<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PKI Certificate - Manual Renewal for VPN Headend in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pki-certificate-manual-renewal-for-vpn-headend/m-p/4449128#M1082868</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/264358"&gt;@nexusrouter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need to delete the trustpoint and recreate it, you just need to run "crypto pki enroll &amp;lt;TRUSTPOINT_NAME&amp;gt;" to re-enrol. Once you've re-enrolled, run "show crypto pki certificates" to confirm the new certificate has been installed.&lt;/P&gt;
&lt;P&gt;You don't need to re-authenticate the root certificates.&lt;/P&gt;
&lt;P&gt;You can re-enrol the certificate whenever your like.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 14:46:08 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2021-08-13T14:46:08Z</dc:date>
    <item>
      <title>PKI Certificate - Manual Renewal for VPN Headend</title>
      <link>https://community.cisco.com/t5/network-security/pki-certificate-manual-renewal-for-vpn-headend/m-p/4449118#M1082867</link>
      <description>&lt;P&gt;Hello Fellow Experts / Professionals.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a couple of pertinent question's regarding the renewal of a PKI certificate on one of our client / spoke router.&amp;nbsp;The router is already enrolled into the PKI infrastructure and have the root and sub CA trust-points implemented. I have access to the CA "Windows Server" that administers certificates to clients to which is a manual enrolment via the CLI terminal. This is per design and does not have auto-enrolment in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read the Cisco white papers regarding this and have a general idea of the process, however I seek confirmation and a cast iron answer to some basic questions from you more experienced Cisco Alumni ,as I have not dealt with this environment before:-&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I authenticate against the trust-points already in place or Do I need to create new trust-points&amp;nbsp; "The Root and SubIssuingCA" when renewing a certificate that's about to expire?&lt;/P&gt;&lt;P&gt;Do I need to create the trust-points once again and then authenticate (even though it would be the same details) ?&lt;/P&gt;&lt;P&gt;Do I need to authenticate the root and Sub CA Trust-point or do I authenticate the Sub CA only before generating a CSR?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificate would be expiring in a week, can I renew the certificate before the expiration date of the active certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please tell me the correct process with a manual enrolment?&lt;BR /&gt;I would very much appreciate if someone can point me in the right direction with the correct process &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 14:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pki-certificate-manual-renewal-for-vpn-headend/m-p/4449118#M1082867</guid>
      <dc:creator>nexusrouter</dc:creator>
      <dc:date>2021-08-13T14:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: PKI Certificate - Manual Renewal for VPN Headend</title>
      <link>https://community.cisco.com/t5/network-security/pki-certificate-manual-renewal-for-vpn-headend/m-p/4449128#M1082868</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/264358"&gt;@nexusrouter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need to delete the trustpoint and recreate it, you just need to run "crypto pki enroll &amp;lt;TRUSTPOINT_NAME&amp;gt;" to re-enrol. Once you've re-enrolled, run "show crypto pki certificates" to confirm the new certificate has been installed.&lt;/P&gt;
&lt;P&gt;You don't need to re-authenticate the root certificates.&lt;/P&gt;
&lt;P&gt;You can re-enrol the certificate whenever your like.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 14:46:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pki-certificate-manual-renewal-for-vpn-headend/m-p/4449128#M1082868</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-08-13T14:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: PKI Certificate - Manual Renewal for VPN Headend</title>
      <link>https://community.cisco.com/t5/network-security/pki-certificate-manual-renewal-for-vpn-headend/m-p/4449454#M1082882</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/264358"&gt;@nexusrouter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You don't need to delete the trustpoint and recreate it, you just need to run "crypto pki enroll &amp;lt;TRUSTPOINT_NAME&amp;gt;" to re-enrol. Once you've re-enrolled, run "show crypto pki certificates" to confirm the new certificate has been installed.&lt;/P&gt;&lt;P&gt;You don't need to re-authenticate the root certificates.&lt;/P&gt;&lt;P&gt;You can re-enrol the certificate whenever your like.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thank you for your reply Rob.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be clear I just need to skip creating the Root and Sub CA Trust-points ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To start I just need to create new RSA keys "if required"&lt;/P&gt;&lt;P&gt;Authenticate the Root CA a&lt;/P&gt;&lt;P&gt;Authenticate the Sub CA&lt;/P&gt;&lt;P&gt;Generate the CSR&lt;/P&gt;&lt;P&gt;Copy and paste into the CA Server "Send that too the CA"&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then Copy the results from the CA&lt;/P&gt;&lt;P&gt;Import the new CSR "Copy Paste via terminal"&lt;/P&gt;&lt;P&gt;Then check the new expiry and hopefully see the VPN link come back up to the other VPN head-ends?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you confirm that's the steps I need to complete when re-enrolling / renewing the PKI certificate?&lt;/P&gt;&lt;P&gt;Appreciate if you could provide the process step by step:-&lt;/P&gt;</description>
      <pubDate>Sat, 14 Aug 2021 10:46:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pki-certificate-manual-renewal-for-vpn-headend/m-p/4449454#M1082882</guid>
      <dc:creator>nexusrouter</dc:creator>
      <dc:date>2021-08-14T10:46:20Z</dc:date>
    </item>
  </channel>
</rss>

