<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower REST API Certificate question.. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-rest-api-certificate-question/m-p/4313580#M327</link>
    <description>&lt;P&gt;I'm trying to use REST API to GET details of external ca certificates I've uploaded via FDM gui, I've noticed the external ca certificates that come with the device show up with details but not the one I've uploaded...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ask because I'll like to make changes to the revocation configuration and the only way is by REST API...&lt;/P&gt;</description>
    <pubDate>Thu, 25 Mar 2021 06:01:40 GMT</pubDate>
    <dc:creator>dvo73d123</dc:creator>
    <dc:date>2021-03-25T06:01:40Z</dc:date>
    <item>
      <title>Firepower REST API Certificate question..</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rest-api-certificate-question/m-p/4313580#M327</link>
      <description>&lt;P&gt;I'm trying to use REST API to GET details of external ca certificates I've uploaded via FDM gui, I've noticed the external ca certificates that come with the device show up with details but not the one I've uploaded...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ask because I'll like to make changes to the revocation configuration and the only way is by REST API...&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 06:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rest-api-certificate-question/m-p/4313580#M327</guid>
      <dc:creator>dvo73d123</dc:creator>
      <dc:date>2021-03-25T06:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower REST API Certificate question..</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rest-api-certificate-question/m-p/4314119#M328</link>
      <description>&lt;P&gt;I just tried this on my 6.7 device it looks like Internal Certificates show detail when clicking on the pencil you will see something similar to this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_1abac187acbcaejarsmith_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_1abac187acbcaejarsmith_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="internal certificate.jpg" style="width: 262px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/107364i540E32EC313AFAB3/image-dimensions/262x239?v=v2" width="262" height="239" role="button" title="internal certificate.jpg" alt="internal certificate.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However external and user-defined external certificates have little very little detail beyond the name.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My suggestion would be to revert to the API explorer to query the details of the certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For external certificates go into the "Certificate" bucket and if you want to look at the CA certs I would suggest going into:&lt;/P&gt;
&lt;H3&gt;&lt;SPAN class="http_method"&gt;&lt;A class="toggleOperation" href="https://ast0072-pod.cisco.com:670/api-explorer/#!/Certificate/getExternalCACertificateList" target="_blank"&gt;GET&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="path"&gt;&lt;A class="toggleOperation " href="https:/api-explorer/#!/Certificate/getExternalCACertificateList" target="_self"&gt;/object/externalcacertificates&lt;/A&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN class="path"&gt;I uploaded Verisigns public certificate as a test and it ends up giving me data like the following regarding that cert:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="path"&gt;&lt;SPAN&gt;{ "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;version&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"jcd67gheb464u"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"verisign-test"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;cert&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"*********"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;privateKey&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-literal"&gt;null&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;passPhrase&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-literal"&gt;null&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;issuerCommonName&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"DigiCert EV RSA CA G2"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;issuerCountry&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"US"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;issuerLocality&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;""&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;issuerOrganization&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"DigiCert Inc"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;issuerOrganizationUnit&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;""&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;issuerState&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;""&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;subjectCommonName&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"&lt;A href="http://www.verisign.com" target="_blank"&gt;www.verisign.com&lt;/A&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;subjectCountry&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"US"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;subjectDistinguishedName&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;" businessCategory=Private Organization/jurisdictionC=US/jurisdictionST=Delaware/serialNumber=2497886, C=US, ST=Virginia, L=Reston, O=Verisign, Inc, OU=Enterprise IT, CN=&lt;A href="http://www.verisign.com" target="_blank"&gt;www.verisign.com&lt;/A&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;subjectLocality&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"Reston"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;subjectOrganization&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"Verisign, Inc"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;subjectOrganizationUnit&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"Enterprise IT"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;subjectState&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"Virginia"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;validityStartDate&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"Jul 13 00:00:00 2020 GMT"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;validityEndDate&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"Jul 14 12:00:00 2021 GMT"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;isSystemDefined&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-literal"&gt;false&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;revocationCheck&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"NONE"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;crlCacheTime&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-number"&gt;60&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;disableOcspNonce&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-literal"&gt;false&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;id&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"6d2facc4-8ccc-11eb-915e-d9dfa128b1fb"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;type&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"externalcacertificate"&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;links&lt;/SPAN&gt;&lt;SPAN&gt;": { "&lt;/SPAN&gt;&lt;SPAN class="hljs-attr"&gt;self&lt;/SPAN&gt;&lt;SPAN&gt;": &lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"&lt;A href="https://ast0072-pod.cisco.com:670/api/fdm/v6/object/externalcacertificates/6d2facc4-8ccc-11eb-915e-d9dfa128b1fb" target="_blank"&gt;https://ast0072-pod.cisco.com:670/api/fdm/v6/object/externalcacertificates/6d2facc4-8ccc-11eb-915e-d9dfa128b1fb&lt;/A&gt;"&lt;/SPAN&gt;&lt;SPAN&gt; } }&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="path"&gt;You can do similar for the other certificate types.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="path"&gt;I'll follow up by filing a bug on this as I don't believe it was ever intentional it is an inconsistency in our UI.&amp;nbsp; So we can see if we can get this repaired.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 21:42:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rest-api-certificate-question/m-p/4314119#M328</guid>
      <dc:creator>jarsmith</dc:creator>
      <dc:date>2021-03-25T21:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower REST API Certificate question..</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rest-api-certificate-question/m-p/4314227#M329</link>
      <description>&lt;P&gt;I did try externalcacertificates but mislooked the limit parameter, I increased the limit parameter and my Certificate showed up &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 03:33:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rest-api-certificate-question/m-p/4314227#M329</guid>
      <dc:creator>dvo73d123</dc:creator>
      <dc:date>2021-03-26T03:33:49Z</dc:date>
    </item>
  </channel>
</rss>

