Guest

Preview Tool

Cisco Bug: CSCur27553 - SCH not using trustpool after trustpoint expiration failure

Last Modified

Apr 16, 2020

Products (1)

  • Cisco ASA 5500-X Series Firewalls

Known Affected Releases

100.12(6.13) 9.2(1)

Description (partial)

Symptom:
ASA fails to use trustpool for SCH SSL cert validation after resident SubCA cert in trustpoint is found to be expired.

Conditions:
When using Smart Call Home (SCH), and the ASA is processing the SCH SSL server cert, it should attempt to use the automatically created trustpoint called _SmartCallHome_ServerCA.  When the SubCA cert associated with this trustpoint is expired, the ASA should proceed to use the trustpool (when enabled).  The ASA is not using trustpool in this case.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.