How To: Import a Certificate into the AnyConnect App on iOS

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    This article explains how to import a PFX certificate into the Cisco AnyConnect app on iOS so it can be used to authenticate to a VPN through a SecureAuth Adaptive Security Appliance (ASA) realm. This procedure is required because current versions of the AnyConnect app cannot access certificates stored in the iOS device's own certificate profile. Without following this procedure, users attempting to log in will see an error similar to the one below.

    Error message displayed in the AnyConnect app on iOS when a certificate has not been imported using this procedure.

     

    Prerequisite

    The ASA realm's Post Auth action must be set to Create PFX Link (ASA).

     

    Import the Certificate

    1. On the iOS device, log into the SecureAuth webpage to get a link to the PFX file.
    2. If you are using Safari, do not tap the link directly — doing so downloads the file into the iOS certificate profile, which AnyConnect cannot access. Instead, long-press the link and choose Copy Link.
    3. Switch to the AnyConnect app.
    4. Tap Diagnostics, then Certificates, then Import User Certificate.
    5. In the Enter URL box, paste the copied link and press Enter.
    6. AnyConnect downloads the certificate and prompts for a password. Enter the same password you used to log into the SecureAuth website.
    7. The certificate is now available in AnyConnect and can be used to log into the VPN.




     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.