<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN3000 with Certificate Backup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn3000-with-certificate-backup/m-p/81597#M1062954</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can somebody tell me if it´s possible to backup a vpn3000 config and its certificate/generated keys in case of hardware failure. If not i have to generate new keys, get a new certificate and tell this all my clients, routers, firewalls ?  (which sounds horrible!).&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 06:17:29 GMT</pubDate>
    <dc:creator>tschlottke</dc:creator>
    <dc:date>2020-02-21T06:17:29Z</dc:date>
    <item>
      <title>VPN3000 with Certificate Backup</title>
      <link>https://community.cisco.com/t5/network-security/vpn3000-with-certificate-backup/m-p/81597#M1062954</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can somebody tell me if it´s possible to backup a vpn3000 config and its certificate/generated keys in case of hardware failure. If not i have to generate new keys, get a new certificate and tell this all my clients, routers, firewalls ?  (which sounds horrible!).&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn3000-with-certificate-backup/m-p/81597#M1062954</guid>
      <dc:creator>tschlottke</dc:creator>
      <dc:date>2020-02-21T06:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN3000 with Certificate Backup</title>
      <link>https://community.cisco.com/t5/network-security/vpn3000-with-certificate-backup/m-p/81598#M1062955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct me if I am wrong but I think it is not possible to backup the private key generated by the failure hardware, be it VPN3000, routers or PIXes. Because it is always hidden and can`t be viewed from the menu or console. I don`t see any menu on the VPN3000, to backup its own private key. Even if you have the VPN3000`s certificate, seems like it is not possible to restore it. So, the new hardware replacing the failure one has to genereate a new private key  and get a public key certified by its trusted root CA. One doesn`t need to announce this new certificate to all clients of the new hardware (routers, firewalls). If there is a need to create a VPN tunnel between the new hardware and the other side, the two VPN devices will authenticate themself using the certificates. If the peer`s certificate issued by its trusted CA, then the device will trust the certifcate (and vice-versa) and continue to the next phase of negotiation. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2002 07:05:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn3000-with-certificate-backup/m-p/81598#M1062955</guid>
      <dc:creator>engel</dc:creator>
      <dc:date>2002-10-09T07:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN3000 with Certificate Backup</title>
      <link>https://community.cisco.com/t5/network-security/vpn3000-with-certificate-backup/m-p/81599#M1062957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Thomas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible to manually backup the certificates with private keys from the VPN3k web-interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Log into the web-administration&lt;/P&gt;&lt;P&gt;2. Navigate to Administration-&amp;gt;Certificate Management&lt;/P&gt;&lt;P&gt;3. Select Export for the certificate you wish to backup.&lt;/P&gt;&lt;P&gt;4. The VPN3k will request a password to encrypt the prifvate RSA key.&lt;/P&gt;&lt;P&gt;5. When you enter the password and click export the certificate and key will be saved as CERTEXP.TXT on the VPN3K flash and it will try to popup a window showing the data.&amp;nbsp; Copy this data and store it somewhere, remember the key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That exported certificate can be imported to the VPN3k Via the Certificate Management-&amp;gt;Installation section using the Import SSL certificate with private key link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The export/import format that the VPN3k uses is not a standard PKCS12, it is a PKCS8 encrypted private key in Base64 with the X509 certificate in base64 encoding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think the XML Export option gives you the certificates, so to have a full backup you would need both items.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps,&lt;BR /&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Dec 2010 22:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn3000-with-certificate-backup/m-p/81599#M1062957</guid>
      <dc:creator>Craig Lorentzen</dc:creator>
      <dc:date>2010-12-17T22:21:13Z</dc:date>
    </item>
  </channel>
</rss>

