Cisco ASA - Certificate based IPSEC VPN "ERROR: Certificate validation failed. Peer certificate key usage is invalid"
When trying to connect using the Cisco VPN Client with certificate based authentication you receive the following error from you debug logs.
This error can occur if the certificate doesn't have the digital signature key usage set.
To resolve this either :
- create a certificate with the digital signature key usage set. i.e if using a Windows 2008 CA then use the IPSEC certificate template.
- configure the ASA to ignore the IPSEC key usage. This configured using the following commands:
crypto ca trustpoint <trustpointname>