<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NX-OS PKI SHA2 CSR in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/nx-os-pki-sha2-csr/m-p/3009220#M43308</link>
    <description>&lt;P&gt;&lt;FONT color="#000000" face="Calibri"&gt;Hi, &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;For our production implementation of Cisco Nexus Data Broker on Nexus 3100 series switches we are using centralised mode and OpenFlow.&amp;nbsp; In order to secure the connection between the controller and switch we require TLS and the use of our enterprise PKI.&amp;nbsp; Our PKI supports only SHA2 certificates and has specific requirements for fields to be included in the CSR.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;Creating the CSR on within NX-OS provides &lt;/FONT&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus3000/sw/security/6x/b_Cisco_n3k_Security_Config_6x/b_Cisco_n3k_Security_Config_6x_chapter_01100.html#task_2185183"&gt;&lt;U&gt;&lt;FONT color="#0563c1" face="Calibri"&gt;extremely limited options&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;FONT color="#000000" face="Calibri"&gt; and all requests are SHA-1.&amp;nbsp; SHA-1 was officially deprecated by NIST in 2011 yet I see no way of using SHA2 certificates with NX-OS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;I thought of creating the certificate using openssl and then importing in PKCS#12 Format, but not sure whether that will work?&amp;nbsp;&amp;nbsp; Any thoughts?&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;Cheers, &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;Andrew&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000" face="Times New Roman"&gt; &lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2017 14:27:00 GMT</pubDate>
    <dc:creator>Andrew Devine</dc:creator>
    <dc:date>2017-04-27T14:27:00Z</dc:date>
    <item>
      <title>NX-OS PKI SHA2 CSR</title>
      <link>https://community.cisco.com/t5/application-networking/nx-os-pki-sha2-csr/m-p/3009220#M43308</link>
      <description>&lt;P&gt;&lt;FONT color="#000000" face="Calibri"&gt;Hi, &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;For our production implementation of Cisco Nexus Data Broker on Nexus 3100 series switches we are using centralised mode and OpenFlow.&amp;nbsp; In order to secure the connection between the controller and switch we require TLS and the use of our enterprise PKI.&amp;nbsp; Our PKI supports only SHA2 certificates and has specific requirements for fields to be included in the CSR.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;Creating the CSR on within NX-OS provides &lt;/FONT&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus3000/sw/security/6x/b_Cisco_n3k_Security_Config_6x/b_Cisco_n3k_Security_Config_6x_chapter_01100.html#task_2185183"&gt;&lt;U&gt;&lt;FONT color="#0563c1" face="Calibri"&gt;extremely limited options&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;FONT color="#000000" face="Calibri"&gt; and all requests are SHA-1.&amp;nbsp; SHA-1 was officially deprecated by NIST in 2011 yet I see no way of using SHA2 certificates with NX-OS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;I thought of creating the certificate using openssl and then importing in PKCS#12 Format, but not sure whether that will work?&amp;nbsp;&amp;nbsp; Any thoughts?&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;Cheers, &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;Andrew&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000" face="Times New Roman"&gt; &lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 14:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/nx-os-pki-sha2-csr/m-p/3009220#M43308</guid>
      <dc:creator>Andrew Devine</dc:creator>
      <dc:date>2017-04-27T14:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: NX-OS PKI SHA2 CSR</title>
      <link>https://community.cisco.com/t5/application-networking/nx-os-pki-sha2-csr/m-p/3744563#M51047</link>
      <description>&lt;P&gt;Solved this by enabling bash and using openssl, then importing a pcks12 file&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 13:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/nx-os-pki-sha2-csr/m-p/3744563#M51047</guid>
      <dc:creator>Andrew Devine</dc:creator>
      <dc:date>2018-11-12T13:31:12Z</dc:date>
    </item>
  </channel>
</rss>

