<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Assuming you're using a self in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asdm-ssl-key-size-for-http-server/m-p/2579153#M197722</link>
    <description>&lt;P&gt;Assuming you're using a self-signed identity certificate here, you need to add a new identity certificate and specify that it uses the new 2048-bit key.&lt;/P&gt;&lt;P&gt;Something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;crypto key generate rsa label 2048-bit-rsakey modulus 2048 noconfirm&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; crypto ca trustpoint ASDM_TrustPoint2&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; revocation-check none&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; keypair 2048-bit-rsakey&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; id-usage ssl-ipsec&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; no fqdn&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; subject-name CN=&amp;lt;your ASA common name&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; enrollment self&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; crypto ca enroll ASDM_TrustPoint2 noconfirm&lt;/P&gt;&lt;P&gt;You can then delete the old identity certificate.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jan 2015 18:57:37 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-01-20T18:57:37Z</dc:date>
    <item>
      <title>ASDM ssl key size for http server</title>
      <link>https://community.cisco.com/t5/network-security/asdm-ssl-key-size-for-http-server/m-p/2579152#M197721</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;question - my understanding was that the ASDM/GUI uses the general public key to generate it's ssl cert - e.g.&lt;/P&gt;&lt;P&gt;when browsing to the ASA for https:// ASDM access -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;customer would like to change the ssl cert from 1024 bits 2048.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas how I do that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed the default public key to 2048 - e.g.&lt;/P&gt;&lt;P&gt;"crypto key generate rsa general-keys modulus 2048"&lt;/P&gt;&lt;P&gt;then disabled and re-enabled ASDM via&lt;/P&gt;&lt;P&gt;"no http server enable " and "http server enable"&lt;/P&gt;&lt;P&gt;when I access the asdm webpage still seeing a 1024 bit cert for it...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-ssl-key-size-for-http-server/m-p/2579152#M197721</guid>
      <dc:creator>mhall</dc:creator>
      <dc:date>2019-03-26T00:54:45Z</dc:date>
    </item>
    <item>
      <title>Assuming you're using a self</title>
      <link>https://community.cisco.com/t5/network-security/asdm-ssl-key-size-for-http-server/m-p/2579153#M197722</link>
      <description>&lt;P&gt;Assuming you're using a self-signed identity certificate here, you need to add a new identity certificate and specify that it uses the new 2048-bit key.&lt;/P&gt;&lt;P&gt;Something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;crypto key generate rsa label 2048-bit-rsakey modulus 2048 noconfirm&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; crypto ca trustpoint ASDM_TrustPoint2&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; revocation-check none&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; keypair 2048-bit-rsakey&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; id-usage ssl-ipsec&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; no fqdn&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; subject-name CN=&amp;lt;your ASA common name&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; enrollment self&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; crypto ca enroll ASDM_TrustPoint2 noconfirm&lt;/P&gt;&lt;P&gt;You can then delete the old identity certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2015 18:57:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-ssl-key-size-for-http-server/m-p/2579153#M197722</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-01-20T18:57:37Z</dc:date>
    </item>
  </channel>
</rss>

