\noo2SwvxiP3jlnAet83zpmc4lqW3X04p+iSaLIO7oHd5YjImaGBk+MjJcvGDAMBiv<br \/>\nv15xyZLEQEPI8uHJ9kau6w89UswI9LlUQONphCcmM6zW3Bj6EPjhQmuWfYl+C8dm<br \/>\n1ptZPnTYdBaNn3lxvH42+narCb\/ThVsERY0dGO9tArf9hTY6LMJVav\/deSSBU3JH<br \/>\nyS+it0ufOzm1ohQQ59IfTR0WfFz2aBJBAGxbXR2YF2AKWUsdH5fugBGdkwc+oWs\/<br \/>\n5uSVMWLuRr4XArj+8ZE7hf\/iOiz9Hz6sQN4zwus97rpNZE6ES0maOMGaQjddjvLC<br \/>\nIBA5W9nbA1rbPUGbD3QiYtBeEOLEc+s8VK\/epGvszq0E1CvuVH2DhcX4J+eqzDA\/<br \/>\n\/T+PLDZneatkhSqZCSJn9QepviEGNnvuK96CG16g\/xD3wphZRaLbBpB6bm5TO6wA<br \/>\naRNyasVFeCwU3Q7bZ8nv48bIoZ7Q4Q1V1BWG6Rmt91g5cnoiYcEgiS487yqxLho\/<br \/>\nQLLPDj7h04WbACZFmkiac97RZ3i3N9otZUrt9udRmqUhADdf5QNv92INe92fDV4v<br \/>\nRxsIlXONLidto9oZt7fBPqtbc7boWjcMKFOsPDfzvzb8AgSdUrP4vT0GqXzGXB1Z<br \/>\nleVTBisIP9AfzpBGWOxbTCximDk2vGKQPiNOZsios3E3klB0qg2Vs\/TnYqvvpZAp<br \/>\nPweI0hfvpNueK3eQPoTZUUpQVjkY3KEBtQnfgr0tocmJv5wxMsoVsLe434vjbCBX<br \/>\navgKwKfJsXdIT+HBeArfMGbsEHMt7rkRXUSDSMkQTEy3G\/Se+XC2qD4+GKNmhXyr<br \/>\nkKEoI82w7U735S0JylvHa7HM+D4wRKcqqIRrTpehj6E5WTd7V8i6V77eDkNINNJI<br \/>\nLdQgMnxpfBNqbJ9FDfddy5xuSEWLQf9LcjBG+RzF5IiiCrVgfyp1ztmdpe4bmqOM<br \/>\njNyIsyDmkE88iolyEIit0Lvt1Tc0J7qUGsOUyTA9MCEwCQYFKw4DAhoFAAQUGXCd<br \/>\n16j53dMCo7mfg1XuwJQm75gEFKUqvF1I80byiJZxMgDCa3zzBEx5AgIEAA==<br \/>\n&#8212;&#8211;END PKCS12&#8212;&#8211;<br \/>\nciscoasa(config)#<\/p><\/blockquote>\n<p>NOTE: Before adding the certificate to the trustpoint, this happened:<\/p>\n<blockquote><p>ciscoasa(config-ca-trustpoint)# crypto ca export VPN_TRUSTPOINT1 pkcs12 ciscoasa#<br \/>\nWARNING: Temporary self-signed certificate is being generated to<br \/>\nexport the keypair since an associated ID certificate is not available.<\/p>\n<p>Exported pkcs12 follows:<br \/>\n&#8212;&#8211;BEGIN PKCS12&#8212;&#8211;<br \/>\nMIILPwIBAzCCCvkGCSqGSIb3DQEHAaCCCuoEggrmMIIK4jCCCt4GCSqGSIb3DQEH<br \/>\nBqCCCs8wggrLAgEAMIIKxAYJKoZIhvcNAQcBMBsGCiqGSIb3DQEMAQMwDQQIcEZC<br \/>\noVByV8oCAQGAggqYT0LnSEbpFLp5BX6nkmrt808ZkNCYAO0yzQZu76047ZESr+yS<br \/>\nT2aZFDkXYA8s2VD9XpdIFyyNM1aPoIhktUsdF10mT\/XvW\/neetbvz3npFZfyuJg+<br \/>\n2IHhua6QhuV\/rt3G9xJfJE0AdP0w\/Uf4jsw8KPEhkmUM5V3iun\/13LmDMiY80Uvu<br \/>\nJXndux3lR+R\/hQKEv6ISZ4+c973YtYhj0nS2U+Rp81krWioxmTWsAob\/xZyhgBct<br \/>\nPc19MFYnpX5q\/oW2cM9AC1rtZ5EHnipoDBKdqlBoCTeegshYACpFZ70KdHwvM3ZT<br \/>\nBivEiltQ0kDIVw2DC8C+lp1Fy\/DmLos4GDuiU5wQLSGYuRBDg4kyXyd8cn2o7G7f<br \/>\n2EJGvEtE9VVuOeyt+kPKOHbEkjz\/1DvH0lFhgqcB0o0LWbNoJizjcgeL6L8uYbzI<br \/>\nWoU6q0at7dVJYM3ow7565tEaVHRby0WP3GKlnr4r8rXJx4r9GiKd5xprhfwBwGh3<br \/>\nzggCVXz9nGvCoi4AKGGlGCam4KZCcT8SPliklXbQ5Sb6vcFk9SubmA5MvHZ1I7g6<br \/>\nUF7e318YJD8SxLIwWusKfz+omi\/GbURi\/DdQxGglgTY6yoTFKAio2R\/DcLDQsl5j<br \/>\nTS9Dm8z+XdD\/VRVMYftMaOSCDEWaa0pVxszg5qDAvwQAXTADONq\/a9PIR0EcOe4k<br \/>\nFBRjF5czqJ0amvbvIxcatmvxNSczQ21YRtotw6TJu+0aMRgWlHaGNlXVmqBG4aTq<br \/>\njxsaIqR+7KfsX5A9z7e9SfJJQ2KQLt0XV1GD5qiplOyJYiwMmYrydCdGKFaAfcaO<br \/>\nj9mh9spsyDJMLigsjELJx2O38Ip4JTwWWutJvIjxlqN\/fiKos\/ZYRfSXd3JZODHm<br \/>\nSwVkJtIVoTQG1ovm+ruyc6dywaiy+pU7aqnBRhnKD+\/K2o+N5YkLdIDp9z426Ng1<br \/>\n5G9bHSndWIjwKOcc6oVFU7kZlEMZER+ER0kFSAm3rCuU+ofTIBJgX+hqUdaS04qS<br \/>\nXbexPfD\/X1Rlc7Jhk6nZsjp2Ap9fjTRfrAHNQoMZtUCno8q2ebl33kbu5Ipfs2y6<br \/>\na1p3Tt8GlxdWP+9JNDeEUM01RT5p1LRs4pW1OkIo8mYem3+LiFd+jABFgrpDPdFe<br \/>\n\/2DUwCXJCzvhsSf4zb0UAsNcoIriJqzO+umRxzopMuvGofUfw\/Z237kOGd\/IHMeZ<br \/>\nEsJ9ho6QG3Qb8Y\/XOcpLC9vWF6xSGjh2MROCCrByL8mH07BeAk2BKb4Mhse+yHBe<br \/>\nISFS\/rADRelL9g3QQWsaQIXWN+fevIXxVdV3UJa52+w80ExMUXpPTHOtJJxbkXoC<br \/>\nHTB9p6KaooI9VoTla0YTYNFPhX7GcK+vGMv6RHD7Zn2ezMeYMSfBS42k6G96Nm30<br \/>\nfPsXSQ6DVRU3sX3Y+Ur80iAkdTo8SpPcfc2zTT2iDZO0LKL\/Wp23R1g2BL87Lgnc<br \/>\niy4oSAS\/2fZ7WsqMeXep6\/nkmb21WWO64YpjSDHQiE7cHYFptU4xzRl99zpqGbTh<br \/>\nffHbIyWk5lwjiJVveDjBMkzh2Qkc9hG\/W2PnhCzVBqUO8SJldBhRp8BT1pCdY78z<br \/>\nUMsH7f2KFT1J1FG48dBHdecp2iRuXnROh5nb1W2fxpyA0JfNCIfV5ne\/1zvuPxXl<br \/>\nAFYnEaIyBGZReqm+mqfe98S7eRM+eSdgmuPOSyYspAJkcpQBCkUDOE\/7vhz3hF46<br \/>\niuMNvB6DsBiIIGGh6kBXYdSpkgjLsB4tGVjdzsJ1A+GNLn\/K0M89Ngn0qftQHGNj<br \/>\nfXxRHHir9Ar\/MGQiFGidozwoG4zWtbdOf+dp+ILPMowt6Et\/7gxTr4pugfuCR59H<br \/>\nDL+xWX31lHH2sxQKQez+B9fKu+K5bOCKFLg28fN1xOSH\/9GaPSPmouSDA6JbcxoU<br \/>\n+IFPLLmzrB\/t9jGTedR4vR\/f5OhYPabTGqBa0zAgfWFQCUVPx9bFL5oN3z1rtf6y<br \/>\niSXxONqO1sfhRssdewUvF3XviypUXn01flfYiZbdK0otD5FwDc6IXz+kEpGGl\/3e<br \/>\nrTVV5SJh4wV6qUsxSe\/hVzlIwbmdbOFAlbERRTak+4TSlSFIY6\/+PPeFuhFh0tmB<br \/>\nu4xG0BrCfbJ1oulFkfKvtmtH4OGwCt9OG61o54C+FBzLYD9klJuHnFdVP9rsm1gO<br \/>\nbobRJwX3RcArImooC\/svGxP\/D4f8XbgH+fxxjOsng0icrZ33TjG8Y1V9+KqYlUuv<br \/>\numoCFg0KQgohghP8Cd3iknp3g5BAIv+5jl+AMACar0xx\/+fM7lX6WKh1EZui4jQP<br \/>\ncU5L7JU1SYyidM0RhbRup3iMch4G2BeTrYoRbBp\/WaaFXbzshykXpiLrkTQimbag<br \/>\nmW4WXW\/imOO3OKjyHTaGUsc6dypFzxDUOO5QmRrVq0d7v+HnVc1eccayj2aIfOyg<br \/>\nSpI2SguLY8wez2t3gdM5qAel7+9CKPk8NYQElBYO7wdbE3wgPmF2VkAou\/PNuVlU<br \/>\nKBlODcliJSbtn6NBcmViGoUVZrMBvpDF\/HZR22B1p01r35ie\/trsBr4rxR5AD2hK<br \/>\nMVjYYrou+33rGQenvtz\/Dl+PjfHTa6X8Wz9FtTYGPMwoHZI3XhPoRWrGc5zWuxOo<br \/>\nNfb2PtqPd8fvzqiLJqC1Tg8bJrQwjbU3jAblN\/l8JmxPyTnDoN+7+lPXTycglyi1<br \/>\na7HrnhPs1AuIg8k4dSdzh+PyCUxChP++\/a2R9mdqZNlwKkqInXwTO0H+It\/PfYib<br \/>\ni4o4zAGALMMnFvugm6LnfVNStC4Meffj0kin9vsAzS8zokD5woObMbV3QGANxiHh<br \/>\n3vjdqRs0dq8tu0rISHt7t15LHJx\/JtyAqVRBGj0PLGt931BSleZNMjH+kt0R\/2gS<br \/>\nOGMvd71mK+imljGIxxMv96Kg7UkdcyAQ\/QKl2sbtPwBEP10uzFS2IDKEuzTqrSTg<br \/>\nlA4cXehDRQb+yXHn\/juRlCl3HmccM9JfZk3Y8cl\/0eeh4WrjAHMVii27Ng2r23LJ<br \/>\nsD2Uub0\/7UVLiM\/m89LXUbSFVWGoddi0irbbVoQ8RTg86s+WngY\/HfbxXQ0Ep0yF<br \/>\nK3kkhioCpWwwLZrKOn1HmVGCZlC26yff5v6JxdfO8cSQw6u4EJUA6RkwiMlaUqF+<br \/>\nptKA0Jeh3bwWDqKMxFxFhf2edMCZELM1YewxOnIuaipK2djnMwLR+qfX07\/7gs9L<br \/>\nyIIhu3UEdZR4e0s+D147gRKnwmPjfkiHEginvm1Xc8p2MFhcx+U8rwMBiPd3pz03<br \/>\nW+M0XEfjiBKG351OqLSKiQubXs12J2NryDSFEN4wi3jqRtpo5\/Fu8BG9MQIfCCwb<br \/>\neuo5eWREhB5M6Itpu7kvesJ9deVrzCcSz8UfaJRSn2kaaDQu05\/hvpanF8v+5WCa<br \/>\nr5mLNRySKQn7LGxo6BHGk2VBsk8qKVcQRJU5sYuPTudRJ5aMnHyT5LOhT1OvhkqG<br \/>\nun06tKGcQ7LH9y3xjeIL4a5r8I5rjxLbj80wr59Gm9QGWVJBCfMgNoXKHBD5dC6V<br \/>\nelkil7ZwpGGJCMwzM7yr\/aE\/k2f9+TBLE9\/MVnltBGst4MdYTbWU\/\/+n5KTsmMYC<br \/>\nNxCh8LcATVsWF5nZDfhdoDWcyCxb\/GBhyR\/YKrvGnPZhUc4+MD0wITAJBgUrDgMC<br \/>\nGgUABBRMSDUwmkkbl5LPYdjT8v4o7ftOLQQUt6zHqDbK6eagb1gujtWZmFqednoC<br \/>\nAgQA<br \/>\n&#8212;&#8211;END PKCS12&#8212;&#8211;<br \/>\nciscoasa(config)#<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Having already generated the RSA key-pair on the ASA with &#8220;crypto key generate rsa mod 2048&#8221;) create a trustpoint for the VPN users, generated an SSL cetificate and CSR and have received the signed X.509 certificate and CA and intermediate SSL certificates, the certificate and CA certs will need to be installked onto the Cisco [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[27,71],"tags":[56],"_links":{"self":[{"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2024"}],"collection":[{"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2024"}],"version-history":[{"count":2,"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2024\/revisions"}],"predecessor-version":[{"id":2102,"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2024\/revisions\/2102"}],"wp:attachment":[{"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2024"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2024"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/darenmatthews.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2024"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}