<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL proxy using p12 certificate file in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ssl-proxy-using-p12-certificate-file/m-p/1506769#M31020</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got it work. The ACE does accept p12 certificate and key file. It was some configuration problem on web servers. I also have tried use openssl command to convert p12 to pem format and applied them in to ACE. it works either way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Oct 2010 21:01:09 GMT</pubDate>
    <dc:creator>liangzheng</dc:creator>
    <dc:date>2010-10-04T21:01:09Z</dc:date>
    <item>
      <title>SSL proxy using p12 certificate file</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-proxy-using-p12-certificate-file/m-p/1506766#M31017</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am configuring SSL termination for a e-commence site. The only certificate and key file for the site is in .p12 format. I have successfully imported the file in ACE context:&lt;/P&gt;&lt;P&gt;Tor-ACE/StagingFrontEnd-LB# sh crypto files&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Filename&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File&amp;nbsp; File&amp;nbsp;&amp;nbsp;&amp;nbsp; Expor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key/&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Size&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp; table&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cert&lt;BR /&gt;-----------------------------------------------------------------------&lt;BR /&gt;secure.seOOOO.ca.p12&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5066&amp;nbsp; PKCS12&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; BOTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tor-ACE/StagingFrontEnd-LB#&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when I configured this cert and key in SSL proxy service, the SSL proxy server didn't work. When I change the cert and key file to cisco sample file, it was working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2010 15:39:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-proxy-using-p12-certificate-file/m-p/1506766#M31017</guid>
      <dc:creator>liangzheng</dc:creator>
      <dc:date>2010-10-04T15:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSL proxy using p12 certificate file</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-proxy-using-p12-certificate-file/m-p/1506767#M31018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; In order for the ACE to terminate SSL, the certs/key need to be in PEM format.&amp;nbsp; Please see the attached configuration guide for SSL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/partner/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/ssl/guide/certkeys.html#wp1052415"&gt;http://www.cisco.com/en/US/partner/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/ssl/guide/certkeys.html#wp1052415&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Oct 2010 15:44:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-proxy-using-p12-certificate-file/m-p/1506767#M31018</guid>
      <dc:creator>cpomeroy</dc:creator>
      <dc:date>2010-10-04T15:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSL proxy using p12 certificate file</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-proxy-using-p12-certificate-file/m-p/1506768#M31019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James/Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to clarify the ACE does support PKCS12 from the very beginning either on the APP or MOD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sounds like your problem could be either that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You only associated the file once under the ssl service. The file needs to be associated with the cert and the key using the same name:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;ssl-proxy service VIP&lt;BR /&gt;&amp;nbsp; key &lt;/SPAN&gt;&lt;SPAN style="color: #339966; font-size: 8pt; font-family: courier new,courier; "&gt;secure.seOOOO.ca.p12&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;&lt;BR /&gt;&amp;nbsp; cert &lt;/SPAN&gt;&lt;SPAN style="color: #339966; font-size: 8pt; font-family: courier new,courier; "&gt;secure.seOOOO.ca.p12&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or you didn't specify the cert passphrase when importing the file:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;switch/Admin# show crypto file&lt;BR /&gt;Filename&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File&amp;nbsp; File&amp;nbsp;&amp;nbsp;&amp;nbsp; Expor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key/&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Size&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp; table&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cert&lt;BR /&gt;-----------------------------------------------------------------------&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 8pt; font-family: courier new,courier; "&gt;secure.seOOOO.ca.p12&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 8pt; font-family: courier new,courier; "&gt;5066&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 8pt; font-family: courier new,courier; "&gt;PKCS12&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 8pt; font-family: courier new,courier; "&gt;&amp;nbsp; No &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 8pt; font-family: courier new,courier; "&gt;BOTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;&lt;SPAN style="color: #000000;"&gt;ACE/Cisco# crypto import ftp &lt;SPAN style="color: #ff0000;"&gt;passphrase &lt;SPAN style="color: #000000;"&gt;password123 10.20.5.10 &lt;USERNAME&gt; &lt;LOCALFILE&gt; secure.seOOOO.ca.p12&lt;/LOCALFILE&gt;&lt;/USERNAME&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;Password:&lt;BR /&gt;Passive mode on.&lt;BR /&gt;Hash mark printing on (1024 bytes/hash mark).&lt;BR /&gt;##&lt;BR /&gt;Successfully imported file from remote server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;__ __&lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Oct 2010 20:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-proxy-using-p12-certificate-file/m-p/1506768#M31019</guid>
      <dc:creator>Pablo</dc:creator>
      <dc:date>2010-10-04T20:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSL proxy using p12 certificate file</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-proxy-using-p12-certificate-file/m-p/1506769#M31020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got it work. The ACE does accept p12 certificate and key file. It was some configuration problem on web servers. I also have tried use openssl command to convert p12 to pem format and applied them in to ACE. it works either way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Oct 2010 21:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-proxy-using-p12-certificate-file/m-p/1506769#M31020</guid>
      <dc:creator>liangzheng</dc:creator>
      <dc:date>2010-10-04T21:01:09Z</dc:date>
    </item>
  </channel>
</rss>

