<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC Audit log Certificate error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893572#M1103006</link>
    <description>&lt;P&gt;I generated a CSR from my FMC for an Audit Log Certificate.&amp;nbsp; I sent that to our PKI admin and he generated a certificate.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try to import the certificate I get the following error:&lt;/P&gt;&lt;P&gt;Error&lt;/P&gt;&lt;P&gt;Unable to identify certificate purpose&lt;/P&gt;&lt;P&gt;Any guidance is greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2023 10:01:08 GMT</pubDate>
    <dc:creator>AMadjeski</dc:creator>
    <dc:date>2023-07-27T10:01:08Z</dc:date>
    <item>
      <title>FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893572#M1103006</link>
      <description>&lt;P&gt;I generated a CSR from my FMC for an Audit Log Certificate.&amp;nbsp; I sent that to our PKI admin and he generated a certificate.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try to import the certificate I get the following error:&lt;/P&gt;&lt;P&gt;Error&lt;/P&gt;&lt;P&gt;Unable to identify certificate purpose&lt;/P&gt;&lt;P&gt;Any guidance is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 10:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893572#M1103006</guid>
      <dc:creator>AMadjeski</dc:creator>
      <dc:date>2023-07-27T10:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893675#M1103007</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp; Note that for&amp;nbsp;&lt;SPAN&gt;an audit log certificate t&lt;/SPAN&gt;&lt;SPAN&gt;he&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;FMC Server Certificate&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;must include the&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" href="https://access.redhat.com/solutions/28965" target="_blank" rel="noopener"&gt;clientAuth&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;extended key usage ,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:15:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893675#M1103007</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-07-27T12:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893682#M1103008</link>
      <description>&lt;P&gt;Thanks for the response.&amp;nbsp; Can you give me a little more detail on that?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where do I check to see if that is included?&lt;/P&gt;&lt;P&gt;Does that need to be set prior to generating the CSR for the Audit Certificate?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893682#M1103008</guid>
      <dc:creator>AMadjeski</dc:creator>
      <dc:date>2023-07-27T12:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893690#M1103009</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Review this article&amp;nbsp; :&amp;nbsp;&lt;A href="https://access.redhat.com/solutions/28965" target="_blank" rel="noopener"&gt;https://access.redhat.com/solutions/28965&lt;/A&gt;&amp;nbsp; &amp;nbsp;and check your certificate and or generate as needed ,&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (look for &lt;STRONG&gt;clientAuth&lt;/STRONG&gt; in the document)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893690#M1103009</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-07-27T12:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893704#M1103011</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- (adding) :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; To generate a CSR certificate with clientauth with clientauth parameter included, you can use the following OpenSSL command:&lt;/P&gt;
&lt;P&gt;openssl req -new -newkey rsa:4096 -nodes -keyout client.key -out client.csr&lt;STRONG&gt; -clientauth&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;This command will generate a CSR certificate with the clientauth parameter included. The clientauth parameter tells the CA that the certificate will be used for client authentication.&lt;/P&gt;
&lt;P&gt;Here is an explanation of the command line arguments:&lt;/P&gt;
&lt;P&gt;-new - This tells OpenSSL to generate a new CSR certificate.&lt;BR /&gt;-newkey rsa:4096 - This tells OpenSSL to generate a new RSA key with a key size of 4096 bits.&lt;BR /&gt;-nodes - This tells OpenSSL to generate a key without a password.&lt;BR /&gt;-keyout client.key - This specifies the output file for the private key.&lt;BR /&gt;-out client.csr - This specifies the output file for the CSR certificate.&lt;BR /&gt;&lt;STRONG&gt;-clientauth&lt;/STRONG&gt; - This tells OpenSSL to include the clientauth parameter in the CSR certificate.&lt;BR /&gt;&lt;BR /&gt;Once you have run the command, you will have a CSR certificate with the clientauth parameter included. You can then submit the CSR certificate to a CA to be signed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893704#M1103011</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-07-27T12:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893730#M1103013</link>
      <description>&lt;P&gt;I am assuming I should do this from expert mode.&amp;nbsp; I am getting a "Unrecognized flag clientauth" error&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:23:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893730#M1103013</guid>
      <dc:creator>AMadjeski</dc:creator>
      <dc:date>2023-07-27T13:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893762#M1103017</link>
      <description>- Could be , I haven't tried it myself or generate the certificate&lt;BR /&gt;externally and import it ,&lt;BR /&gt;&lt;BR /&gt; M.&lt;BR /&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4893762#M1103017</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-07-27T13:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4895917#M1103080</link>
      <description>&lt;P&gt;I still have not found a resolution to this.&amp;nbsp; Has anyone else experienced this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 07:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4895917#M1103080</guid>
      <dc:creator>AMadjeski</dc:creator>
      <dc:date>2023-07-31T07:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4975191#M1106721</link>
      <description>&lt;P&gt;I was able to get passed the "&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;Unable to identify certificate purpose&lt;/FONT&gt;"&lt;/SPAN&gt; error. I see the new cert info in the browser, but still get a certificate error in the browser, not FMC specifically. Working on that. I believe it's my DNS.&lt;/P&gt;
&lt;P&gt;I used an Ubuntu Linux server where I already created a CA to respond to CSRs for my internal lab. You can also use a third part service. My steps are specific to the Linux box.&lt;/P&gt;
&lt;P&gt;Here's what I did to get passed the error:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&amp;nbsp;In FMC click on the System settings cog -&amp;gt; Configuration -&amp;gt; HTTPS Certificate -&amp;gt; Generate NEW CSR&lt;/LI&gt;
&lt;LI&gt;Fill in the pop-up form information.&lt;/LI&gt;
&lt;LI&gt;Copy the PEM to a simple text editor.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Paste the PEM into your favorite text editor and then save it. Make sure the name you give it ends with &lt;FONT face="courier new,courier"&gt;.csr&lt;/FONT&gt; so you know what this file is for when you look at it again in the future.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Create a new extension file called &lt;FONT face="courier new,courier"&gt;v3.ext&lt;/FONT&gt; in your favorite text editor.&lt;/LI&gt;
&lt;LI&gt;Put this inside the file and save it:&amp;nbsp;&lt;BR /&gt;
&lt;PRE&gt;&lt;FONT face="courier new,courier"&gt;subjectAltName = DNS:fmcname.domain.local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;extendedKeyUsage = serverAuth, clientAuth&lt;/FONT&gt;&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;Run this command in the Linux box to create a CSR response that the FMC will accept. Depending upon which directory you are doing this in, you may need to use &lt;FONT face="courier new,courier"&gt;sudo&lt;/FONT&gt;.
&lt;PRE&gt;openssl x509 -req -sha256 -in fmcname.domain.local.csr -CA rootCACert.pem -CAkey rootCAKey.pem -CAcreateserial -out fmcname.domain.local.cert.pem -days 1000 -extfile v3.ext&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;Check the purpose of the certificate you just created with this command.
&lt;PRE&gt;openssl x509 -noout -text -purpose -in fmcname.domain.local.cert.pem&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;Look for the Subject Alternative Name and Extended Key Usage in your output to match the &lt;FONT face="courier new,courier"&gt;v3.ext&lt;/FONT&gt; file contents.&lt;/LI&gt;
&lt;LI&gt;View the new certificate PEM contents and copy to clipboard.&lt;/LI&gt;
&lt;LI&gt;Back in FMC, click "Import HTTPS Server Certificate".&lt;/LI&gt;
&lt;LI&gt;Paste clipboard contents into the "Server Certificate" section.&lt;/LI&gt;
&lt;LI&gt;Click the "Save" button.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;You should expect to not receive a "&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;Unable to identify certificate purpose&lt;/FONT&gt;"&lt;/SPAN&gt; error and also see the "Current HTTPS Server Certificate" information update.&lt;/P&gt;
&lt;P&gt;If you are not getting the same behavior, please post here. If this post helped you, please give it a thumbs up.&lt;/P&gt;
&lt;P&gt;Securely,&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2023 22:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4975191#M1106721</guid>
      <dc:creator>daveschw</dc:creator>
      <dc:date>2023-12-10T22:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit log Certificate error</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4975221#M1106724</link>
      <description>&lt;P&gt;Basically this stems from the certificate template used by the issuing CA. As noted, tweaking the parameter in the CSR can sometime override this.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 03:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-log-certificate-error/m-p/4975221#M1106724</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-12-11T03:51:46Z</dc:date>
    </item>
  </channel>
</rss>

