<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trustpoint expired in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/trustpoint-expired/m-p/4392038#M1080248</link>
    <description>&lt;P&gt;It depends on how and if the certificate associated with the trustpoint is being used. Since it appears to be a CA certificate, the most common use is to present the issuing CA certificate for an identity certificate used for remote access VPN so that users can verify a complete trust chain. Other less-common uses include using the ASA as a SCEP proxy to forward certificate enrollment requests to the CA. Again, only you can tell use if any of those apply to your situation. If you are able to share the complete config, we might be able to assist in more detail.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Apr 2021 08:44:27 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-04-23T08:44:27Z</dc:date>
    <item>
      <title>Trustpoint expired</title>
      <link>https://community.cisco.com/t5/network-security/trustpoint-expired/m-p/4391951#M1080247</link>
      <description>&lt;P&gt;I got a message that a trust point has expired. I don't see any impact so far. I can ssh to manage&amp;nbsp;&lt;/P&gt;&lt;P&gt;the asa, I can connect via anyconnect, manage via ASDM. How can I verify if anything might be&lt;/P&gt;&lt;P&gt;impacted that I just haven't yet considered.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;185&amp;gt;Apr 22 2021 21:46:31 BOS-ASA01 : %ASA-1-717055: The &amp;lt;CA&amp;gt; certificate in the trustpoint &amp;lt;CAPF_4&amp;gt; has expired. Expiration &amp;lt;12:31:43 PDT Jul 17 2019&amp;gt; Subject Name &amp;lt;l=BOSTON,st=MASS,cn=CAPF-453ee840,ou=IT,o=ACME Mortgage,c=US&amp;gt; Issuer Name &amp;lt;l=BOSTON,st=MASS,cn=CAPF-453ee840,ou=IT,o=ACME Mortgage,c=US&amp;gt; Serial Number &amp;lt;xxxxxxxxC5336C3CB8C78C06E73B3E5A1&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 05:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustpoint-expired/m-p/4391951#M1080247</guid>
      <dc:creator>CiscoMedMed</dc:creator>
      <dc:date>2021-04-23T05:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Trustpoint expired</title>
      <link>https://community.cisco.com/t5/network-security/trustpoint-expired/m-p/4392038#M1080248</link>
      <description>&lt;P&gt;It depends on how and if the certificate associated with the trustpoint is being used. Since it appears to be a CA certificate, the most common use is to present the issuing CA certificate for an identity certificate used for remote access VPN so that users can verify a complete trust chain. Other less-common uses include using the ASA as a SCEP proxy to forward certificate enrollment requests to the CA. Again, only you can tell use if any of those apply to your situation. If you are able to share the complete config, we might be able to assist in more detail.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 08:44:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustpoint-expired/m-p/4392038#M1080248</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-04-23T08:44:27Z</dc:date>
    </item>
  </channel>
</rss>

