<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HI Marvin, I think that only in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/delete-certificates-cisco-asa/m-p/2691121#M194493</link>
    <description>&lt;P&gt;HI Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think&amp;nbsp;that only lets you interact with trust points;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="page" title="Page 5"&gt;&lt;DIV class="section"&gt;&lt;DIV class="layoutArea"&gt;&lt;DIV class="column"&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'"&gt;To enter certificate chain configuration mode for the indicated trustpoint, use the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;crypto ca certificate chain &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'"&gt;command in global configuration mode. To return to global configuration mode, use the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;no &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'"&gt;form of this command or use the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;exit &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'"&gt;command. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;crypto ca certificate chain &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-style: italic"&gt;trustpoint&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;[no] crypto ca certificate chain &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-style: italic"&gt;trustpoint&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 11 Jun 2015 07:07:09 GMT</pubDate>
    <dc:creator>Peter Long</dc:creator>
    <dc:date>2015-06-11T07:07:09Z</dc:date>
    <item>
      <title>Delete Certificates Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/delete-certificates-cisco-asa/m-p/2691119#M194479</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I&amp;nbsp;can't find any syntax for removing &lt;EM&gt;&lt;STRONG&gt;single&lt;/STRONG&gt;&lt;/EM&gt; certs.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;show crypto ca certificates&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;shows &lt;STRONG&gt;all&lt;/STRONG&gt; the certificates in the ASA Crypto archive, for all the trust-points (of which there are three). But theres some old and unused certificates in there, I know removing the truspoint and recreating it will remove all the associated certificates, but &lt;STRONG&gt;is there a way&lt;/STRONG&gt; to delete an individual certificate either by its serial number or some other method.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: I've tried revoking the certs in the PKI (Windows certificate services), but that does not remove them either.&lt;/P&gt;&lt;P&gt;I know they are not doing any harm, but the client wants them removed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-certificates-cisco-asa/m-p/2691119#M194479</guid>
      <dc:creator>Peter Long</dc:creator>
      <dc:date>2019-03-12T06:05:06Z</dc:date>
    </item>
    <item>
      <title>Hi Pete,</title>
      <link>https://community.cisco.com/t5/network-security/delete-certificates-cisco-asa/m-p/2691120#M194486</link>
      <description>&lt;P&gt;Hi Pete,&lt;/P&gt;
&lt;P&gt;Does this fit the bill for what you're asking?&lt;/P&gt;

&lt;PRE&gt;
ASA(config)# no crypto ca certificate chain ?

configure mode commands/options:
  WORD &amp;lt; 65 char  Trustpoint Name&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 01:41:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-certificates-cisco-asa/m-p/2691120#M194486</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-06-11T01:41:00Z</dc:date>
    </item>
    <item>
      <title>HI Marvin, I think that only</title>
      <link>https://community.cisco.com/t5/network-security/delete-certificates-cisco-asa/m-p/2691121#M194493</link>
      <description>&lt;P&gt;HI Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think&amp;nbsp;that only lets you interact with trust points;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="page" title="Page 5"&gt;&lt;DIV class="section"&gt;&lt;DIV class="layoutArea"&gt;&lt;DIV class="column"&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'"&gt;To enter certificate chain configuration mode for the indicated trustpoint, use the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;crypto ca certificate chain &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'"&gt;command in global configuration mode. To return to global configuration mode, use the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;no &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'"&gt;form of this command or use the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;exit &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'"&gt;command. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;crypto ca certificate chain &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-style: italic"&gt;trustpoint&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-weight: 700"&gt;[no] crypto ca certificate chain &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'Times'; font-style: italic"&gt;trustpoint&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 Jun 2015 07:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-certificates-cisco-asa/m-p/2691121#M194493</guid>
      <dc:creator>Peter Long</dc:creator>
      <dc:date>2015-06-11T07:07:09Z</dc:date>
    </item>
    <item>
      <title>Follow Up:OK you can delete a</title>
      <link>https://community.cisco.com/t5/network-security/delete-certificates-cisco-asa/m-p/2691122#M194499</link>
      <description>&lt;P&gt;Follow Up:&lt;/P&gt;&lt;P&gt;OK you can delete a CA cert like so;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;crypto ca certificate chain {Trustpointt}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;no certificate ca {Certificate ID}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;However, if you want to delete an identity cert then just do the same but drop the 'ca' keyword.&lt;/P&gt;&lt;P&gt;You will have a problem if this trustpoint is enrolled via SCEP/NDES, (as mine was).&lt;/P&gt;&lt;P&gt;And trying to change the trustpoint to 'enrolment terminal' wont help because you can't make a change to an authenticated trustpoint.&lt;/P&gt;&lt;P&gt;Before proceeding backup the trustpoint configurations.&lt;/P&gt;&lt;P&gt;So Im my case I had to remove the CA cert for this trustpoint (this automatically removes all the identity certs as well but that's OK).&lt;/P&gt;&lt;P&gt;Then re-autheticate to SCEP and get the CA cert back&amp;nbsp;again. (&lt;STRONG&gt;Note&lt;/STRONG&gt;: For some reason the firewall has lost its fqdn info from the truspoint, (setup in the config). I restored from earlier, but its only one line!&lt;/P&gt;&lt;P&gt;To get the CA Cert back;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;crypto ca authenticate {Trustpoint}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Finally re-enroll with NDES/SCEP and you are good to go;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;crypto ca enroll {Trustpoint}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem solved.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.petenetlive.com"&gt;Pete&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2015 09:17:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-certificates-cisco-asa/m-p/2691122#M194499</guid>
      <dc:creator>Peter Long</dc:creator>
      <dc:date>2015-06-12T09:17:19Z</dc:date>
    </item>
  </channel>
</rss>

