<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using FMC GUI to replace RA VPN Certificate in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053101#M1068302</link>
    <description>Really hoping to avoid that as I've already reissued once, and I think GoDaddy only allows two! Man I hate these things.</description>
    <pubDate>Thu, 26 Mar 2020 18:37:41 GMT</pubDate>
    <dc:creator>LVS-Derek</dc:creator>
    <dc:date>2020-03-26T18:37:41Z</dc:date>
    <item>
      <title>Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4052972#M1068285</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm replacing the SSL cert for our RA VPN.&amp;nbsp; I've used the GUI because I'm not much of a Linux guy and I'm fairly new to Cisco stuff.&amp;nbsp; I have a pair of 5525s with the FMC virtual appliance.&amp;nbsp; I used the FMC GUI to generate a CSR but the interface timed out before I got the response back.&amp;nbsp; If I click the option to Enroll the identity certificate, it wants to start from scratch with a new CSR.&amp;nbsp; How do I get it to accept the certificate I got from GoDaddy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any help you can offer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Derek&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 15:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4052972#M1068285</guid>
      <dc:creator>LVS-Derek</dc:creator>
      <dc:date>2020-03-26T15:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053003#M1068289</link>
      <description>Hi,&lt;BR /&gt;When you generate the CSR you should be able to safely close the screen and then return later to import the signed certificate. If you closed the screen and re-entered it later, it might say that it's going to regenerate a CSR but I've tested, it doesn't, it's the same CSR. You should be able to successfully import the signed identity certificate from godaddy.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Thu, 26 Mar 2020 16:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053003#M1068289</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-26T16:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053018#M1068291</link>
      <description>Thanks. I'll try that right now and report back!</description>
      <pubDate>Thu, 26 Mar 2020 16:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053018#M1068291</guid>
      <dc:creator>LVS-Derek</dc:creator>
      <dc:date>2020-03-26T16:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053026#M1068292</link>
      <description>No luck. What format should this certificate be in? Maybe I need to convert it first?</description>
      <pubDate>Thu, 26 Mar 2020 16:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053026#M1068292</guid>
      <dc:creator>LVS-Derek</dc:creator>
      <dc:date>2020-03-26T16:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053030#M1068293</link>
      <description>I've never had a problem importing an identity certicate in PEM format....these are prefixed with a “—–--- BEGIN …” line and end with "------ END CERTIFICATE---".&lt;BR /&gt;&lt;BR /&gt;What format is your cerificate in? If not PEM then yes perhaps convert to PEM.&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;</description>
      <pubDate>Thu, 26 Mar 2020 16:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053030#M1068293</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-26T16:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053048#M1068294</link>
      <description>I'm trying the PEM again right now. It's possible I may have misselected the first time because it's taking a lot longer this time. I'll let it spin for a bit before I refresh.</description>
      <pubDate>Thu, 26 Mar 2020 17:25:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053048#M1068294</guid>
      <dc:creator>LVS-Derek</dc:creator>
      <dc:date>2020-03-26T17:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053060#M1068296</link>
      <description>No dice. It was still spinning when I got back to it so I hit Refresh. It's back to "Identity certificate import required." So I tried the PEM file once more and this time it quickly returned to the same message.</description>
      <pubDate>Thu, 26 Mar 2020 17:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053060#M1068296</guid>
      <dc:creator>LVS-Derek</dc:creator>
      <dc:date>2020-03-26T17:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053065#M1068297</link>
      <description>Is the file just the identity certificate certificate or the entire chain?&lt;BR /&gt;I assume the FTD you are applying the certificate to is actually online? If it's turned off then you cannot import the certificate.</description>
      <pubDate>Thu, 26 Mar 2020 17:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053065#M1068297</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-26T17:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053093#M1068298</link>
      <description>Just the identity certificate. I was able to successfully upload the CA chain but it won't take the identity cert. I can't create a PKCS12 file because the interface doesn't give me access to the key used.</description>
      <pubDate>Thu, 26 Mar 2020 18:28:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053093#M1068298</guid>
      <dc:creator>LVS-Derek</dc:creator>
      <dc:date>2020-03-26T18:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053095#M1068299</link>
      <description>&lt;P&gt;What enrollment type did you use? Manual?&lt;/P&gt;&lt;P&gt;You might have to just start again and re-submit to the CA.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 18:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053095#M1068299</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-26T18:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053101#M1068302</link>
      <description>Really hoping to avoid that as I've already reissued once, and I think GoDaddy only allows two! Man I hate these things.</description>
      <pubDate>Thu, 26 Mar 2020 18:37:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053101#M1068302</guid>
      <dc:creator>LVS-Derek</dc:creator>
      <dc:date>2020-03-26T18:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053122#M1068303</link>
      <description>&lt;P&gt;Which version of FMC are you using?&lt;/P&gt;&lt;P&gt;What enrolment type did you use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just so we are on the right wave length, these are the steps that work:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If using manual, you import the root certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn 1.PNG" style="width: 605px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/69999i66F3828B50973D3B/image-dimensions/605x386?v=v2" width="605" height="386" role="button" title="vpn 1.PNG" alt="vpn 1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Define the certificate parameters.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn 2.PNG" style="width: 594px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/70001iEF0381263C65FB0B/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn 2.PNG" alt="vpn 2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Click &lt;STRONG&gt;Save&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Navigate to &lt;STRONG&gt;Devices &amp;gt; Certificates&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Click &lt;STRONG&gt;Add&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;From the Device drop-down list select your device&lt;/P&gt;&lt;P&gt;From the Cert Enrollment drop-down list selectthe certificate enrolment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn 3.PNG" style="width: 515px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/70000i90666F474202756D/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn 3.PNG" alt="vpn 3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Click the ID button&lt;/P&gt;&lt;P&gt;Generate the CSR&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn 44.png" style="width: 367px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/70002i3699EFE00E77188A/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn 44.png" alt="vpn 44.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Copy the contents of the CSR and send to GoDaddy to sign the certificate&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn 5.PNG" style="width: 539px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/69998iA01D710C30DD13D0/image-dimensions/539x343?v=v2" width="539" height="343" role="button" title="vpn 5.PNG" alt="vpn 5.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Browse identity certificate to import the signed identity certifcate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that the steps you followed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 18:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053122#M1068303</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-26T18:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Using FMC GUI to replace RA VPN Certificate</title>
      <link>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053131#M1068304</link>
      <description>Yes, that's exactly what I did. I'm using FMC 6.5 on a pair of 5525s.</description>
      <pubDate>Thu, 26 Mar 2020 19:11:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-fmc-gui-to-replace-ra-vpn-certificate/m-p/4053131#M1068304</guid>
      <dc:creator>LVS-Derek</dc:creator>
      <dc:date>2020-03-26T19:11:35Z</dc:date>
    </item>
  </channel>
</rss>

