Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor

Question about certificate chain

Hi mates,

We’re trying to authenticate an internal user with CAPI, but I’m getting the following error:

cannot complete certificate chain CN=xxxx CA=xxx O=xxxx

As far as I understand, this might be happening because the management system only has the ICA certificate.

My question is: to resolve this issue, do I need to import a new CA, or are there any other steps I need to take to complete the certificate chain?

Thanks!

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

Assuming this is an ICA-generated certificate, you need to import the ICA CA certificate in Windows.
The public CA of the ICA in can be exported from SmartConsole in Object Categories >  Servers > Trusted CA > internal_ca.

0 Kudos
RemoteUser
Advisor

 

HI @PhoneBoy 

So, I need to import the customer’s CA under Server > Trusted CAs.

Is there anything else I need to do to resolve the connection issue, or is that enough?

Under IPsec VPN, do I also need to add the same CA to get rid of the warning, or is that not necessary?

Thanks!

0 Kudos
PhoneBoy
Admin
Admin

If the certificates are generated from a third party CA, yes, the CA key needs to be imported as described and access policy needs to be installed on the gateway.
Note that the gateway does need to be able to reach the CRL specified in the CA key. 
Not sure if any other configuration is needed, but it should get you past this error.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events