<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 2100-series Https Certificate Expired in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-2100-series-https-certificate-expired/m-p/4179689#M1075548</link>
    <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, i opened a TAC case in the end.&lt;/P&gt;&lt;P&gt;TAC mentioned that FTD is being managed by the FMC hence this http service is not used anywhere.&lt;BR /&gt;Hence we do not have an option to make any changes on this certificate.&lt;BR /&gt;However if you use on-box management or FDM to manage the FTD then yes you should be able to change the certificate and also the validity time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So there is no way to change the FXOS keyring for 2100 series.&lt;/P&gt;&lt;P&gt;I then use the email to get the management to&amp;nbsp;&lt;SPAN&gt;accept the risk.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2020 01:50:26 GMT</pubDate>
    <dc:creator>benong1989</dc:creator>
    <dc:date>2020-11-06T01:50:26Z</dc:date>
    <item>
      <title>Firepower 2100-series Https Certificate Expired</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2100-series-https-certificate-expired/m-p/4156404#M1074173</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My firepower2130 is running on FTD 6.4.0.9&lt;/P&gt;&lt;P&gt;One day, the VAPT scan detected Certificate has Expired, and i found out its the https certificate.&lt;/P&gt;&lt;P&gt;and this certificate is located in the FXOS. unlike those you can set in FMC &amp;gt; devices &amp;gt; certificates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So as it is running FTD, i am not able to use the FXOS cli "commit-buffer", and to renew the certificate, based on this bug ID, i need to use this command instead.&lt;/P&gt;&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvk26612" target="_blank" rel="noopener"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCvk26612&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;system support regenerate-security-keyring&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However this renew the certificate with 10 years period, but our policy only allows 5 years max.&lt;/P&gt;&lt;P&gt;Anyone knows how can i create a new keyring or change the keyring period to 5 years?&lt;/P&gt;&lt;P&gt;As i an unable to "commit-buffer", i cannot create a new one in FXOS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 08:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2100-series-https-certificate-expired/m-p/4156404#M1074173</guid>
      <dc:creator>benong1989</dc:creator>
      <dc:date>2020-09-24T08:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2100-series Https Certificate Expired</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2100-series-https-certificate-expired/m-p/4157033#M1074202</link>
      <description>&lt;P&gt;I'd suggest opening a TAC case on this one. You may need to create a private key and CSR and import a CA-signed certificate using an external tool (openssl, xca etc.).&lt;/P&gt;
&lt;P&gt;Or just write a compensating control / accept the risk of the expired certificate that you don't use anyway.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 07:32:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2100-series-https-certificate-expired/m-p/4157033#M1074202</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-09-25T07:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2100-series Https Certificate Expired</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2100-series-https-certificate-expired/m-p/4179689#M1075548</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, i opened a TAC case in the end.&lt;/P&gt;&lt;P&gt;TAC mentioned that FTD is being managed by the FMC hence this http service is not used anywhere.&lt;BR /&gt;Hence we do not have an option to make any changes on this certificate.&lt;BR /&gt;However if you use on-box management or FDM to manage the FTD then yes you should be able to change the certificate and also the validity time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So there is no way to change the FXOS keyring for 2100 series.&lt;/P&gt;&lt;P&gt;I then use the email to get the management to&amp;nbsp;&lt;SPAN&gt;accept the risk.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 01:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2100-series-https-certificate-expired/m-p/4179689#M1075548</guid>
      <dc:creator>benong1989</dc:creator>
      <dc:date>2020-11-06T01:50:26Z</dc:date>
    </item>
  </channel>
</rss>

