<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you are confident, you can in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916204#M6776</link>
    <description>&lt;P&gt;If you are confident, you can perform below:&lt;/P&gt;
&lt;P&gt;- save the configuration file from the S170&lt;/P&gt;
&lt;P&gt;- Go to the same section for that certificate from the S170 configuration file and check if the cert is valid.&lt;/P&gt;
&lt;P&gt;- If its valid you can copy them (you will need to copy from the cert_name, the cert it self and the key)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Then paste them(in the exact section in the config file) to the existing configuration file that you want to upload&lt;/P&gt;
&lt;P&gt;If not you can always open TAC case to get assistance&lt;/P&gt;</description>
    <pubDate>Sun, 26 Jun 2016 08:51:59 GMT</pubDate>
    <dc:creator>Handy Putra</dc:creator>
    <dc:date>2016-06-26T08:51:59Z</dc:date>
    <item>
      <title>WSA config load</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916195#M6767</link>
      <description>&lt;P&gt;I am trying to load a configuration on my WSA appliance and I am receiving this error:&lt;/P&gt;
&lt;P&gt;Error&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp; Configuration File was not loaded. Parse Error on element "wga_config" line number 1090 column 15: Error in certificate validation: Signing key has expired.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have loaded configs and the past and had No problems, can someone tell me what this msg means?&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 14:02:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916195#M6767</guid>
      <dc:creator>cmazur</dc:creator>
      <dc:date>2016-06-13T14:02:21Z</dc:date>
    </item>
    <item>
      <title>It looks a duplicated thread</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916196#M6768</link>
      <description>&lt;P&gt;It looks a duplicated thread of&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/discussion/13044706/wsa-config-load&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 00:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916196#M6768</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2016-06-14T00:29:32Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916197#M6769</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;not able to open the link , i am having the same issue , what was done to resolve&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;any help highly appreciated&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 04:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916197#M6769</guid>
      <dc:creator>sunilferrao</dc:creator>
      <dc:date>2016-06-26T04:39:03Z</dc:date>
    </item>
    <item>
      <title>The error advised that the</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916198#M6770</link>
      <description>&lt;P&gt;The error advised that the signing certificate in the appliance has been expired.&lt;/P&gt;
&lt;P&gt;You can check the expiry date of the certificate from your HTTPS proxy page (GUI -&amp;gt; Security Services -&amp;gt; HTTPS proxy)&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 06:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916198#M6770</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2016-06-26T06:33:25Z</dc:date>
    </item>
    <item>
      <title>Hello Handy</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916199#M6771</link>
      <description>&lt;P&gt;Hello Handy&lt;/P&gt;
&lt;P&gt;Thanks for your response&lt;/P&gt;
&lt;P&gt;basically i am trying to restore the config from c160 to c170 box and stuck in WSA_config&lt;/P&gt;
&lt;P&gt;What needs to done to bypass this error , the mentioned option is disabled ( https-proxy) in c160 config&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;
&lt;P&gt;Snl&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 07:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916199#M6771</guid>
      <dc:creator>sunilferrao</dc:creator>
      <dc:date>2016-06-26T07:41:30Z</dc:date>
    </item>
    <item>
      <title>Can you confirm the appliance</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916200#M6772</link>
      <description>&lt;P&gt;Can you confirm the appliance is WSA or ESA since C160/C170 is Email security appliance not WSA.&lt;/P&gt;
&lt;P&gt;Are you able to share the configuration file for me have a look.&lt;/P&gt;
&lt;P&gt;Alternatively open TAC case for them to investigate which cert that showing as expired from the config file.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 07:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916200#M6772</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2016-06-26T07:46:59Z</dc:date>
    </item>
    <item>
      <title>Hello Handy</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916201#M6773</link>
      <description>&lt;P&gt;Hello Handy&lt;/P&gt;
&lt;P&gt;its S160 wsa and we trying to migrate the xml config to S170 new rma box&lt;/P&gt;
&lt;P&gt;sorry for the confusion&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;snl&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 08:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916201#M6773</guid>
      <dc:creator>sunilferrao</dc:creator>
      <dc:date>2016-06-26T08:27:00Z</dc:date>
    </item>
    <item>
      <title>I think you are referring to</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916202#M6774</link>
      <description>&lt;P&gt;I think you are referring to S160 model for WSA since anything that has C in front of it is dedicated for Email Security Appliance (ESA) not WSA.&lt;/P&gt;
&lt;P&gt;would suggest open a TAC case for the engineer to check which cert in the config file that showing as expired&lt;/P&gt;
&lt;P&gt;You can also search the cert from the config file:&lt;/P&gt;
&lt;P&gt;- Open the config file using XML editor&lt;/P&gt;
&lt;P&gt;- Search for any cert keywords such as:&amp;nbsp;generated_cert or&amp;nbsp;secure_auth_cert or&amp;nbsp;uploaded_cert&lt;/P&gt;
&lt;P&gt;- copy the cert and use SSLshopper to help you decode the cert to see if its still valid:&lt;/P&gt;
&lt;P&gt;https://www.sslshopper.com/certificate-decoder.html&lt;/P&gt;
&lt;P&gt;- If its showing expired, you can replaced it or delete it if the certs are generated cert or uploaded cert or you can use the cert that you have from the replacement unit and paste it to the same section of the configuration file that you need to loads.&lt;/P&gt;
&lt;P&gt;However still recommend to contact TAC for further assistance&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 08:32:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916202#M6774</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2016-06-26T08:32:35Z</dc:date>
    </item>
    <item>
      <title>Hello Handy</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916203#M6775</link>
      <description>&lt;P&gt;Hello Handy&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for your kind support&amp;nbsp; , indeed cert expired&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;DIV style="display: block; overflow: auto;" id="certData"&gt;
&lt;DIV class="decodedInfo"&gt;&lt;STRONG&gt;Certificate Information:&lt;/STRONG&gt;
&lt;H5&gt;&lt;B&gt;Common Name:&lt;/B&gt; IronPort Appliance Demo Certificate&lt;/H5&gt;
&lt;H5&gt;&lt;B&gt;Organization:&lt;/B&gt; IronPort Systems, Inc.&lt;/H5&gt;
&lt;H5&gt;&lt;B&gt;Locality:&lt;/B&gt; San Bruno&lt;/H5&gt;
&lt;H5&gt;&lt;B&gt;State:&lt;/B&gt; California&lt;/H5&gt;
&lt;H5&gt;&lt;B&gt;Country:&lt;/B&gt; US&lt;/H5&gt;
&lt;H5&gt;&lt;B&gt;Valid From:&lt;/B&gt; May 1, 2006&lt;/H5&gt;
&lt;H5&gt;&lt;B&gt;Valid To:&lt;/B&gt; May 1, 2016&lt;/H5&gt;
&lt;H5&gt;&lt;B&gt;Issuer:&lt;/B&gt; IronPort Appliance Demo Certificate, IronPort Systems, Inc.&lt;/H5&gt;
&lt;H5&gt;&lt;B&gt;Serial Number:&lt;/B&gt; 1 (0x1)&lt;/H5&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i may need to raise tac now&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;S&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 26 Jun 2016 08:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916203#M6775</guid>
      <dc:creator>sunilferrao</dc:creator>
      <dc:date>2016-06-26T08:47:40Z</dc:date>
    </item>
    <item>
      <title>If you are confident, you can</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916204#M6776</link>
      <description>&lt;P&gt;If you are confident, you can perform below:&lt;/P&gt;
&lt;P&gt;- save the configuration file from the S170&lt;/P&gt;
&lt;P&gt;- Go to the same section for that certificate from the S170 configuration file and check if the cert is valid.&lt;/P&gt;
&lt;P&gt;- If its valid you can copy them (you will need to copy from the cert_name, the cert it self and the key)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Then paste them(in the exact section in the config file) to the existing configuration file that you want to upload&lt;/P&gt;
&lt;P&gt;If not you can always open TAC case to get assistance&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 08:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916204#M6776</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2016-06-26T08:51:59Z</dc:date>
    </item>
    <item>
      <title>Strangely new s170 box also</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916205#M6777</link>
      <description>&lt;P&gt;Strangely new s170 box also have same certificate which is expired &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 09:05:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916205#M6777</guid>
      <dc:creator>sunilferrao</dc:creator>
      <dc:date>2016-06-26T09:05:34Z</dc:date>
    </item>
    <item>
      <title>That is strange.</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916206#M6778</link>
      <description>&lt;P&gt;That is strange.&lt;/P&gt;
&lt;P&gt;You will need TAC case for them to use their internal WSA appliances that are still valid and edited your configuration file.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 09:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916206#M6778</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2016-06-26T09:08:58Z</dc:date>
    </item>
    <item>
      <title>TAC has been raised , its a</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916207#M6779</link>
      <description>&lt;P&gt;TAC has been raised , its a bug CSCuh31504&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 12:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916207#M6779</guid>
      <dc:creator>sunilferrao</dc:creator>
      <dc:date>2016-06-26T12:24:20Z</dc:date>
    </item>
    <item>
      <title>I got the same problem and</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916208#M6780</link>
      <description>&lt;P&gt;I got the same problem and opened a TAC case.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The engineer told me to delete everything between those tags:&lt;BR /&gt;&amp;lt;prox_config_secure_auth_cert_name&amp;gt;&amp;lt;/prox_config_secure_auth_cert_name&amp;gt;&amp;lt;prox_config_secure_auth_cert&amp;gt;&amp;lt;/prox_config_secure_auth_cert&amp;gt;&lt;BR /&gt;&amp;lt;prox_config_secure_auth_key&amp;gt;&amp;lt;/prox_config_secure_auth_key&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Loading the config into the appliance worked just fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 09:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916208#M6780</guid>
      <dc:creator>FM2011</dc:creator>
      <dc:date>2016-07-05T09:32:13Z</dc:date>
    </item>
    <item>
      <title>You are not authorized to</title>
      <link>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916209#M6781</link>
      <description>&lt;P&gt;&lt;SPAN&gt;You are not authorized to access this page. Trying to open&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/discussion/13044706/wsa-config-load"&gt;https://supportforums.cisco.com/discussion/13044706/wsa-config-load&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 15:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-config-load/m-p/2916209#M6781</guid>
      <dc:creator>Artem Grigoryev</dc:creator>
      <dc:date>2016-08-01T15:49:27Z</dc:date>
    </item>
  </channel>
</rss>

