Redirecting you to
Tech Document Sep 26, 2018

How to Generate Certificate Signing Request on Cisco ASA 5500 VPN

This article will go into detail on how to generate certificate signing request on Cisco ASA 5500 VPN.

  1. From the Cisco Adaptive Security Device Manager (ASDM), select "Configuration" and then "Device Management."
  2. Expand "Certificate Management," then select "Identity Certificates," and then "Add."
  3. Change the key size to 2048 and leave Usage on General purpose.
  4. Next you will define the "Certificate Subject DN" by clicking the Select button to the right of that field. In the Certificate Subject DN window, configure the following values by selecting each from the "Attribute" drop-down list, entering the appropriate value, and clicking "Add."

    CN - The name through which the firewall will be accessed (usually the fully-qualified domain name, e.g.,

    OU - The name of your department within the organization (frequently this entry will be listed as "IT," "Web Security," or is simply left blank).

    O - The legally registered name of your organization/company.

    C - If you do not know your country's two digit code, find it on our list.

    ST - The state in which your organization is located.

    L - The city in which your organization is located.

    Please note: None of the above fields should exceed a 64 character limit. Exceeding that limit could cause problems later on while trying to install your certificate.

  5. Next, click "Advanced" in the "Add Identity Certificate" window.
  6. In the FQDN field, type in the fully-qualified domain name through which the device will be accessed externally, e.g., (or the same name as was entered in the CN value in step 5).
  7. Click "OK" and then "Add Certificate." You will then be prompted to save your newly created CSR information as a text file (.txt extension).

    Remember the filename that you choose and the location to which you save it. You will need to open this file as a text file and copy the entire body of it (including the Begin and End Certificate Request tags) into the online order process when prompted.

  8. After you receive your SSL Certificate, you can install it.