<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Export/Import certificates from ASA to FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650080#M1091828</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/256705"&gt;@Chess Norris&lt;/a&gt; &lt;A href="https://integratingit.wordpress.com/2019/09/28/asa-export-import-certificate/" target="_self"&gt;here&lt;/A&gt; is a guide to export the ASA certificate to PKCS12 file. On the FTD you just need to import the PKCS12 file.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jul 2022 07:28:29 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-07-14T07:28:29Z</dc:date>
    <item>
      <title>Export/Import certificates from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650072#M1091827</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm migrating a multi-context ASA with both identity and CA certificates to a FTD and I wonder what would be the best way to export those certificates from the ASA and then import them to a FTD? I have access to both CLI and ASDM on the ASA, but would prefere using the CLI. In ASDM there is an option to export identity certificates, but not the CA certificates so I guess I need to use a different methods for those?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 07:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650072#M1091827</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-07-14T07:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Export/Import certificates from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650080#M1091828</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/256705"&gt;@Chess Norris&lt;/a&gt; &lt;A href="https://integratingit.wordpress.com/2019/09/28/asa-export-import-certificate/" target="_self"&gt;here&lt;/A&gt; is a guide to export the ASA certificate to PKCS12 file. On the FTD you just need to import the PKCS12 file.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 07:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650080#M1091828</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-07-14T07:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Export/Import certificates from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650085#M1091829</link>
      <description>&lt;P&gt;Thanks for the quick reply. I'll take a look at this guide.&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 07:40:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650085#M1091829</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-07-14T07:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Export/Import certificates from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650100#M1091831</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;While I was able to export/import some of the certificates, the one that are currently associated with RA VPN on the ASA fails. When I'm trying to enroll it on FTD, it gives me an error saying "Fail to configure CA certificate"&lt;/P&gt;
&lt;P&gt;Using the exact same method I was able to enroll some other identity certificates, so I am not sure why this one fails. How can I troubleshoot this?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 08:07:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650100#M1091831</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-07-14T08:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: Export/Import certificates from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650180#M1091836</link>
      <description>&lt;P&gt;Followed every step in this troubleshoot guide - &lt;A title="Troubleshoot Certificate Error &amp;quot;Fail to configure CA certificate&amp;quot; on FMC" href="https://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/215855-troubleshoot-certificate-error-fail-to.html" target="_self"&gt;Troubleshoot Certificate Error "Fail to configure CA certificate" on FMC&lt;/A&gt;&amp;nbsp;, but without any luck. I'm still getting the same error when trying to enroll. It's so strange because the same cert works perfectly on the ASA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 10:52:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650180#M1091836</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-07-14T10:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Export/Import certificates from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650234#M1091838</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/256705"&gt;@Chess Norris&lt;/a&gt; what is the difference between the certificate(s) that worked and the one that doesn't? Perhaps a key size not supported on FTD/FMC?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 12:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4650234#M1091838</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-07-14T12:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Export/Import certificates from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4651333#M1091872</link>
      <description>&lt;P&gt;I was able to solve the issue by following this guide&amp;nbsp;&lt;A href="https://www.linkedin.com/pulse/anyconnect-ftd-pkcs12-openssl-matt-albrecht/" target="_self"&gt;AnyConnect (FTD), PKCS12, and OpenSSL&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I used OpenSSL to&amp;nbsp;associate the CA chain&amp;nbsp;and created a new PKCS12 file. After doing that, I could enroll the certificate in FMC without any issues.&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 18:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/export-import-certificates-from-asa-to-ftd/m-p/4651333#M1091872</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-07-15T18:01:51Z</dc:date>
    </item>
  </channel>
</rss>

