IPsec, L2TP, Split tunneling, PPTP and all other VPN related posts.
Hello,I try to install a digital certifcate from verisign on a vpn concentrator (release 4.1.6). This certificate shall be used for WebVPN-HTTPS (SSL).When I try to install the certificate for SSL I get following error message:Error installing SSL certificate: Incomplete chain.(The certificate has a duration till 2006. The only note I have found on CCO is the duration of the certificate is longer then 2048).Has anybody an idea what is wrong ??Thanks Horst
You'll usually get this message if you haven't loaded the CA (root) cert onto the 3000 before trying to load the identity cert. You can't have an identity cert for SSL from an external CA server without having the root cert from that CA server installed also.Go under Administration - Certificate Mgmt - CLick here to install a CA certificate, install that first then install the SSL cert.
Is there a difference between a cert for CA and for ssl ?I have installed the CA cert and then I produced under SSl Certificates - Enrollment - Enroll via PKCS10 (manual) a CSR File. Verisign sends me back the cert.But if I try to install that I get the error message as you can see above.Under Enrollment Status I can see it "in progress"Have a look to the attachment to see the screenshot !There is no Identity Certificate - is that right ??Thanks Horst