<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACI Simulator Sandbox Certificate Error in DevNet Sandbox</title>
    <link>https://community.cisco.com/t5/devnet-sandbox/aci-simulator-sandbox-certificate-error/m-p/3840103#M3533</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The certificate installed on the ACI Simulator Sandbox (&lt;A href="https://sandboxapicdc.cisco.com/" target="_blank"&gt;https://sandboxapicdc.cisco.com/&lt;/A&gt;) is not the correct one.&amp;nbsp; The certificate presented when browsing to the APIC has no SAN (Subject Alternative Name) configured, and the Common Name is configured as “devnetsbx-netacad-apicem-1.cisco.com”, which is a URL that points to an APIC-EM (i.e. something else entirely).&amp;nbsp; The certificate configured on the Simulator needs to be changed.&lt;/P&gt;
&lt;P&gt;I would also highlight that the certificate must have the identities (hostname/FQDN etc.) that will be used to connect to it in the SAN field.&amp;nbsp; The use of Common Name in browsers as part of the certificate identity checks has been deprecated for some time now, so failure to specify a SAN will cause browsers to throw cert warnings.&amp;nbsp; See &lt;A href="https://textslashplain.com/2017/03/10/chrome-deprecates-subject-cn-matching/" target="_blank"&gt;https://textslashplain.com/2017/03/10/chrome-deprecates-subject-cn-matching/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Cheers, Lee&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2019 09:49:07 GMT</pubDate>
    <dc:creator>lwainwri</dc:creator>
    <dc:date>2019-06-04T09:49:07Z</dc:date>
    <item>
      <title>ACI Simulator Sandbox Certificate Error</title>
      <link>https://community.cisco.com/t5/devnet-sandbox/aci-simulator-sandbox-certificate-error/m-p/3840103#M3533</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The certificate installed on the ACI Simulator Sandbox (&lt;A href="https://sandboxapicdc.cisco.com/" target="_blank"&gt;https://sandboxapicdc.cisco.com/&lt;/A&gt;) is not the correct one.&amp;nbsp; The certificate presented when browsing to the APIC has no SAN (Subject Alternative Name) configured, and the Common Name is configured as “devnetsbx-netacad-apicem-1.cisco.com”, which is a URL that points to an APIC-EM (i.e. something else entirely).&amp;nbsp; The certificate configured on the Simulator needs to be changed.&lt;/P&gt;
&lt;P&gt;I would also highlight that the certificate must have the identities (hostname/FQDN etc.) that will be used to connect to it in the SAN field.&amp;nbsp; The use of Common Name in browsers as part of the certificate identity checks has been deprecated for some time now, so failure to specify a SAN will cause browsers to throw cert warnings.&amp;nbsp; See &lt;A href="https://textslashplain.com/2017/03/10/chrome-deprecates-subject-cn-matching/" target="_blank"&gt;https://textslashplain.com/2017/03/10/chrome-deprecates-subject-cn-matching/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Cheers, Lee&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 09:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/devnet-sandbox/aci-simulator-sandbox-certificate-error/m-p/3840103#M3533</guid>
      <dc:creator>lwainwri</dc:creator>
      <dc:date>2019-06-04T09:49:07Z</dc:date>
    </item>
  </channel>
</rss>

