<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Pradip, in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019396#M7185</link>
    <description>&lt;P&gt;Hi Pradip,&lt;/P&gt;
&lt;P&gt;Watch the video in the following link, there are some parameters (in blue color) you should take in consideration while signing the CSR by your CA.&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/video/11933356/steps-enable-https-proxy-wsa-certificate-signing-request-csr-option&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To request a certificate by using a PKCS&amp;nbsp;#10 or PKCS&amp;nbsp;#7 file &lt;/STRONG&gt;&lt;/P&gt;
&lt;OL class="ordered"&gt;
&lt;LI&gt;
&lt;P&gt;Open a Web browser.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Open https://&lt;EM&gt;servername&lt;/EM&gt;/certsrv, where &lt;EM&gt;servername&lt;/EM&gt; is the name of the Web server hosting the CA Web enrollment pages.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Click &lt;STRONG&gt;Request a certificate&lt;/STRONG&gt;, and then click &lt;STRONG&gt;Advanced certificate request&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Click &lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;Submit a certificate request using a base-64-encoded CMC or PKCS&amp;nbsp;#10 file&lt;/STRONG&gt; or &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="color: #0000ff;"&gt;Submit a renewal request by using a base-64-encoded PKCS&amp;nbsp;#7&lt;/SPAN&gt; file&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In Notepad, click &lt;STRONG&gt;File&lt;/STRONG&gt;, click &lt;STRONG&gt;Open&lt;/STRONG&gt;, select the PKCS&amp;nbsp;#10 or PKCS&amp;nbsp;#7 file, click &lt;STRONG&gt;Edit&lt;/STRONG&gt;, click &lt;STRONG&gt;Select all&lt;/STRONG&gt;, click &lt;STRONG&gt;Edit&lt;/STRONG&gt;, and then click &lt;STRONG&gt;Copy&lt;/STRONG&gt;. On the Web page, click in the &lt;STRONG&gt;Saved request&lt;/STRONG&gt; box. Click &lt;STRONG&gt;Edit&lt;/STRONG&gt;, and then click &lt;STRONG&gt;Paste&lt;/STRONG&gt; to paste the contents of the certificate request into the box.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Choose &lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;Subordinate CA&lt;/STRONG&gt;&lt;/SPAN&gt; as the certificate template you want to use.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Click &lt;STRONG&gt;Submit&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regards!&lt;/P&gt;
&lt;P&gt;Jocelyn&lt;/P&gt;</description>
    <pubDate>Mon, 13 Mar 2017 10:22:05 GMT</pubDate>
    <dc:creator>ZINSOU ADAM JOCELYN ADISSO</dc:creator>
    <dc:date>2017-03-13T10:22:05Z</dc:date>
    <item>
      <title>Cisco WSA https Proxy Certificate Issue</title>
      <link>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019392#M7181</link>
      <description>&lt;P&gt;we recently installed Cisco WSA S380 in our environment. We enabled https proxy and generate CSR and send it to sign when we got the signed certificate and tried to upload we got error mentioning " Error — Certificate upload failed. The certificate file appears to be a server certificate. A signing certificate is required". I have uploaded the root CA as well but didn't find any proper solution to solve this.&lt;/P&gt;
&lt;P&gt;Looking for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;
&lt;TABLE height="12" width="21" cellspacing="0" cellpadding="0" border="0"&gt;
&lt;TBODY&gt;
&lt;TR valign="top"&gt;
&lt;TD nowrap="nowrap"&gt;&lt;/TD&gt;
&lt;TD style="padding: 0 6px 0 3px;"&gt;&lt;/TD&gt;
&lt;TD id="action-results-message"&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 07 Mar 2017 06:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019392#M7181</guid>
      <dc:creator>Pradip Upreti</dc:creator>
      <dc:date>2017-03-07T06:33:42Z</dc:date>
    </item>
    <item>
      <title>Hi Pradip,</title>
      <link>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019393#M7182</link>
      <description>&lt;P&gt;Hi Pradip,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It seems you have used an incorrect template to generate the certificate.&lt;/P&gt;
&lt;P&gt;On the CA, make sure you&amp;nbsp;use the certificate template as a "subordinate CA" not the 'web server' template.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Kush&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 10:46:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019393#M7182</guid>
      <dc:creator>kushsriva</dc:creator>
      <dc:date>2017-03-07T10:46:36Z</dc:date>
    </item>
    <item>
      <title>Hi Kush,</title>
      <link>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019394#M7183</link>
      <description>&lt;P&gt;Hi Kush,&lt;/P&gt;
&lt;P&gt;Thanks for the reply, I will contact my certificate provider for the same hope this will solve our issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Pradip&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2017 04:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019394#M7183</guid>
      <dc:creator>Pradip Upreti</dc:creator>
      <dc:date>2017-03-08T04:30:11Z</dc:date>
    </item>
    <item>
      <title>I am unaware of any CAs</title>
      <link>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019395#M7184</link>
      <description>&lt;P&gt;I am unaware of any CAs (GlobalSign, Verisign, etc) that will issue the type of Certificate that you need. In order to do decryption you need a CA Cert or an Intermediate CA Cert.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;GlobalSign states this...&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&lt;A href="https://www.globalsign.com/en/certificate-authority-root-signing/"&gt;https://www.globalsign.com/en/certificate-authority-root-signing/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Trusted Root is a select service with strict requirements. &lt;SPAN style="text-decoration: underline;"&gt;Trusted Root is both technically and contractually prohibited from being used for deep packet inspection/scanning of outbound/inbound HTTPS traffic.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;You may be better served by generating a Self Signed Cert on the WSA or generating an Intermediate Cert from your own CA if you have a PKI infrastructure setup.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please rate helpful replies. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 21:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019395#M7184</guid>
      <dc:creator>Tim Glen</dc:creator>
      <dc:date>2017-03-09T21:00:56Z</dc:date>
    </item>
    <item>
      <title>Hi Pradip,</title>
      <link>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019396#M7185</link>
      <description>&lt;P&gt;Hi Pradip,&lt;/P&gt;
&lt;P&gt;Watch the video in the following link, there are some parameters (in blue color) you should take in consideration while signing the CSR by your CA.&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/video/11933356/steps-enable-https-proxy-wsa-certificate-signing-request-csr-option&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To request a certificate by using a PKCS&amp;nbsp;#10 or PKCS&amp;nbsp;#7 file &lt;/STRONG&gt;&lt;/P&gt;
&lt;OL class="ordered"&gt;
&lt;LI&gt;
&lt;P&gt;Open a Web browser.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Open https://&lt;EM&gt;servername&lt;/EM&gt;/certsrv, where &lt;EM&gt;servername&lt;/EM&gt; is the name of the Web server hosting the CA Web enrollment pages.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Click &lt;STRONG&gt;Request a certificate&lt;/STRONG&gt;, and then click &lt;STRONG&gt;Advanced certificate request&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Click &lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;Submit a certificate request using a base-64-encoded CMC or PKCS&amp;nbsp;#10 file&lt;/STRONG&gt; or &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="color: #0000ff;"&gt;Submit a renewal request by using a base-64-encoded PKCS&amp;nbsp;#7&lt;/SPAN&gt; file&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In Notepad, click &lt;STRONG&gt;File&lt;/STRONG&gt;, click &lt;STRONG&gt;Open&lt;/STRONG&gt;, select the PKCS&amp;nbsp;#10 or PKCS&amp;nbsp;#7 file, click &lt;STRONG&gt;Edit&lt;/STRONG&gt;, click &lt;STRONG&gt;Select all&lt;/STRONG&gt;, click &lt;STRONG&gt;Edit&lt;/STRONG&gt;, and then click &lt;STRONG&gt;Copy&lt;/STRONG&gt;. On the Web page, click in the &lt;STRONG&gt;Saved request&lt;/STRONG&gt; box. Click &lt;STRONG&gt;Edit&lt;/STRONG&gt;, and then click &lt;STRONG&gt;Paste&lt;/STRONG&gt; to paste the contents of the certificate request into the box.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Choose &lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;Subordinate CA&lt;/STRONG&gt;&lt;/SPAN&gt; as the certificate template you want to use.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Click &lt;STRONG&gt;Submit&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regards!&lt;/P&gt;
&lt;P&gt;Jocelyn&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 10:22:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/cisco-wsa-https-proxy-certificate-issue/m-p/3019396#M7185</guid>
      <dc:creator>ZINSOU ADAM JOCELYN ADISSO</dc:creator>
      <dc:date>2017-03-13T10:22:05Z</dc:date>
    </item>
  </channel>
</rss>

