<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure LDAP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515353#M1085611</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/242701"&gt;@Srinivasan Nagarajan&lt;/a&gt; you'll need to upload the root and intermediate root certificates to the FMC in order to trust the AD server's identity certificate.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Dec 2021 16:39:25 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2021-12-08T16:39:25Z</dc:date>
    <item>
      <title>Secure LDAP</title>
      <link>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515351#M1085610</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;We've Cisco ASA with SFR modules being managed by FMC. Currently, we're using LDAP server as 'domain.com' which resolves to multiple AD servers and the port used is TCP/389.&lt;/P&gt;&lt;P&gt;We've been asked to change it to secure LDAP-TCP/636 and in this case, not sure which cert of the AD server to be uploaded into FMC as this resolves to multiple AD servers.&lt;/P&gt;&lt;P&gt;Can someone please assist? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 16:36:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515351#M1085610</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-12-08T16:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Secure LDAP</title>
      <link>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515353#M1085611</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/242701"&gt;@Srinivasan Nagarajan&lt;/a&gt; you'll need to upload the root and intermediate root certificates to the FMC in order to trust the AD server's identity certificate.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 16:39:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515353#M1085611</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-12-08T16:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Secure LDAP</title>
      <link>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515367#M1085615</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've configured 'domain.com' in the primary server config which is resolving to multiple AD servers. So, in this case, should we need to upload the wildcard cert of this Root AD server?&lt;/P&gt;&lt;P&gt;Also, as given here, it shows the Root cert of the AD server to be uploaded. Can you please suggest where to upload the intermediate and identity cert of the server?&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215538-configure-firepower-management-center-an.html#anc7" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215538-configure-firepower-management-center-an.html#anc7&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 16:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515367#M1085615</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-12-08T16:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Secure LDAP</title>
      <link>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515374#M1085619</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/242701"&gt;@Srinivasan Nagarajan&lt;/a&gt; see section 5 of that guide, step 2.&lt;/P&gt;
&lt;P&gt;Step 2. Upload the certificate of the CA who signed the server's certificate. The certificate must be in PEM format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So export the root certificate of the certificate that signed the server's certificate and import in step 2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 17:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515374#M1085619</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-12-08T17:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Secure LDAP</title>
      <link>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515379#M1085623</link>
      <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;for taking your time in replying to this.&lt;/P&gt;&lt;P&gt;Should only the Root CA cert will suffice or we need to add the Intermediate and Identity certs? if yes, can you please suggest where to get this uploaded into FMC as step5 only says for Root certs?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 17:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-ldap/m-p/4515379#M1085623</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-12-08T17:23:59Z</dc:date>
    </item>
  </channel>
</rss>

