Troubleshooting: Cisco AnyConnect Cannot Validate SecureAuth SHA-2 512 Certificates

Follow
    Applies to:
Deployment model:
  • On Premises
  • Version Affected: All
     
     

    Overview

    Cisco AnyConnect cannot validate a valid SHA-2 512 ECDSA SecureAuth-issued user certificate for VPN access, even though the proper SecureAuth root and intermediate certificate chain has already been uploaded to the Cisco ASA firewall. This issue is specific to the Windows OS, and is often seen on only a few affected end-user machines.

     

    Cause

    The affected machine's Windows registry key that controls which certificate signing algorithms are available doesn't have SHA512 enabled. The registry key value used in the initial installations of Windows 7, 8, and 8.1 disables the use of SHA2-512 algorithms over the Transport Layer Security (TLS) 1.2 protocol; Microsoft later released a patch that corrects this.

    A fresh installation of Windows 10 enables SHA2-512 by default. However, when a Windows 7, 8, or 8.1 system is upgraded to Windows 10 (rather than a fresh install), the old registry key value is carried over to the new OS version and the patch described above is never applied.

     

    Resolution

    Apply Microsoft's SHA512 is disabled in Windows when you use TLS 1.2 patch to the affected machine. This corrects the carried-over registry key so the machine's certificate store enables SHA2-512 over TLS 1.2, matching what a fresh Windows 10 install already has by default.


     

    Special Considerations

    This fix modifies a system-wide Windows registry key that controls which certificate signing algorithms the machine trusts — it is not specific to SecureAuth or Cisco AnyConnect, and can affect any other software on the machine that relies on the same setting. Back up the registry key before applying the patch, and confirm with the appropriate Windows or security team that enabling SHA2-512 over TLS 1.2 does not conflict with other software or security policy on that machine.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.