Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Adding a Windows Server CA to the CA List

Hi All

I am new to XG and having certificate issues.

I want to be able to add my own Windows Server Certificate Authority to the XG.  The Windows CA is the root for my environment.  I have used the Windows Server CA web admin to download the CA certificate, however I cannot get the XG to accept the certificate no matter what option I use. I get this error "Certificate Authority could not be uploaded". 

I am also having trouble importing commercial host certificates (DigiCert), including certificates that used a CSR created on the XG.  I have tried to update their CA certificates but have the same issue as with the Windows CA.

I have tried all manner of certificate formats, without luck.  It is like the whole certificate service is broken, or I don't have the correct rights to perform certificate functions.  All the different certificates I have tried all import into Windows and Linux hosts are appear to work fine.

I am using version XG 16.01.0 running in Hyper-V.

Can anyone please advise.

Thanks in advance

 



This thread was automatically locked due to age.
Parents
  • I have exactly the same issue. 

    SFVH_SO01_SFOS 16.01.1

    Certificates are from Godaddy. Cant add the certificates in PEM, DER or P12 format. Also cant add the GoDaddy CA bundle/root cert. All I get is "certificate authority could not be uploaded". It looks like the entire certificate management is broken in 16.01.1. Not sure if I can add these via the advanced shell as a workaround?

    Anyone please help. 

  • Make sure to add the Certificate Authority before adding the signed certificates released from godaddy or whatever CA is. Even if you see godaddy inside the CA TAB, upload the CA (it is bundle within the zip).

    Thanks

  • Yep, I know I have to do that.  I tried to add the bundle and thats when I'm getting the "certificate authority could not be uploaded" error. Tried converting the bundle which they issue in .crt format to PEM and DER but I get the same error. 

    I also tried to separate the 3 certs inside the bundle to try and upload them one by one but I get the same error still.

     

Reply
  • Yep, I know I have to do that.  I tried to add the bundle and thats when I'm getting the "certificate authority could not be uploaded" error. Tried converting the bundle which they issue in .crt format to PEM and DER but I get the same error. 

    I also tried to separate the 3 certs inside the bundle to try and upload them one by one but I get the same error still.

     

Children