<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption using certificate generated from Active Directory C in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137237#M1113859</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1494970"&gt;@davparker&lt;/a&gt;&amp;nbsp;glad to hear it's working.&lt;/P&gt;
&lt;P&gt;FYI, SSL decryption is expensive on resources, so I would be selective on what you decrypt, don't decrypt everything.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2024 20:58:06 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-06-27T20:58:06Z</dc:date>
    <item>
      <title>SSL Decryption using certificate generated from Active Directory CA?</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5136590#M1113821</link>
      <description>&lt;P&gt;I have not been able to find any good documentation on how to generate/install a certificate issued by an Active Directory CA for use with SSL Decryption policy. I've read through the config guides for 7.2x. It seems like this would be an incredibly common scenario. Any help would be appreciated.&lt;/P&gt;&lt;P&gt;Thanks - David&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 22:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5136590#M1113821</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-06-26T22:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption using certificate generated from Active Directory C</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5136591#M1113822</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1494970"&gt;@davparker&lt;/a&gt;&amp;nbsp;try this guide &lt;A href="https://integratingit.wordpress.com/2019/02/16/firepower-ssl-decryption/" target="_blank" rel="noopener"&gt;https://integratingit.wordpress.com/2019/02/16/firepower-ssl-decryption/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;When signing the CSR make sure the certificate template selected is the Subordinate Root Authority.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 22:17:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5136591#M1113822</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-06-26T22:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption using certificate generated from Active Directory C</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5136592#M1113823</link>
      <description>&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2019/02/16/firepower-ssl-decryption/" target="_blank" rel="noopener"&gt;https://integratingit.wordpress.com/2019/02/16/firepower-ssl-decryption/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=tAIdcZ3EBiw&amp;amp;t=207s" target="_blank"&gt;https://www.youtube.com/watch?v=tAIdcZ3EBiw&amp;amp;t=207s&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;check these link&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 22:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5136592#M1113823</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-26T22:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption using certificate generated from Active Directory C</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137052#M1113849</link>
      <description>&lt;P&gt;Thanks. My PKI person is asking about the compatibility settings on Subordinate Certificate Authority Template used to generate the certificate for the following fields:&lt;/P&gt;&lt;P&gt;Certificate Authority&lt;BR /&gt;Certificate Recipient&lt;/P&gt;&lt;P&gt;Our AD servers are at ver 2016. Any thoughts?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 14:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137052#M1113849</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-06-27T14:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption using certificate generated from Active Directory C</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137085#M1113850</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1494970"&gt;@davparker&lt;/a&gt; the standard Microsoft Sub CA template will suffice. They could duplicate the existing template (without modifications) if they wish.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 15:14:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137085#M1113850</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-06-27T15:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption using certificate generated from Active Directory C</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137232#M1113858</link>
      <description>&lt;P&gt;Very nice! Decryption is now working. Now trying to figure out what not to decrypt prior to enabling it for more resources.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 20:51:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137232#M1113858</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-06-27T20:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption using certificate generated from Active Directory C</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137237#M1113859</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1494970"&gt;@davparker&lt;/a&gt;&amp;nbsp;glad to hear it's working.&lt;/P&gt;
&lt;P&gt;FYI, SSL decryption is expensive on resources, so I would be selective on what you decrypt, don't decrypt everything.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 20:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137237#M1113859</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-06-27T20:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption using certificate generated from Active Directory C</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137245#M1113860</link>
      <description>&lt;P&gt;I think you need to config decrypt known key i.e. the server inside your network&amp;nbsp;&lt;BR /&gt;so using it IP to filter which traffic need to decrypt&amp;nbsp;&lt;BR /&gt;if you allow all traffic your traffic will start drop&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (142).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221849i6C7B09C485621FEA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (142).png" alt="Screenshot (142).png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (143).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221850iD00D89C26A6876B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (143).png" alt="Screenshot (143).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 21:20:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137245#M1113860</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-27T21:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption using certificate generated from Active Directory C</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137254#M1113861</link>
      <description>&lt;P&gt;All our Internet exposed servers are in external data centers. We basically have no inbound rules other than what is needed for VPN. I plan on excluding traffic from decryption for our common domains where most our business apps reside. Also excluding stuff like WebEx and Teams. Also for What categories of web traffic do people typically decrypt traffic for?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 22:02:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5137254#M1113861</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-06-27T22:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption using certificate generated from Active Directory C</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5139081#M1113940</link>
      <description>&lt;P&gt;FYI,&lt;/P&gt;&lt;P&gt;I found this resource to be very helpful when trying to figure out what to decrypt vs DND. &lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKSEC-3063.pdf" target="_blank"&gt;BRKSEC-3063 (ciscolive.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 18:16:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-using-certificate-generated-from-active-directory/m-p/5139081#M1113940</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-07-02T18:16:09Z</dc:date>
    </item>
  </channel>
</rss>

