<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC/FTD 10 ACME Cert in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5379053#M1124819</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for submitting the feedback for this document.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have updated the "Prerequisites for Using ACME Certificates" topic with a sample I&lt;SPAN&gt;SRG root certificate.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/usecase/VPN/using-acme-certificates-ravpn-policies-fmc.html#prerequisites-for-using-acme-certificates" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/usecase/VPN/using-acme-certificates-ravpn-policies-fmc.html#prerequisites-for-using-acme-certificates&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;Please do let me know if this is the info that you wanted.&lt;/P&gt;
&lt;P&gt;Thanks,&amp;nbsp;&lt;BR /&gt;Rashmy&lt;/P&gt;</description>
    <pubDate>Tue, 24 Mar 2026 08:15:39 GMT</pubDate>
    <dc:creator>Rashmy Abraham</dc:creator>
    <dc:date>2026-03-24T08:15:39Z</dc:date>
    <item>
      <title>FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374277#M1124629</link>
      <description>&lt;P&gt;Just curious if anyone has made this work with FTD/FMC 10.0?&amp;nbsp; I decided to try it in lab just to see using Lets Encrypt and following the document here:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/usecase/VPN/using-acme-certificates-ravpn-policies-fmc.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/usecase/VPN/using-acme-certificates-ravpn-policies-fmc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I'm using a custom domain name that resolves to the IP of the outside interface of my firewall.&amp;nbsp; I'm using that interface as my Authentication Interface as well as my Source Interface in the Cert Enrollment although I've probably tried this every different way with every different interface.&amp;nbsp; A packet capture run on the outside interface when I try this shows ssl coversation with&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" href="https://acme-v02.api.letsencrypt.org/directory" target="_blank" rel="noopener" data-config-metrics-title="dest_pg_body_links" data-config-metrics-group="dest_pg_body"&gt;https://acme-v02.api.letsencrypt.org&lt;/A&gt;.&amp;nbsp; It also shows the http get request for /.well-known/acme-challange/randomstring resulting in an HTTP/1.1 200 OK.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My result is always the spinning in progress for a period of time followed by failure and it stating the generic:&lt;BR /&gt;&lt;STRONG&gt;Possible Recommended Actions:&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;1. Ensure the following to make sure of connectivity to the ACME Server from the Firewall Threat Defense&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Route is added to the ACME Server via the source interface&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- If ACME Server is referred with hostname/FQDN/ALT FQDN, configure DNS at Threat Defense Platform Settings to resolve hostname&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Ensure that the ACME Server and the Firewall Threat Defense are in time-sync by configuring the same NTP Server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I ran the debug crypto ca acme but didn't yield anything that would be giving me a failure reason.&amp;nbsp;&lt;BR /&gt;Just curious if anyone else has played with this or made it work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 02:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374277#M1124629</guid>
      <dc:creator>brian1stamper1</dc:creator>
      <dc:date>2026-03-04T02:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374284#M1124630</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1586848"&gt;@brian1stamper1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;One thing to check: are there any upstream devices that might be handling the ACME challenge instead of the FTD?&lt;/P&gt;
&lt;P&gt;The HTTP/1.1 200 message may be coming from an ISP modem, router, CPE, or any other upstream device before it reaches the FTD.&lt;/P&gt;
&lt;P&gt;If another device that is not the FTD is responding, then obviously the ACME challenge will fail because the correct ACME token won't be served.&lt;/P&gt;
&lt;P&gt;Check the data path from the FTD to the ACME server and that might help you fix your issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 02:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374284#M1124630</guid>
      <dc:creator>Ben Weber</dc:creator>
      <dc:date>2026-03-04T02:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374285#M1124631</link>
      <description>&lt;P&gt;If there's an upstream firewall, are you allowing both http and https inbound to your lab firewall's outside interface? The ACME enrollment uses http for a brief moment while enrolling.&lt;/P&gt;
&lt;P&gt;I did get it to work in my lab environment FYI. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 03:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374285#M1124631</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-03-04T03:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374289#M1124633</link>
      <description>&lt;P&gt;There would not be.&amp;nbsp; The firewall itself has the public IP that the FQDN of the cert request resolves to.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 05:02:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374289#M1124633</guid>
      <dc:creator>brian1stamper1</dc:creator>
      <dc:date>2026-03-04T05:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374290#M1124634</link>
      <description>&lt;P&gt;There is no upstream firewall in this case.&amp;nbsp; The firewall requesting the cert has the public IP and directly connects to the internet.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 05:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374290#M1124634</guid>
      <dc:creator>brian1stamper1</dc:creator>
      <dc:date>2026-03-04T05:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374414#M1124643</link>
      <description>&lt;P&gt;I figured this out!!&amp;nbsp; I think Cisco needs to update this documentation as they have a critical step missing.&amp;nbsp; In the below portion of the document they have you add the Cert to the firewall.&amp;nbsp; What isn't listed or is maybe assumed is that you have to add the Root to the firewall first.&amp;nbsp; You can see it in the background of the pic in Step 5. Stands to reason and makes sense that would need to be there.&amp;nbsp; However, no where in the document does it actually tell you to do that other than in this screenshot it shows it.&amp;nbsp;&lt;BR /&gt;I remember having to do this setting up SAML auth to Entra for VPN as well and I'm pretty sure if I remember right they tell you in that how to document to add this root cert before adding the cert from Entra for the SAML/IDP.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Hopefully this helps someone else following the document or Cisco updates it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2026-03-04_07-58-54.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/260602i67D1E121BB17A40E/image-size/large?v=v2&amp;amp;px=999" role="button" title="2026-03-04_07-58-54.jpg" alt="2026-03-04_07-58-54.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_e795378119f90brian1stamper1_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 14:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374414#M1124643</guid>
      <dc:creator>brian1stamper1</dc:creator>
      <dc:date>2026-03-04T14:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374483#M1124645</link>
      <description>&lt;P&gt;I agree it's a bit tricky. I had just re-built mine and recreated an ACME enrollment successfully for the first time since originally doing it during 10.0 beta testing.&lt;/P&gt;
&lt;P&gt;If you read the "General Prerequisites" section it does say "Enroll an ACME CA certificate, a manual CA-only certificate that authenticates the ACME server, on the device." It shows a screenshot of the cert enrollment but not the part about making it a trustpoint on the device. It would be better if that was explicitly called out in the instructions.&lt;/P&gt;
&lt;P&gt;I submitted feedback to the Cisco documentation to that effect. Hopefully they will update it.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 16:46:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5374483#M1124645</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-03-04T16:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5379053#M1124819</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for submitting the feedback for this document.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have updated the "Prerequisites for Using ACME Certificates" topic with a sample I&lt;SPAN&gt;SRG root certificate.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/usecase/VPN/using-acme-certificates-ravpn-policies-fmc.html#prerequisites-for-using-acme-certificates" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/usecase/VPN/using-acme-certificates-ravpn-policies-fmc.html#prerequisites-for-using-acme-certificates&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;Please do let me know if this is the info that you wanted.&lt;/P&gt;
&lt;P&gt;Thanks,&amp;nbsp;&lt;BR /&gt;Rashmy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 08:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5379053#M1124819</guid>
      <dc:creator>Rashmy Abraham</dc:creator>
      <dc:date>2026-03-24T08:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5379107#M1124826</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/288240"&gt;@Rashmy Abraham&lt;/a&gt;&amp;nbsp;- that's clearer now.&lt;/P&gt;
&lt;P&gt;I have been asking in another thread if it is possible to have the CA certificate included in the ACME certificate trustpoint. So far it appears that is not possible. This results in an incomplete chain being presented for the TLS connections.&lt;BR /&gt;&lt;BR /&gt;Reference:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-security/ama-secure-firewall-new-features-automation-and-troubleshooting/td-p/5374154" target="_blank"&gt;https://community.cisco.com/t5/network-security/ama-secure-firewall-new-features-automation-and-troubleshooting/td-p/5374154&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 12:04:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5379107#M1124826</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-03-24T12:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5547189#M1125026</link>
      <description>&lt;P&gt;I wonder if they'll add a way for it to pull down full-chain bundles in the future so a new intermediate CA is included. you can sometimes get away with signing with root CA's but it's definitely not best practice. otherwise you'll be stuck babysitting the validity for your intermediates.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 21:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5547189#M1125026</guid>
      <dc:creator>stpsucks</dc:creator>
      <dc:date>2026-04-21T21:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD 10 ACME Cert</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5551869#M1125164</link>
      <description>&lt;P&gt;I had a bit of a struggle with this one too. I already had the&amp;nbsp;&lt;SPAN&gt;I&lt;/SPAN&gt;&lt;SPAN&gt;SRG root certificate enrolled on the FTD, but I also selected it on the actually ACME enrolment, and then it fails. just leave the selection box blank and it will say "manual CA Certificate"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 May 2026 17:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-10-acme-cert/m-p/5551869#M1125164</guid>
      <dc:creator>kelwingmen</dc:creator>
      <dc:date>2026-05-10T17:27:49Z</dc:date>
    </item>
  </channel>
</rss>

