<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic certificate update in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299511#M343063</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You saw on the post that the certificate was removed after the change so you will need to set it once back with the right RSA key, Afterwards you should be up and running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just check the lab recreation I did above....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Oct 2013 04:39:30 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-10-09T04:39:30Z</dc:date>
    <item>
      <title>certificate update</title>
      <link>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299507#M343055</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a cisco 5500 ASA running on 1024 bit certificate. Now i need to update to 2048. how do i go about doing this ? do i remove the exisiting certificate and then add the new one or can i simply update with the exisiting one ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if anyone has a link with step by step instructions please post&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299507#M343055</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2019-03-12T02:37:50Z</dc:date>
    </item>
    <item>
      <title>certificate update</title>
      <link>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299508#M343058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh crypto ca certificates&lt;/P&gt;&lt;P&gt;Certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp; Status: Available&lt;/P&gt;&lt;P&gt;&amp;nbsp; Certificate Serial Number: 87f73152&lt;/P&gt;&lt;P&gt;&amp;nbsp; Certificate Usage: General Purpose&lt;/P&gt;&lt;P&gt;&amp;nbsp; Public Key Type: RSA (1024 bits)&lt;/P&gt;&lt;P&gt;&amp;nbsp; Signature Algorithm: SHA1 with RSA Encryption&lt;/P&gt;&lt;P&gt;&amp;nbsp; Issuer Name:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serialNumber=123456789AB+hostname=ciscoasa&lt;/P&gt;&lt;P&gt;&amp;nbsp; Subject Name:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serialNumber=123456789AB+hostname=ciscoasa&lt;/P&gt;&lt;P&gt;&amp;nbsp; Validity Date:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; start date: 17:19:34 UTC Sep 12 2013&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; end&amp;nbsp;&amp;nbsp; date: 17:19:34 UTC Sep 10 2023&lt;/P&gt;&lt;P&gt;&amp;nbsp; Associated Trustpoints: test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I will create a new crypto-key&lt;/P&gt;&lt;P&gt;ciscoasa(config)# crypto key generate rsa label Jcarvaja modulus 2048&lt;/P&gt;&lt;P&gt;INFO: The name for the keys will be: Jcarvaja&lt;/P&gt;&lt;P&gt;Keypair generation process begin. Please wait...&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh crypto key mypubkey rsa&lt;/P&gt;&lt;P&gt;Key pair was generated at: 17:18:56 UTC Sep 12 2013&lt;/P&gt;&lt;P&gt;Key name: &lt;DEFAULT-RSA-KEY&gt;&lt;/DEFAULT-RSA-KEY&gt;&lt;/P&gt;&lt;P&gt; Usage: General Purpose Key&lt;/P&gt;&lt;P&gt; Modulus Size (bits): 1024&lt;/P&gt;&lt;P&gt; Key Data:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 30819f30 0d06092a 864886f7 0d010101 05000381 8d003081 89028181 00a534df&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1b982cf7 eeca1dd7 7c6e60d8 da8a68df b5df8e07 a18c29c2 2ec277af 0a0363e8&lt;/P&gt;&lt;P&gt;&amp;nbsp; 35261ceb 6998cbdf c50950bd baaa22ff 5a695555 34095a5d 5a3c6fa4 ec6e6b9b&lt;/P&gt;&lt;P&gt;&amp;nbsp; 0984f847 4fab0b08 dc4f7bb7 2049a590 9651a50a 32f1c952 684e234d e60c6e4c&lt;/P&gt;&lt;P&gt;&amp;nbsp; e8b8fad6 e4a0aa21 787b37ad 40e6470d 742c80bc 9b317d4c 1c514a42 d7020301 0001&lt;/P&gt;&lt;P&gt;Key pair was generated at: 17:21:14 UTC Sep 12 2013&lt;/P&gt;&lt;P&gt;Key name: Jcarvaja&lt;/P&gt;&lt;P&gt; Usage: General Purpose Key&lt;/P&gt;&lt;P&gt; Modulus Size (bits): 2048&lt;/P&gt;&lt;P&gt; Key Data:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 30820122 300d0609 2a864886 f70d0101 01050003 82010f00 3082010a 02820101&lt;/P&gt;&lt;P&gt;&amp;nbsp; 00f7abfc 0220f7f2 388f6ed8 77566e3d 88a0c62e da191353 194e6ef1 d01adfe5&lt;/P&gt;&lt;P&gt;&amp;nbsp; d3450563 92ff0182 34589c8e 2e3f4354 a8ecfd46 a7ae5a81 e3da135e 5877a8ff&lt;/P&gt;&lt;P&gt;&amp;nbsp; 36f67049 ce888256 9a69a3d5 2b26b00e 02bf48e5 2b7e1342 f1aa5e5b 30e148f2&lt;/P&gt;&lt;P&gt;&amp;nbsp; c9543619 53c9c1da 476cf61c 5783a4ff e961fcaa 6c1c2b97 85a7b6fc 7ceee876&lt;/P&gt;&lt;P&gt;&amp;nbsp; bc733a7f 26581e5a f6936bc7 62c69ba0 f91261d4 a6da281b f29da920 3417cd28&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4d229274 ff4ebaa2 729248eb 67060228 622506ef 72ec7486 414db626 5f6f1b5b&lt;/P&gt;&lt;P&gt;&amp;nbsp; 0645fdfa c05e5b60 79f7bcfb f645d069 475846c6 3a2c1b4c 63c0559e 8165792d&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8da4ff8f cd1c4c06 9569f448 538a6ce4 73bf6273 23ccbe3d f0b273ca 4a7bd293&lt;/P&gt;&lt;P&gt;&amp;nbsp; c7020301 0001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, let's set it into the certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# crypto ca trustpoint test&lt;/P&gt;&lt;P&gt;ciscoasa(config-ca-trustpoint)# keypair Jcarvaja&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Afterwards the certificate will not be shown as we changed it, we need to enroll once.&lt;/P&gt;&lt;P&gt;ciscoasa# sh crypto ca certificates&lt;/P&gt;&lt;P&gt;ciscoasa# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# crypto ca enroll test noconfirm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;% The fully-qualified domain name in the certificate will be: ciscoasa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh crypto ca certificates&lt;/P&gt;&lt;P&gt;Certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp; Status: Available&lt;/P&gt;&lt;P&gt;&amp;nbsp; Certificate Serial Number: 88f73152&lt;/P&gt;&lt;P&gt;&amp;nbsp; Certificate Usage: General Purpose&lt;/P&gt;&lt;P&gt;&amp;nbsp; Public Key Type: RSA (2048 bits)&lt;/P&gt;&lt;P&gt;&amp;nbsp; Signature Algorithm: SHA1 with RSA Encryption&lt;/P&gt;&lt;P&gt;&amp;nbsp; Issuer Name:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serialNumber=123456789AB+hostname=ciscoasa&lt;/P&gt;&lt;P&gt;&amp;nbsp; Subject Name:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serialNumber=123456789AB+hostname=ciscoasa&lt;/P&gt;&lt;P&gt;&amp;nbsp; Validity Date:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; start date: 17:24:12 UTC Sep 12 2013&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; end&amp;nbsp;&amp;nbsp; date: 17:24:12 UTC Sep 10 2023&lt;/P&gt;&lt;P&gt;&amp;nbsp; Associated Trustpoints: test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2013 16:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299508#M343058</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-09-12T16:22:54Z</dc:date>
    </item>
    <item>
      <title>certificate update</title>
      <link>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299509#M343060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is this simple, does it require any downtime ? so will this process replace the existing certificate ? and what is the rollback ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Sep 2013 08:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299509#M343060</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2013-09-16T08:29:30Z</dc:date>
    </item>
    <item>
      <title>certificate update</title>
      <link>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299510#M343062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same questions that Network Pro had and I guess I would also like the answer to his questions. I assume that someone has these answers since this was last posted in March of 2011.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 20:15:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299510#M343062</guid>
      <dc:creator>robinsra82</dc:creator>
      <dc:date>2013-10-08T20:15:44Z</dc:date>
    </item>
    <item>
      <title>certificate update</title>
      <link>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299511#M343063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You saw on the post that the certificate was removed after the change so you will need to set it once back with the right RSA key, Afterwards you should be up and running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just check the lab recreation I did above....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 04:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-update/m-p/2299511#M343063</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-09T04:39:30Z</dc:date>
    </item>
  </channel>
</rss>

