<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring CRL FTD FDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847664#M1101163</link>
    <description>&lt;P&gt;Using version v7.0.5 FDM (or any 7x) , is it possible to reference a certificate revocation List(CRL)?&lt;/P&gt;
&lt;P&gt;For use with RA VPN (anyconnect / Secure Client). I know this is possible using FMC, however is this possible using FDM.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2023 13:50:55 GMT</pubDate>
    <dc:creator>Jonathan Haldane</dc:creator>
    <dc:date>2023-06-02T13:50:55Z</dc:date>
    <item>
      <title>Configuring CRL FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847664#M1101163</link>
      <description>&lt;P&gt;Using version v7.0.5 FDM (or any 7x) , is it possible to reference a certificate revocation List(CRL)?&lt;/P&gt;
&lt;P&gt;For use with RA VPN (anyconnect / Secure Client). I know this is possible using FMC, however is this possible using FDM.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 13:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847664#M1101163</guid>
      <dc:creator>Jonathan Haldane</dc:creator>
      <dc:date>2023-06-02T13:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring CRL FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847706#M1101166</link>
      <description>&lt;P&gt;I don't believe that is supported:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cisco.com/quickview/bug/CSCvs19613" target="_blank"&gt;https://bst.cisco.com/quickview/bug/CSCvs19613&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Even if you try to use the Flexconfig that wouldn't work as I remember the crypto command is a blacklisted command.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 15:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847706#M1101166</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-02T15:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring CRL FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847726#M1101167</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/215850-certificate-installation-and-renewal-on.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/215850-certificate-installation-and-renewal-on.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This certificate for FTD via FDM.&lt;/P&gt;
&lt;P&gt;Can you more elaborate about CRL?&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 15:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847726#M1101167</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-02T15:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring CRL FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847743#M1101168</link>
      <description>&lt;P&gt;Using a 2100 series firepower with only GUI FDM for Remote Access VPN with anyconnect/secure client authenticated using Client Certificates only.&lt;/P&gt;
&lt;P&gt;If we needed to revoke a client certificate (lost laptop etc). Visibility of the CRL would enable&amp;nbsp;the Firepower to know that this client certificate had been revoked. If there is no mechanism for CRL that would remove client certificate only as an option.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The next best option would be AAA (SAML, LDAP, RADIUS etc) &amp;amp; client certificate&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 15:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847743#M1101168</guid>
      <dc:creator>Jonathan Haldane</dc:creator>
      <dc:date>2023-06-02T15:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring CRL FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847761#M1101169</link>
      <description>&lt;P&gt;If you should enable SAML on the FDM, please be aware that the FDM will error out when you try to push the changes if the SAML certificate has the "ca-check" enabled. Unlike the FMC, the FDM does not have any option to turn that feature off, and the Flexconfig won't allow you to do it due to the crypto command being blacklisted. So in that case you would need to use a third party tool such as OpenSSL or XCA to generate a new cert and its private key, disable the ca-check, import the cert and the private key into Azure, and finally import the cert into FDM.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 16:08:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847761#M1101169</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-02T16:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring CRL FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847767#M1101170</link>
      <description>&lt;DIV dir="auto"&gt;Thanks Aref, I have already come across that issue. XCA worked a treat.&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;Regards&lt;SPAN&gt;,&lt;BR /&gt;Jonathan&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Jun 2023 16:17:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-crl-ftd-fdm/m-p/4847767#M1101170</guid>
      <dc:creator>Jonathan Haldane</dc:creator>
      <dc:date>2023-06-02T16:17:35Z</dc:date>
    </item>
  </channel>
</rss>

