<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Importing certificate for LDAPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/importing-certificate-for-ldaps/m-p/4801393#M1099003</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thanks for the fast respond, appreciated.&amp;nbsp; Thought this would be simple where we get the certification from our Domain Controller (ldap server) and import into ASA as a trustpoint, then it threw that error trying install.&amp;nbsp; we have a internal CA server, so can you share how you got your colleague to generated the LDAPS certificate with a shorter expiration date such as 2 years?&amp;nbsp; Does that mean it will that it would need renewal every 2 years?&amp;nbsp; Btw, I'm running asa 9.16.4 on the asa I am testing, but would need to update my live environment ASA from 9.12.4 to 9.16.4 as we have Duo 2FA which they announced recent change to secure LDAPS and their certificate work.&amp;nbsp; Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 25 Mar 2023 21:19:36 GMT</pubDate>
    <dc:creator>joeyx31x13</dc:creator>
    <dc:date>2023-03-25T21:19:36Z</dc:date>
    <item>
      <title>Importing certificate for LDAPS</title>
      <link>https://community.cisco.com/t5/network-security/importing-certificate-for-ldaps/m-p/4705220#M1094333</link>
      <description>&lt;P&gt;We need to import the server certificate to the ASA in order to use LDAPS for VPN authentication.&amp;nbsp; The server certificate has a creation date of 06-06-2021 but an expiration of 06-06-2121.&amp;nbsp; When I attempt to import the certificate into the ASA the creation date looks correct, but the expiration date shows 04-30-1985??&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.16(3)19&lt;/P&gt;&lt;P&gt;% CA Cert not yet valid or is expired -&lt;BR /&gt;start date: 14:05:13 UTC Jun 6 2021&lt;BR /&gt;end date: 07:46:57 UTC Apr 30 1985&lt;BR /&gt;% Error in saving certificate: status = FAIL&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 23:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/importing-certificate-for-ldaps/m-p/4705220#M1094333</guid>
      <dc:creator>lmqtechnology</dc:creator>
      <dc:date>2022-10-18T23:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificate for LDAPS</title>
      <link>https://community.cisco.com/t5/network-security/importing-certificate-for-ldaps/m-p/4801379#M1099000</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;did you have this resolved as I have the issue as well? Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 25 Mar 2023 19:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/importing-certificate-for-ldaps/m-p/4801379#M1099000</guid>
      <dc:creator>joeyx31x13</dc:creator>
      <dc:date>2023-03-25T19:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificate for LDAPS</title>
      <link>https://community.cisco.com/t5/network-security/importing-certificate-for-ldaps/m-p/4801385#M1099002</link>
      <description>&lt;P&gt;Yup, it's an ASA bug whereby it cannot accept certificates that have an expiration date that is too far in the future (the error message is completely misleading).&amp;nbsp; In our case the person who generated the LDAPS certificate gave it an expiration date of 100 years in the future.&amp;nbsp; We simply got them to regenerate the certificate with a shorter expiration date such as 2 years.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Mar 2023 19:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/importing-certificate-for-ldaps/m-p/4801385#M1099002</guid>
      <dc:creator>lmqtechnology</dc:creator>
      <dc:date>2023-03-25T19:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificate for LDAPS</title>
      <link>https://community.cisco.com/t5/network-security/importing-certificate-for-ldaps/m-p/4801393#M1099003</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thanks for the fast respond, appreciated.&amp;nbsp; Thought this would be simple where we get the certification from our Domain Controller (ldap server) and import into ASA as a trustpoint, then it threw that error trying install.&amp;nbsp; we have a internal CA server, so can you share how you got your colleague to generated the LDAPS certificate with a shorter expiration date such as 2 years?&amp;nbsp; Does that mean it will that it would need renewal every 2 years?&amp;nbsp; Btw, I'm running asa 9.16.4 on the asa I am testing, but would need to update my live environment ASA from 9.12.4 to 9.16.4 as we have Duo 2FA which they announced recent change to secure LDAPS and their certificate work.&amp;nbsp; Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Mar 2023 21:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/importing-certificate-for-ldaps/m-p/4801393#M1099003</guid>
      <dc:creator>joeyx31x13</dc:creator>
      <dc:date>2023-03-25T21:19:36Z</dc:date>
    </item>
  </channel>
</rss>

