<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WSA Change HTTPS Certificate in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/3754859#M8199</link>
    <description>&lt;P&gt;The problem is that I setup certificate from CLI from PEM format and even imported using GUI in P12 format and chose it from CLI. However when I enter WSA it still give me the old Certificate with wrong url. I mean although I imported the certificate and selected it from CLI, it doesn`t change.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Nov 2018 04:52:59 GMT</pubDate>
    <dc:creator>orkhan.rustamli.96</dc:creator>
    <dc:date>2018-11-29T04:52:59Z</dc:date>
    <item>
      <title>WSA Change HTTPS Certificate</title>
      <link>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/3754113#M8194</link>
      <description>&lt;P&gt;Hello, everyone. I would like to change the web interface https certificate of my WSA because&amp;nbsp;previous&amp;nbsp;workers issued the certificate with wrong URL and therefore although everything is installed it still gives an error. I changed through CLI however nothing changed. WSA still uses old one. My question do I have to reload the ironport for changes to take effect? I haven`t tried it because I cannot stop the users system. I wanted to be sure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 07:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/3754113#M8194</guid>
      <dc:creator>orkhan.rustamli.96</dc:creator>
      <dc:date>2018-11-28T07:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: WSA Change HTTPS Certificate</title>
      <link>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/3754727#M8198</link>
      <description>&lt;P&gt;For WSA management&amp;nbsp;cert you can generate new certificate and install, not required reboot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 22:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/3754727#M8198</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-11-28T22:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: WSA Change HTTPS Certificate</title>
      <link>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/3754859#M8199</link>
      <description>&lt;P&gt;The problem is that I setup certificate from CLI from PEM format and even imported using GUI in P12 format and chose it from CLI. However when I enter WSA it still give me the old Certificate with wrong url. I mean although I imported the certificate and selected it from CLI, it doesn`t change.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 04:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/3754859#M8199</guid>
      <dc:creator>orkhan.rustamli.96</dc:creator>
      <dc:date>2018-11-29T04:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: WSA Change HTTPS Certificate</title>
      <link>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/3989474#M8875</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same issue.&lt;/P&gt;&lt;P&gt;Changed the certificate using the web interface, but still getting the old one.&lt;/P&gt;&lt;P&gt;Did you managed to solve this issue? How?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;João Domingues&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 13:02:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/3989474#M8875</guid>
      <dc:creator>joaodomingues</dc:creator>
      <dc:date>2019-11-26T13:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: WSA Change HTTPS Certificate</title>
      <link>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/4004482#M8910</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN class="user-badges-list"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;A class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/210745" target="_self"&gt;orkhan.rustamli&lt;WBR /&gt;.96/&lt;SPAN&gt;joaodomingues,&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class="user-badges-list"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Please make sure you submit and commit the details before you download&amp;nbsp;the certificate.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;System administration -&amp;gt; Https proxy -&amp;gt;edit settings&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;If you are generating a self signed certificate on the WSA, you click "Generated Certificate and Key". You get a popup where it asks for Common name, Organization, Organizational Unit etc" you fill all this up and go to the bottom of the page and submit the details and commit changes (twice). Only now the new cert will be in use. now come&amp;nbsp; back to the same page&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;System administration -&amp;gt; Https proxy -&amp;gt;edit settings&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;Now go ahead and download the certificate&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;The downloaded certificate needs to be present on all users machine in the trusted certificate store of all the browsers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;if you need to download a certificate signing request, click download certificate signing request (CSR), take this CSR to your CA, get it signed and get a certificate. Come back to the same page and browse and upload this certificate. submit and commit the changes. Only then this new certificate will be used. In this case make sure your Root CA is present in all the user machine browsers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Shikha Grover&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and select as validated answer if this answered your question&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2019 14:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-change-https-certificate/m-p/4004482#M8910</guid>
      <dc:creator>shgrover</dc:creator>
      <dc:date>2019-12-29T14:10:01Z</dc:date>
    </item>
  </channel>
</rss>

