Cisco Bug: CSCur27553 - SCH not using trustpool after trustpoint expiration failure
Last Modified
Apr 16, 2020
Products (1)
- Cisco ASA 5500-X Series Firewalls
Known Affected Releases
100.12(6.13) 9.2(1)
Description (partial)
Symptom: ASA fails to use trustpool for SCH SSL cert validation after resident SubCA cert in trustpoint is found to be expired. Conditions: When using Smart Call Home (SCH), and the ASA is processing the SCH SSL server cert, it should attempt to use the automatically created trustpoint called _SmartCallHome_ServerCA. When the SubCA cert associated with this trustpoint is expired, the ASA should proceed to use the trustpool (when enabled). The ASA is not using trustpool in this case.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Status
- Severity
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases