Manually install an SSL certificate on my Cisco ASA 5500 VPN/Firewall
After your certificate request is approved, you can download your certificate from the SSL manager and install it on your Cisco Adaptive Security Appliance (ASA) 5500 VPN or firewall.
- Find the directory on your server where certificate and key files are stored, then upload your intermediate certificate (
gd_bundle.crt
or similar) and primary certificate (.crt
file with randomized name) into that folder. - Launch the Cisco ASDM (Adaptive Security Device Manager).
- In the list of icons near the top of the screen, click Configuration.
- On the left hand sidebar, click Remote Access VPN.
- In the new panel on the left, click to expand Certificate Management and click CA Certificates.
- On the right-hand side of the main panel, click Add.
- For the Trustpoint Name, simply enter a name to easily identify your intermediate certificate at a later date.
- Select the radio button to Install from a file and click Browse....
- Select your recently uploaded
gd_bundle.crt
(or similar) file and click OK. - Click Install Certificate to install the intermediate certificate.
- In the panel on the left, locate the expanded Certificate Management section and click Identity Certificates.
- Select your recently installed intermediate certificate, which will show Not Available for Issued By and Pending for Expiry Date.
- On the right-hand side of the main panel, click Install.
- Select the radio button to Install from a file and click Browse....
- Select your recently uploaded primary certificate (randomly named
.crt
file) and click OK. - Click Install Certificate.
- Click OK to close the success message.
- Back in the Cisco ASDM, find the panel on the left. Click to expand Advanced and click SSL Settings.
- In the Certificates section, select the interface used to terminate WebVPN sessions and click Edit.
- For Primary Enrolled Certificate, select your newly installed SSL from the drop down menu and click OK.
- Click Apply to finalize the settings for WebVPN sessions that terminate on your selected interface.
Next step
- Use our Certificate Checker to confirm the SSL is installed.
More info
Note: As a courtesy, we provide information about how to use certain third-party products, but we do not endorse or directly support third-party products and we are not responsible for the functions or reliability of such products. Third-party marks and logos are registered trademarks of their respective owners. All rights reserved.