<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic See the release notes for ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456232#M238642</link>
    <description>&lt;P&gt;See the &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/release/notes/asarn90.html"&gt;release notes for ASA 9.0(x)&lt;/A&gt;. As of 9.0(1) the ASA software introduced (among other things) support for "&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 11px; line-height: normal;"&gt;RSA certificates with 4096 bit keys for DTLS and IKEv2&lt;/SPAN&gt;"&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2014 14:04:27 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-05-08T14:04:27Z</dc:date>
    <item>
      <title>Cisco ASA platform\version RSA 4096 support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456231#M238641</link>
      <description>&lt;P&gt;Hi, all!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cisco ASA 5510 with 8.4(3)8 software onboar.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now i have an issue with Third Party wildcard certificate, which i whant to use in SSL-VPN. Issue is that it doesn't import. Doesn't import without any &lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt;intelligible messages. I'm use pks12.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;In other side i've tried import the same cert&lt;/SPAN&gt;&lt;/SPAN&gt;ificate&amp;nbsp; in ASA 5545X with&amp;nbsp; 9.1(2) software and it imported fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The previous wildcard certificate was working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Differents in this certificates that i found is RSA key lenth. In previous it was 2048, in current - 4096. It's look like my platform (5510) or my software (8.4(3)) doesn't support RSA 4096. But i cant found some official document about this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does &lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt;anyone else&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;encountered this kind of problem&lt;/SPAN&gt;&lt;/SPAN&gt;? Ot mayby someone reading about there?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:10:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456231#M238641</guid>
      <dc:creator>Luxoft Professional</dc:creator>
      <dc:date>2019-03-12T04:10:26Z</dc:date>
    </item>
    <item>
      <title>See the release notes for ASA</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456232#M238642</link>
      <description>&lt;P&gt;See the &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/release/notes/asarn90.html"&gt;release notes for ASA 9.0(x)&lt;/A&gt;. As of 9.0(1) the ASA software introduced (among other things) support for "&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 11px; line-height: normal;"&gt;RSA certificates with 4096 bit keys for DTLS and IKEv2&lt;/SPAN&gt;"&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 14:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456232#M238642</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-08T14:04:27Z</dc:date>
    </item>
    <item>
      <title>Still no support for certs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456233#M238643</link>
      <description>&lt;P&gt;Still no support for certs with key size 4096 for SSL certificates though....&amp;nbsp; just tried ( 9.2.1 ).&lt;/P&gt;&lt;P&gt;It imports to be used for other purposes, but when adding the trustpoint to the interface :&lt;/P&gt;&lt;P&gt;"RSA 4096 keys are not supported for ssl"&lt;/P&gt;&lt;P&gt;Bummer..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2014 09:00:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456233#M238643</guid>
      <dc:creator>Daniel Sandstrom</dc:creator>
      <dc:date>2014-09-02T09:00:31Z</dc:date>
    </item>
    <item>
      <title>Not a bummer. Wholly and</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456234#M238644</link>
      <description>&lt;P&gt;Not a bummer. Wholly and utterly unacceptable.&amp;nbsp;&lt;BR /&gt;"Hey, I know, let's arbitrarily limit the strength of the encryption on our so-called security appliances!"&lt;/P&gt;&lt;P&gt;Presently very displeased. I now either have to re-issue or re-purchase my wildcard cert and then re-re-install it everywhere (no thanks), or purchase an additional weaker cert specifically for my FWs. &amp;nbsp;Thanks Cisco!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2014 19:18:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456234#M238644</guid>
      <dc:creator>blake</dc:creator>
      <dc:date>2014-12-08T19:18:46Z</dc:date>
    </item>
    <item>
      <title>And still no support for this</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456235#M238645</link>
      <description>&lt;P&gt;And still no support for this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Beyond flabbergasted why they wouldn't have this feature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I too have a 4096 RSA wildcard certificate and cannot use it on my ASA's.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are my VPN servers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2014 02:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456235#M238645</guid>
      <dc:creator>AIS-ITADMIN</dc:creator>
      <dc:date>2014-12-18T02:20:16Z</dc:date>
    </item>
    <item>
      <title>Ok, so I have 3 ASAs (2x</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456236#M238646</link>
      <description>&lt;P&gt;Ok, so I have 3 ASAs (2x 5515X and one 5505)&lt;/P&gt;&lt;P&gt;The 5515X are running 9.4.1(3) (ASDM 7.4(3)), the 5505 is running 9.2(3).3 (ASDM 7.4(2))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't see this issue on my 5515X systems, but my 5505 did throw the error about not supporting RSA 4096 for SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2015 15:46:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456236#M238646</guid>
      <dc:creator>dirkmelvin</dc:creator>
      <dc:date>2015-08-06T15:46:04Z</dc:date>
    </item>
    <item>
      <title>I actually found the Cisco</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456237#M238647</link>
      <description>&lt;P&gt;I actually found the Cisco document that details the platforms that support 4096 encryption. In case the link gets broken, this was the statement as of July 25, 2016.&lt;/P&gt;
&lt;P&gt;----------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;H3&gt;CSR Generation&lt;/H3&gt;
&lt;P&gt;This is the first step in the lifecycle of any X.509 digital certificate. Once the private/public Rivest-Shamir-Adleman (RSA) or&amp;nbsp;Elliptic Curve Digital Signature Algorithm (ECDSA) keypair is generated (&lt;A href="http://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/200339-Configure-ASA-SSL-Digital-Certificate-I.html#anc30" target="_self" rel="nofollow noopener noreferrer"&gt;Appendix A&lt;/A&gt; details the difference between the use of&amp;nbsp;RSA or ECDSA), a Certficate Signing Request (CSR) is created. A CSR is basically a PKCS10 formatted message that contains&amp;nbsp;the public key and identity information of the requesting host. &lt;A href="http://www.cisco.com/c/en/us/support/docs/security/vpn-client/116039-pki-data-formats-00.html" target="_blank" rel="nofollow noopener noreferrer"&gt;PKI Data Formats&lt;/A&gt;explains the different certificate formats applicable to the ASA and Cisco IOS&lt;SUP&gt;®&lt;/SUP&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Notes&lt;/STRONG&gt;:&lt;BR /&gt;1. Check with the CA on the required keypair size. The CA/Browser Forum has mandated&amp;nbsp;that all certificates&amp;nbsp;generated by their member CAs have a&amp;nbsp; minimum size of 2048 bits. &lt;BR /&gt;2. ASA currently does not support 4096 bit keys (Cisco bug ID&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCut53512" target="_blank" rel="nofollow noopener noreferrer"&gt;CSCut53512&lt;/A&gt;) for SSL server authentication. However, IKEv2 does support the use of 4096 bit server certificates on the ASA 5580, 5585, and 5500-X platforms alone. &lt;BR /&gt;3. Use the DNS Name of the ASA in the FQDN field of the CSR in order to prevent Untrusted Certificate warnings and pass Strict Certificate check.&lt;/P&gt;
&lt;P&gt;----------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/200339-Configure-ASA-SSL-Digital-Certificate-I.html#anc5"&gt;ASA 4096 RSA key&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I know this is an old thread, but I searched for an hour after I found this post. Would have been nice to have it here.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2016 23:44:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-platform-version-rsa-4096-support/m-p/2456237#M238647</guid>
      <dc:creator>wchilds01</dc:creator>
      <dc:date>2016-08-23T23:44:36Z</dc:date>
    </item>
  </channel>
</rss>

