<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Install self-signed cert in Defense Center in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/install-self-signed-cert-in-defense-center/m-p/2917055#M1031492</link>
    <description>&lt;P abp="2777"&gt;Hi all,&lt;/P&gt;
&lt;P abp="2778"&gt;&lt;/P&gt;
&lt;P abp="2780"&gt;I am setting up my new Defense Center 6.0.1 (VM), which will manage a single 5508X.&amp;nbsp; I am building my policies and am trying to get my realm working.&amp;nbsp; I will run LDAP queries against two Windows 2012 R2 DC's.&amp;nbsp; These DC's use self-signed certs, named dc1.domain.com and dc2.domain.com.&amp;nbsp; I have copies of these certs in PFX format, and would like to upload them into the Defense Center so that I can secure my LDAP queries using LDAPS.&amp;nbsp; As they are self-signed, they would need to be Trusted Cert Authorities.&lt;/P&gt;
&lt;P abp="2781"&gt;&lt;/P&gt;
&lt;P abp="2783"&gt;I am familiar with the upload process, however whenever I try to upload the PFX certs, I receive error &lt;EM abp="2784"&gt;'Error uploading file. Please verify that this is a certificate and it uses a supported PKCS encoding&lt;/EM&gt;.' &amp;nbsp;I have used OpenSSL to convert the PFX certs to PEM format, which Defense Center can then read; however when I try to use this imported cert to secure LDAP, the Test connection fails.&amp;nbsp; Using the ldp.exe utility on Windows, I am able to successfully connect to the domain controllers on port 636 using LDAPS.&lt;/P&gt;
&lt;P abp="2785"&gt;&lt;/P&gt;
&lt;P abp="2787"&gt;My question is: What type of cert does Defense Center "like" best?&amp;nbsp; Should I be using CRT or CER format certs instead of PEM?&lt;/P&gt;
&lt;P abp="2788"&gt;&lt;/P&gt;
&lt;P abp="2790"&gt;My OpenSSL command was: &lt;STRONG abp="2791"&gt;openssl pkcs12 -in cert.pfx -out cert.pem -nodes&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 12:56:48 GMT</pubDate>
    <dc:creator>cooperben</dc:creator>
    <dc:date>2019-03-12T12:56:48Z</dc:date>
    <item>
      <title>Install self-signed cert in Defense Center</title>
      <link>https://community.cisco.com/t5/network-security/install-self-signed-cert-in-defense-center/m-p/2917055#M1031492</link>
      <description>&lt;P abp="2777"&gt;Hi all,&lt;/P&gt;
&lt;P abp="2778"&gt;&lt;/P&gt;
&lt;P abp="2780"&gt;I am setting up my new Defense Center 6.0.1 (VM), which will manage a single 5508X.&amp;nbsp; I am building my policies and am trying to get my realm working.&amp;nbsp; I will run LDAP queries against two Windows 2012 R2 DC's.&amp;nbsp; These DC's use self-signed certs, named dc1.domain.com and dc2.domain.com.&amp;nbsp; I have copies of these certs in PFX format, and would like to upload them into the Defense Center so that I can secure my LDAP queries using LDAPS.&amp;nbsp; As they are self-signed, they would need to be Trusted Cert Authorities.&lt;/P&gt;
&lt;P abp="2781"&gt;&lt;/P&gt;
&lt;P abp="2783"&gt;I am familiar with the upload process, however whenever I try to upload the PFX certs, I receive error &lt;EM abp="2784"&gt;'Error uploading file. Please verify that this is a certificate and it uses a supported PKCS encoding&lt;/EM&gt;.' &amp;nbsp;I have used OpenSSL to convert the PFX certs to PEM format, which Defense Center can then read; however when I try to use this imported cert to secure LDAP, the Test connection fails.&amp;nbsp; Using the ldp.exe utility on Windows, I am able to successfully connect to the domain controllers on port 636 using LDAPS.&lt;/P&gt;
&lt;P abp="2785"&gt;&lt;/P&gt;
&lt;P abp="2787"&gt;My question is: What type of cert does Defense Center "like" best?&amp;nbsp; Should I be using CRT or CER format certs instead of PEM?&lt;/P&gt;
&lt;P abp="2788"&gt;&lt;/P&gt;
&lt;P abp="2790"&gt;My OpenSSL command was: &lt;STRONG abp="2791"&gt;openssl pkcs12 -in cert.pfx -out cert.pem -nodes&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/install-self-signed-cert-in-defense-center/m-p/2917055#M1031492</guid>
      <dc:creator>cooperben</dc:creator>
      <dc:date>2019-03-12T12:56:48Z</dc:date>
    </item>
  </channel>
</rss>

