<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I had this at one of my in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916659#M43996</link>
    <description>&lt;P&gt;I had this at one of my customers. I dug into it and found the following:&lt;/P&gt;
&lt;P&gt;Cisco updated their SSL certificates earlier this year to use SHA2 signed certificates. They are signed by a different Root CA (Verizon if I recall correctly) and the IPS system image needs to be updated to the latest version (7.3(5)) in order to trust the certificates from that root CA.&lt;/P&gt;
&lt;P&gt;This is mentioned in the IPS 7.3(5) release notes:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ips/7-3/release/notes/release7-3-5.html#pgfId-1381236&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="pBu1_Bullet1"&gt;
&lt;BLOCKQUOTE&gt;You need IPS 7.3(5) to use auto update, global correlation, and network participation after migration of the SHA-2 Certificates on the Cisco web sites.&lt;/BLOCKQUOTE&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Wed, 27 Apr 2016 19:10:14 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2016-04-27T19:10:14Z</dc:date>
    <item>
      <title>ASA-SSM-20 Error: AutoUpdate exception: HTTP connection failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916658#M43995</link>
      <description>&lt;P&gt;Autoupdate has been working for years, but now is not.&lt;/P&gt;
&lt;P&gt;I have verified that the sensor is establishing a connection with the peer at&amp;nbsp;&lt;A href="https://72.163.4.161//cgi-bin/front.x/ida/locator/locator.pl" target="_blank"&gt;https://72.163.4.161//cgi-bin/front.x/ida/locator/locator.pl&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;CCO creds have not changed.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What is going here? &amp;nbsp;I have two sensors behaving this way, btw.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916658#M43995</guid>
      <dc:creator>N3t W0rK3r</dc:creator>
      <dc:date>2019-03-10T13:36:20Z</dc:date>
    </item>
    <item>
      <title>I had this at one of my</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916659#M43996</link>
      <description>&lt;P&gt;I had this at one of my customers. I dug into it and found the following:&lt;/P&gt;
&lt;P&gt;Cisco updated their SSL certificates earlier this year to use SHA2 signed certificates. They are signed by a different Root CA (Verizon if I recall correctly) and the IPS system image needs to be updated to the latest version (7.3(5)) in order to trust the certificates from that root CA.&lt;/P&gt;
&lt;P&gt;This is mentioned in the IPS 7.3(5) release notes:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ips/7-3/release/notes/release7-3-5.html#pgfId-1381236&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="pBu1_Bullet1"&gt;
&lt;BLOCKQUOTE&gt;You need IPS 7.3(5) to use auto update, global correlation, and network participation after migration of the SHA-2 Certificates on the Cisco web sites.&lt;/BLOCKQUOTE&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 27 Apr 2016 19:10:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916659#M43996</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-04-27T19:10:14Z</dc:date>
    </item>
    <item>
      <title>Hello John,</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916660#M43997</link>
      <description>&lt;P&gt;Hello John,&lt;/P&gt;
&lt;P&gt;Could you please specify what all auto updates you are referring to ? Is it includes the product updates and SRU updates also ?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 08:38:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916660#M43997</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-04-28T08:38:27Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin... I will take</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916661#M43998</link>
      <description>&lt;P&gt;Thanks Marvin... I will take a look at this and see if it applies to my platform.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Cheers.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 15:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916661#M43998</guid>
      <dc:creator>N3t W0rK3r</dc:creator>
      <dc:date>2016-04-28T15:10:34Z</dc:date>
    </item>
    <item>
      <title>Hello Jetsy,</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916662#M43999</link>
      <description>&lt;P&gt;Hello Jetsy,&lt;/P&gt;
&lt;P&gt;The updates I'm referring to are signature updates accessed via the URL referenced in the first message.&lt;/P&gt;
&lt;P&gt;My platforms are ASA-SSM-20 and ASA-SSM-40. &amp;nbsp;Running version&amp;nbsp;7.1(7)E4 on both IPS modules.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 15:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-20-error-autoupdate-exception-http-connection-failed/m-p/2916662#M43999</guid>
      <dc:creator>N3t W0rK3r</dc:creator>
      <dc:date>2016-04-28T15:21:10Z</dc:date>
    </item>
  </channel>
</rss>

