Click here to get back home

Cannot authenticate after MSCEP re-install

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Cannot authenticate after MSCEP re-install Alan 05-18-2006
Posted by Alan on May 18, 2006, 3:56 am
Please log in for more thread options
The CEP certificate on our CA expired and, not being able to renew it,
we were told to re-install the MSCEP program. This meant were able to
auto-enrol certificates from the Cisco VPN client but there was a
problem actually using them. There is only one CA.

The VPN concentrators are both Cisco VPN 3000 series. The existing unit
has certificates issued prior to SCEP re-install, the new (spare) unit
has freshly cut certificates. Other than this, there are no changes or
differences to the concentrators.
Certificates issued both manually and via MSCEP will not authenticate
on the existing VPN concentrator. They are able to authenticate against
the spare concentrator. Existing certificates are able to authenticate
against the existing concentrator but not against the spare.

In each case the client shows the same error - Received un-encrypted
ISAKPM packet, but our SA is crypto active. The spare concentrator's
error log complains: "Unable to complete certificate chain, reason =
Incomplete certificate chain" Both concentrators can see the CA OK.


Similar ThreadsPosted
Authenticate USB PORT October 18, 2006, 6:49 am
Radius server in a DMZ, how to authenticate AD users ? June 12, 2007, 4:35 am
Local account tries to authenticate to DC when service starts August 14, 2006, 10:09 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap