<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA: Problems when a certificate for AnyConnect users expired in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-problems-when-a-certificate-for-anyconnect-users-expired/m-p/4431227#M1082139</link>
    <description>&lt;P&gt;Generally speaking, we should never use a self-signed certificate outside of a lab environment. So replacing the expired certificate from a known Certificate Authority (CA) with a self-signed one is not a recommended practice.&lt;/P&gt;
&lt;P&gt;The correct practice would be to either:&lt;/P&gt;
&lt;P&gt;a. renew the certificate from the same CA or&lt;/P&gt;
&lt;P&gt;b. generate a new Certificate Signing Request (CSR), submit it the CA, get a new CA-issued certificate and install it.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jul 2021 02:17:36 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-07-12T02:17:36Z</dc:date>
    <item>
      <title>ASA: Problems when a certificate for AnyConnect users expired</title>
      <link>https://community.cisco.com/t5/network-security/asa-problems-when-a-certificate-for-anyconnect-users-expired/m-p/4431082#M1082133</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;today I have a problem with certificates on the ASA running 9.8(4)32&lt;BR /&gt;for AnyConnect (4.9.05042) users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The self-signed certificate expired recently and since that time the&lt;BR /&gt;AnyConnect users get the AnyConnect "Security Warning: Untrusted Server Certificate"&lt;BR /&gt;(see attached). The customer clicked 'Connect anyway' and could login.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I indicated the properties of the expired certificate and generated&lt;BR /&gt;a new self-signed certificate with same properties Common Name (CN) etc.&lt;BR /&gt;following the guide on:&lt;BR /&gt;&lt;A href="https://asame2.blogspot.com/2018/06/how-to-generate-self-signed-certificate.html" target="_blank" rel="noopener"&gt;https://asame2.blogspot.com/2018/06/how-to-generate-self-signed-certificate.html&lt;/A&gt;&lt;BR /&gt;with expiry date in 2031 and assigned it to the outside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At next login attempt the customer gets the AnyConnect "Security Warning:&lt;BR /&gt;Untrusted Server Certificate" again but this time with option to import&lt;BR /&gt;the certificate (see attached).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when he chosed this option and clicked 'Connect anyway' he could not&lt;BR /&gt;login at all anymore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assigned the expired certificate to the outside interface and then the&lt;BR /&gt;customer could login in again after clicking 'Connect anyway'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My questions:&lt;/P&gt;&lt;P&gt;1. Is tere a relation between the Common Name (CN) and the VPN server&lt;BR /&gt;that the user has in the AnyConnect client before he click 'Connect'?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Could it be that the import did not work correctly that way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Is there a step to step guide what's to do when a certificate&lt;BR /&gt;expired?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every hint is very welcome.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jul 2021 07:54:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problems-when-a-certificate-for-anyconnect-users-expired/m-p/4431082#M1082133</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2021-07-11T07:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: Problems when a certificate for AnyConnect users expired</title>
      <link>https://community.cisco.com/t5/network-security/asa-problems-when-a-certificate-for-anyconnect-users-expired/m-p/4431088#M1082134</link>
      <description>&lt;P&gt;You are use Dynadns as FQDN ? do you have Public Cert for this ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you are using self signed, the Certificate need to be pushed to all clients, this is mostly done with your Centralised Windows update system what you have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or user need to&amp;nbsp; check that box and install cert so&amp;nbsp; user will not get any error. (this is not recommended)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 08:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problems-when-a-certificate-for-anyconnect-users-expired/m-p/4431088#M1082134</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-12T08:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: Problems when a certificate for AnyConnect users expired</title>
      <link>https://community.cisco.com/t5/network-security/asa-problems-when-a-certificate-for-anyconnect-users-expired/m-p/4431227#M1082139</link>
      <description>&lt;P&gt;Generally speaking, we should never use a self-signed certificate outside of a lab environment. So replacing the expired certificate from a known Certificate Authority (CA) with a self-signed one is not a recommended practice.&lt;/P&gt;
&lt;P&gt;The correct practice would be to either:&lt;/P&gt;
&lt;P&gt;a. renew the certificate from the same CA or&lt;/P&gt;
&lt;P&gt;b. generate a new Certificate Signing Request (CSR), submit it the CA, get a new CA-issued certificate and install it.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 02:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problems-when-a-certificate-for-anyconnect-users-expired/m-p/4431227#M1082139</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-07-12T02:17:36Z</dc:date>
    </item>
  </channel>
</rss>

