<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CDO and device certificate in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285290#M1078067</link>
    <description>&lt;P&gt;The certificate in ASA exists by default or I have to create it somehow?&lt;/P&gt;</description>
    <pubDate>Wed, 03 Feb 2021 15:18:52 GMT</pubDate>
    <dc:creator>kostasthedelegate</dc:creator>
    <dc:date>2021-02-03T15:18:52Z</dc:date>
    <item>
      <title>CDO and device certificate</title>
      <link>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285246#M1078060</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to onboard an ASA device in CDO.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get the error&lt;/P&gt;&lt;P&gt;Certificate could not be retrieved for IPADDRESS:PORT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To which certificate it refers to?&lt;BR /&gt;How could I change it?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 14:17:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285246#M1078060</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-02-03T14:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: CDO and device certificate</title>
      <link>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285250#M1078061</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/864895"&gt;@kostasthedelegate&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's referring to the certificate in use by ASDM for mgmt is used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my experience the ASA's self-signed certificate or a public signed certificate works, but a certificate issued by an internal CA (i.e. Windows CA) does not work.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 14:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285250#M1078061</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-02-03T14:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: CDO and device certificate</title>
      <link>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285252#M1078062</link>
      <description>&lt;P&gt;Ok But I use the ethernet port 1/1 that has a public IP to connect to CDO.&lt;/P&gt;&lt;P&gt;I do not use the management port&lt;/P&gt;&lt;P&gt;What should I do?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 14:26:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285252#M1078062</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-02-03T14:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: CDO and device certificate</title>
      <link>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285262#M1078063</link>
      <description>&lt;P&gt;Are you permitting http access from the CDO networks to the outside interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example (the address below are the EU CDO servers):&lt;/P&gt;
&lt;PRE class="wp-block-preformatted"&gt;&lt;SPAN style="font-size: 10pt;"&gt;http 35.157.12.126 255.255.255.255 outside&lt;/SPAN&gt;
&lt;SPAN style="font-size: 10pt;"&gt;http 35.157.12.15 255.255.255.255 outside
http server enable 8443&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 14:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285262#M1078063</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-02-03T14:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: CDO and device certificate</title>
      <link>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285276#M1078064</link>
      <description>&lt;P&gt;I had put these ones&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;52.25.109.29,&amp;nbsp;52.34.234.2,&amp;nbsp;52.36.70.147&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I added the ones you mentioned but still I&amp;nbsp;get the same&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 14:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285276#M1078064</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-02-03T14:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: CDO and device certificate</title>
      <link>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285290#M1078067</link>
      <description>&lt;P&gt;The certificate in ASA exists by default or I have to create it somehow?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 15:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285290#M1078067</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-02-03T15:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: CDO and device certificate</title>
      <link>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285295#M1078068</link>
      <description>&lt;P&gt;Yes, it should have a self-signed certificate.&lt;/P&gt;
&lt;P&gt;Do you have a trustpoint enabled on the outside interface?&lt;/P&gt;
&lt;P&gt;Have you enable the certificate on the correct port and configured in CDO using the correct port (as configured on the ASA)?&lt;/P&gt;
&lt;PRE class="wp-block-preformatted"&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;EM&gt;ssl trust-point TP OUTSIDE&lt;/EM&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;Run a packet capture and confirm traffic is being received.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 15:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285295#M1078068</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-02-03T15:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: CDO and device certificate</title>
      <link>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285357#M1078076</link>
      <description>&lt;P&gt;Thanks for the help&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems the issue was with the access on HTTP management.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I allowed everything temporarily and it worked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 16:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cdo-and-device-certificate/m-p/4285357#M1078076</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-02-03T16:31:28Z</dc:date>
    </item>
  </channel>
</rss>

