<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower: exporting private key of Self-signed certificate in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134823#M1072922</link>
    <description>&lt;P&gt;Francesco, my post is mentioning the private key because we want to backup in case we need to restore FMC.&amp;nbsp; We know that the private key is not needed on workstation to perform SSL decrypt; that only the root cert of the signing authority of FMC identity cert needs to be installed on the certificate store of inside hosts (and in both stores:&amp;nbsp; default window store used by Chrome, IE, Edge, etc) and in Firefox cert store.)&amp;nbsp; Again, my question is: how do I export, for backup, the private key of a FMC Self-Signed certificate.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Aug 2020 19:37:07 GMT</pubDate>
    <dc:creator>cpaquet</dc:creator>
    <dc:date>2020-08-12T19:37:07Z</dc:date>
    <item>
      <title>Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134225#M1072874</link>
      <description>&lt;P&gt;How can I download (export) the private key of the self-signed certificate created through Object &amp;gt; PKI &amp;gt; Internal CAs ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Firepower self-signed certificate is to be installed on corporate computers as Trusted Authority and used by FTD for outbound SSL decryption.&amp;nbsp; If so, the private key needs to be backup, but I can't find where.&amp;nbsp; Under Internal CAs, I see how to download the self-signed cert, but not how to export its key private.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 00:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134225#M1072874</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2020-08-12T00:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134258#M1072876</link>
      <description>Hi &lt;BR /&gt;&lt;BR /&gt;To do ssl decryption, on objects management window, under PKI/Internal CAs, generate a self signed CA and use it in your ssl policy.&lt;BR /&gt;What you need is to export this certificate and add it into your machine on the trusted CA vault. Private key isn't needed here.&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Aug 2020 02:25:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134258#M1072876</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-08-12T02:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134320#M1072877</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;If it you enabled exportable during the certificate generation then from&lt;BR /&gt;CLI you can do it as follow&lt;BR /&gt;&lt;BR /&gt;crypto ca export &lt;TRUSTPOINT&gt; pkcs12 &lt;PASSPHRASE&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;&lt;/PASSPHRASE&gt;&lt;/TRUSTPOINT&gt;</description>
      <pubDate>Wed, 12 Aug 2020 05:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134320#M1072877</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-08-12T05:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134818#M1072920</link>
      <description>&lt;P&gt;Mohammed, I'm on the PKI &amp;gt; Generate Internal Certificate Authority window, to generate a new Self-signed cert from FMC, but I don't see an option to make that cert / key pair exportable.&amp;nbsp; I have attached the screen capture.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 19:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134818#M1072920</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2020-08-12T19:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134823#M1072922</link>
      <description>&lt;P&gt;Francesco, my post is mentioning the private key because we want to backup in case we need to restore FMC.&amp;nbsp; We know that the private key is not needed on workstation to perform SSL decrypt; that only the root cert of the signing authority of FMC identity cert needs to be installed on the certificate store of inside hosts (and in both stores:&amp;nbsp; default window store used by Chrome, IE, Edge, etc) and in Firefox cert store.)&amp;nbsp; Again, my question is: how do I export, for backup, the private key of a FMC Self-Signed certificate.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 19:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4134823#M1072922</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2020-08-12T19:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4135722#M1072983</link>
      <description>&lt;P&gt;Sorry, my bad I didn't understood your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So when you go into FMC, under objects/PKI/Internal CA, click on edit icon on your selfsigned Internal CA.&lt;/P&gt;
&lt;P&gt;It will prompt you a password and export a p12 file.&lt;/P&gt;
&lt;P&gt;Once you have the p12 file exported, run the following command:&lt;/P&gt;
&lt;P&gt;openssl pkcs12 -info -in &lt;STRONG&gt;nameofyourexportedfile.p12&lt;/STRONG&gt; -nodes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This command will ask you to type in a password which is the one you typed in FMC at the export step.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It will show you your certificate and private key.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 03:03:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4135722#M1072983</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-08-14T03:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4145459#M1073537</link>
      <description>&lt;P&gt;Thanks Francesco for the help. However, I dont get the result you are suggesting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I got to FMC &amp;gt; Objects &amp;gt; Objects Management &amp;gt; PKI &amp;gt; Internal CAs and I edit the Self-Signed certificate. contrary to what you wrote, I am not "prompt you a password and export p12. "&amp;nbsp; When I click edit on the self-signed certificate, it just opens the Self-Signed cert where the only editable field is the Name of the object. All the other fields are none-editable. The only button is DOWNLOAD, which downloads the .p12 in the Download folder of the local computer from which FMC is being accessed.&amp;nbsp; I have attached the screen capture - no export functionality.&lt;/P&gt;&lt;P&gt;Question: are you sure that the step you are describing with the capabilities to export are available to self-signed certificates? Or wouldn't this functionality be reserved only to identity cert signed by a Trusted Authority?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cath.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 00:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4145459#M1073537</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2020-09-03T00:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4145508#M1073544</link>
      <description>&lt;P&gt;For self-signed certificates we don't have the option of either making the key exportable when creating them or exporting it later.&lt;/P&gt;
&lt;P&gt;If it's a virtual FMC you can backup the entire VM from outside of FMC (e.g a VMware snapshot).&lt;/P&gt;
&lt;P&gt;If you want just the key and certificate then don't use self-signed. Generate the key and csr externally using openssl (cli) or XCA (open source Windows GUI-based tool) and save the key and issued certificate from your internal CA using those tools.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 03:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4145508#M1073544</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-09-03T03:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4146085#M1073581</link>
      <description>&lt;P&gt;Thank you Marvin for the straight answer.&amp;nbsp; Much appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 22:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4146085#M1073581</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2020-09-03T22:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower: exporting private key of Self-signed certificate</title>
      <link>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4146099#M1073584</link>
      <description>&lt;P&gt;Here is a self signed certificate that I can export without problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 641px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/82796iC09B24B1ED281216/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 395px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/82797iA4276F783FB1EE4D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 377px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/82798i23A4B7E110772582/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm sorry to hear you can't do it.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 23:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-exporting-private-key-of-self-signed-certificate/m-p/4146099#M1073584</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-09-03T23:20:51Z</dc:date>
    </item>
  </channel>
</rss>

