<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC: Automatic renew certificates? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5368943#M1124426</link>
    <description>&lt;P&gt;I wonder which ACME challenges FTD/FMC 10.x will support and whether automatic enrollment works for VPN peer certificate, FMC admin certificate and service provider certificate used by Azure Entra SSO.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ACME HTTP-01 and TLS-ALPN-01 could work for firewalls acting as VPN peers that are accessible from the internet and from the registrar's ACME service to verify the token. But our management center is in the internal network.&lt;/LI&gt;&lt;LI&gt;ACME DNS-01 challenge could work for devices that are not accessible from the internet such as the FMC, but we're currently using DNS delegation with Azure DNS and Certbot Azure DNS plugin and grant only write access to TXT records in acme DNS subdomain referenced by _acme-challenge.&amp;lt;hostname&amp;gt; CNAME.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Feb 2026 06:52:32 GMT</pubDate>
    <dc:creator>Network Diver</dc:creator>
    <dc:date>2026-02-10T06:52:32Z</dc:date>
    <item>
      <title>FMC: Automatic renew certificates?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5290529#M1121009</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Managing certificates is getting more and more a nightmare as the valid lifetime will be reduced to 47 days, especially on devices and virtual appliances that don't support any kind of automatic renewal protocol.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="47-day-certificate-lifespan-what-to-expect.png" style="width: 499px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244965i80A0CB137501660B/image-dimensions/499x459?v=v2" width="499" height="459" role="button" title="47-day-certificate-lifespan-what-to-expect.png" alt="47-day-certificate-lifespan-what-to-expect.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What are the options in FMC to automatically renew VPN peer certificates signed by an external public CA? Currently FMC 7.4 only supports EST and SCEP enrollment. [1] None of them supports automatic renewal. Also latest FMC 7.7 does not support ACME. We also use the VPN peer certificate for signing SAML requests for Microsoft EntraID, so renewing a certificate for a VPN peer involves multiple manual steps.&lt;BR /&gt;&lt;BR /&gt;[1]&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/objects-certs.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/objects-certs.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;[2] &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/770/management-center-device-config-77/objects-certs.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/770/management-center-device-config-77/objects-certs.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 06:57:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5290529#M1121009</guid>
      <dc:creator>Network Diver</dc:creator>
      <dc:date>2025-05-14T06:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Automatic renew certificates?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5301869#M1121420</link>
      <description>&lt;P&gt;Any outlook when FMC will support ACME for certificate renewals?&lt;BR /&gt;There's an enhancement request for this: &lt;A href="https://bst.cisco.com/quickview/bug/CSCvi00886" target="_blank"&gt;https://bst.cisco.com/quickview/bug/CSCvi00886&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 07:50:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5301869#M1121420</guid>
      <dc:creator>Network Diver</dc:creator>
      <dc:date>2025-06-24T07:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Automatic renew certificates?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5301880#M1121422</link>
      <description>&lt;P&gt;Thanks for sharing&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a nice day&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 07:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5301880#M1121422</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-24T07:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Automatic renew certificates?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5301982#M1121431</link>
      <description>&lt;P&gt;ACME-based certificate renewal support for FMC-managed FTD devices is expected to be introduced later this year (2025) with the next major release (10.0). It is already present and working in the latest ASA code and the FMC support builds on that same foundation.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 12:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5301982#M1121431</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-06-24T12:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Automatic renew certificates?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5302370#M1121455</link>
      <description>&lt;P&gt;I agree that the ASA code in 9.23(1) and later works but it installs only the requested certificate, not any intermediates, which means the certificate chain is incomplete. So, it doesn't work unless the client is able to use AIA fetching. The ones that don't support it complain about the cert.&amp;nbsp;&lt;SPAN&gt;I have a case open for this, actually.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 12:02:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5302370#M1121455</guid>
      <dc:creator>kajtzu</dc:creator>
      <dc:date>2025-06-25T12:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Automatic renew certificates?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5302543#M1121465</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/204624"&gt;@kajtzu&lt;/a&gt;&amp;nbsp;Good point - I have also brought up this issue with the Cisco team during FTD beta testing. We will see if they are able to incorporate the intermediate certificate(s) sooner vs. later. Behind the scenes it's a simple chaining operation that can be done in openssl.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 17:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5302543#M1121465</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-06-25T17:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Automatic renew certificates?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5368943#M1124426</link>
      <description>&lt;P&gt;I wonder which ACME challenges FTD/FMC 10.x will support and whether automatic enrollment works for VPN peer certificate, FMC admin certificate and service provider certificate used by Azure Entra SSO.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ACME HTTP-01 and TLS-ALPN-01 could work for firewalls acting as VPN peers that are accessible from the internet and from the registrar's ACME service to verify the token. But our management center is in the internal network.&lt;/LI&gt;&lt;LI&gt;ACME DNS-01 challenge could work for devices that are not accessible from the internet such as the FMC, but we're currently using DNS delegation with Azure DNS and Certbot Azure DNS plugin and grant only write access to TXT records in acme DNS subdomain referenced by _acme-challenge.&amp;lt;hostname&amp;gt; CNAME.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 06:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-automatic-renew-certificates/m-p/5368943#M1124426</guid>
      <dc:creator>Network Diver</dc:creator>
      <dc:date>2026-02-10T06:52:32Z</dc:date>
    </item>
  </channel>
</rss>

