Wednesday, September 30, 2020

VPN with Digital certificate enrollment question

Greetings everyone,

I am learning Digital certificates on the ASA.

My question would be whats the difference between "enrollment self" and "enrollment terminal"

Now obviously with "enrollment self" the ASA is generating its own self signed Certificate

I tought that if I give out the "enrollment terminal" i would be able to import an existing certificate via pasting its "crypto ca certificate chain" into the console.

But asap I give out:

conf t

crypto ca trustpoint Our_New_CA
enrollment terminal
exit
!
crypto ca enroll Our_New_CA (With or without the "noconfirm" keyword)

what happens is that the ASA does not promts me to give a copy-paste input of an existing key chain, it just gives me the following text:

Certificate Request follows:

-----BEGIN CERTIFICATE REQUEST-----

MIICljCCAX4CAQAwGjEYMBYGCSqGSIb3DQEJAhYJUHJpbWFyeUZXMIIBIjANBgkq

hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAjJgmV3GYrP21UJoQ2u0gOdD4H/fC0Q/Y

Q7vjg/8HT9CiVw9m0SN9RTVga8gnuqf1JjCQZIPRwtwowq1WImIFN6NMJPjlTNRM

jkMI0lrG31/iR5koBBx9m/+3a9tQRFThETpkTrIzYAJGLQ5zZHS1x6r37+EbC+ui

UoVH7SxETOj+0MYT4WjwpvNRlttcdXUin1sCJUKUrZIVCL3rYAaogoXhOPAb99is

ZNIa2566137OzLvEuqZu/G0EXtVtdWjyrcGpEnbfosU2EVA4ZJkHdHyTbFnsAuvI

jARmVzIkhCwreH47lIT1Q7Cw7ckVoOeBjf6d8u2pzwE8H6vUfT++jQIDAQABoDcw

NQYJKoZIhvcNAQkOMSgwJjAOBgNVHQ8BAf8EBAMCBaAwFAYDVR0RBA0wC4IJUHJp

bWFyeUZXMA0GCSqGSIb3DQEBBQUAA4IBAQA2RM2UlU2wyfC3dhPYmcUfiYLMHqYu

MKT05T12PzXNwxyt/yQ0XguOTA3x8bEBQnTQMJVgacUXMKkTjG5Wt9dSWabq2E/C

F8oKSAYYOh3+a/24SN+/DorLoqXwNz+Gfp48AKLJAOaouA1XG9wX5gczltnhA7eI

nHcCa0Ob4UPY8GVNQDodq3/uZvQA9beh1fFC2lyM3dXCNZhmgijJk49koQL9mW+6

X5utUAKV1xWIWoZmbMCxOJ1u0wtvJI31d/hSMF2nYYWuaR2EtkQFF++/n6L6s356

1s3cGL/KTzSjPUM6MkRL1vOR16ufCSkP7lddm4Rh8z4uTNCE5hTOkqtV

-----END CERTIFICATE REQUEST-----

Redisplay enrollment request? [yes/no]: no

What did I do wrong here?

Is it how this intended how this is supposed to be working?



No comments:

Post a Comment