<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5506 Firepower Module Certificate in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3996822#M1013784</link>
    <description>&lt;P&gt;How to do this using SSH, as the Firepower ASDM onbox management it´s not available, since the Sourcefire3d certificate its unknown for ASDM host?&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2019 22:12:06 GMT</pubDate>
    <dc:creator>erickflamenco</dc:creator>
    <dc:date>2019-12-10T22:12:06Z</dc:date>
    <item>
      <title>ASA 5506 Firepower Module Certificate</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3724678#M1013781</link>
      <description>&lt;HR /&gt;
&lt;P&gt;Hi All&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Really struggling to find an answer to this which is strange.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Weve got got a couple of ASA’s with Firepower module on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the firewalls themselves have got Certs installed from m our CA so we don’t get cert warnings. However I’m still getting a warning because the Firepower module isnusing a self signed cert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i don’t want to go around admin stations installing this cert as that’s time consuming and in any case I’d rather it was usong&lt;/P&gt;
&lt;P&gt;one of ours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;does anyone know how to add a cert to Firepower from Windows CA?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what should the subject be for this cert. at the moment it’s Firepower, should it be the same or follow our naming convention?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3724678#M1013781</guid>
      <dc:creator>benkelly`8</dc:creator>
      <dc:date>2019-03-12T14:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 Firepower Module Certificate</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3724907#M1013782</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can install the certificate on ASA from CA to be used for firepower using below link. This uses CSR:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/200339-Configure-ASA-SSL-Digital-Certificate-I.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/200339-Configure-ASA-SSL-Digital-Certificate-I.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or&amp;nbsp; you can install the certificate directly from windows CA:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/71050-ASA-cert.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/71050-ASA-cert.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Oct 2018 06:05:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3724907#M1013782</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-10-14T06:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 Firepower Module Certificate</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3724924#M1013783</link>
      <description>&lt;P&gt;The only time I can think of that you would be accessing a Firepower service module via TLS is when you are doing local management with ASDM. Is that where you are seeing errors? I've not seen such an error the few times I've managed a module with ASDM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to add a certificate to the module itself you should be able to do so following this procedure:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/623/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v623/Managing-Objects.html?bookSearch=true#28976" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/623/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v623/Managing-Objects.html?bookSearch=true#28976&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe ASDM will be requesting information from the module using the module's IP address (vs. FQDN) so the address would need to be at least a SAN (if not the CN) in the certificate.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Oct 2018 08:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3724924#M1013783</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-10-14T08:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 Firepower Module Certificate</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3996822#M1013784</link>
      <description>&lt;P&gt;How to do this using SSH, as the Firepower ASDM onbox management it´s not available, since the Sourcefire3d certificate its unknown for ASDM host?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 22:12:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3996822#M1013784</guid>
      <dc:creator>erickflamenco</dc:creator>
      <dc:date>2019-12-10T22:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 Firepower Module Certificate</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3996957#M1013786</link>
      <description>&lt;P&gt;Can't you allow/accept the self-signed certificate on one workstation - just enough to be able to then go int via ASM and update it using the documented GUI procedure mentioned earlier?&lt;/P&gt;
&lt;P&gt;If you cannot, then I would suggest opening a TAC case as there's not (as far as I know) a supported procedure for customer's doing it via the cli.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 05:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-firepower-module-certificate/m-p/3996957#M1013786</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-12-11T05:38:07Z</dc:date>
    </item>
  </channel>
</rss>

