Anyconnect MX - Custom hostname certificates - non MX generated CSR (privatekey) ?

Kind of a big deal

Anyconnect MX - Custom hostname certificates - non MX generated CSR (privatekey) ?

So , Im trying to find out, do the MX support custom certificate where the MX did not do the CSR/Private key ?


I mean, I could just upload my certificate with the private key included in fx. PEM, no worries, but does it support it ?
I think the answer is no, because when I try, i get the error : "Unknown Error Failed Device Cert does not match private key" (even when I have not created a CSR yet directly on the MX).
But documentation is unclear. Documentation states : "Administrators can generate a CSR, that can be signed by a public CA." - Key-word here "can" , not "must".




6 Replies 6
Kind of a big deal

Perhaps it does not support 3rd party CSR, but at least I got it so far now that I get another error message : Unknown Error Failed verifying Device Cert with Cert Chain

So I guess I just need to create the right CA chain for it to work ?

Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

Hi @thomasthomsen ,

Correct. The Chain of Trust is a must.  😉 

See the below excerpt from the AnyConnect Authentication Methods guide.


"AnyConnect server will use the uploaded trusted CA certificate to validate authenticating clients before requesting for the users' credentials.




Ivan Jukić,
Meraki APJC

If you found this post helpful, please give it kudos. If it solved your problem, click "accept as solution" so that others can benefit from it.
Kind of a big deal

But that does not really give an answer to my original question, and why , as mentioned below, it would, apparently, never work because I did my CSR "offline" so to speak. 

Or let me re-phrase, why would it complain about certchain, when i try to import the signed cert (with the private key) from my "offline" CSR, if it does not even support this ?

Kind of a big deal

PS: And this is not for "certificate based authentication" as the document you are pointing to, but "Server certificates" on the MX itself, for the initial connection :

Kind of a big deal
Kind of a big deal

>do the MX support custom certificate where the MX did not do the CSR/Private key ?



Kind of a big deal

So we agree that the documentation is "unclear" here then ? 🙂

(Especially if you ONLY have the new Anyconnect look and feel, where it does not even say 1. 2. 3.  --- and you dont have to do 1, in order to just start uploading certs at 3).

Get notified when there are additional replies to this discussion.