Symptom
Users can't get the Certificate from the Local CA Server (while using the AnyConnect VPN), unless they are using the https://--IP--/+CSCOCA+/enroll.html URL.
Conditions
Using ASA version 9.12(4)9 and 9.12(4)30
Workaround
Download the Certificate from web (https://--IP--/+CSCOCA+/enroll.html URL)
Further Problem Description