<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You need to tell the IPS, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601902#M45286</link>
    <description>&lt;P&gt;You need to tell the IPS, either from cli or via IPS Device Manager (IDM), to trust the cisco.com hosts where your signatures are downloaded from. Once you've set that up, future updates should occur without having to revisit that step.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ips/7-0/configuration/guide/cli/cliguide7/cli_setup.html#wpxref19523"&gt;CLI method&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ips/5-1/configuration/guide/idm/idmguide/dmSetup.html#wp1060343"&gt;IDM method&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Nov 2014 19:04:54 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-11-26T19:04:54Z</dc:date>
    <item>
      <title>What do you mean by "trusted TLS certificates" on the AutoUpdate section of the IPS</title>
      <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601901#M45285</link>
      <description>&lt;P&gt;Hi everybody,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been having issue on updating the signature of our IPS Device. I can download the signature from the URL below&amp;nbsp;at&amp;nbsp;&lt;SPAN style="font-size: 16.3636360168457px;"&gt;72.163.7.60 which tells us that our credentials is working. However, when I tried to update via the "Auto Update" I'm getting an error that "the host is not trusted....." &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 16.3636360168457px;"&gt;Please can you help? Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; section Auto Update Statistics&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; lastDirectoryReadAttempt 05:58:06 GMT-05:00 Tue Nov 25 2014&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Read directory: &lt;A href="https://deleted@72.163.7.60//swc/esd/11/273556262/guest/" target="_blank"&gt;https://deleted@72.163.7.60//swc/esd/11/273556262/guest/&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Success&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; lastDownloadAttempt 05:58:07 GMT-05:00 Tue Nov 25 2014&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Download: &lt;A href="https://deleted@72.163.7.60//swc/esd/11/273556262/guest/IPS-sig-S837-req-E4.pkg" target="_blank"&gt;https://deleted@72.163.7.60//swc/esd/11/273556262/guest/IPS-sig-S837-req-E4.pkg&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN style="color:#FF0000;"&gt;&lt;STRONG&gt;Error: autoUpdate successfully selected a package (https://deleted@72.163.7.60//swc/esd/11/273556262/guest/IPS-sig-S837-req-E4.pkg) from the cisco.com locator service, however, package download failed: The host is not trusted. Add the host to the system's trusted TLS certificates.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; lastInstallAttempt N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; nextAttempt 05:58:00 GMT-05:00 Wed Nov 26 2014&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601901#M45285</guid>
      <dc:creator>NED PH</dc:creator>
      <dc:date>2019-03-10T13:17:15Z</dc:date>
    </item>
    <item>
      <title>You need to tell the IPS,</title>
      <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601902#M45286</link>
      <description>&lt;P&gt;You need to tell the IPS, either from cli or via IPS Device Manager (IDM), to trust the cisco.com hosts where your signatures are downloaded from. Once you've set that up, future updates should occur without having to revisit that step.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ips/7-0/configuration/guide/cli/cliguide7/cli_setup.html#wpxref19523"&gt;CLI method&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ips/5-1/configuration/guide/idm/idmguide/dmSetup.html#wp1060343"&gt;IDM method&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Nov 2014 19:04:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601902#M45286</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-11-26T19:04:54Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin, I already did</title>
      <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601903#M45287</link>
      <description>&lt;P&gt;Thanks Marvin, I already did that and even created a new TLS key. However, I'm still getting the same error. I wonder if its some kind of a bug on version 7.1(7)E4. I already reloaded the module (IP-SSM-20) but still the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sensor-1# show tls trusted-hosts&amp;nbsp;&lt;BR /&gt;72.163.4.161&lt;BR /&gt;72.163.7.60&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 09:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601903#M45287</guid>
      <dc:creator>NED PH</dc:creator>
      <dc:date>2014-11-27T09:58:35Z</dc:date>
    </item>
    <item>
      <title>You might try re-importing</title>
      <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601904#M45288</link>
      <description>&lt;P&gt;You might try re-importing the certificate for that host. Even though the host address is correctly in your configuration, if Cisco updates their certificate (or if you have a transparent proxy between you and them that does the same) it can cause that error.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 13:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601904#M45288</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-11-27T13:08:50Z</dc:date>
    </item>
    <item>
      <title>I see, but I'm not pretty</title>
      <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601905#M45289</link>
      <description>&lt;P&gt;I see, but I'm not pretty sure how to re-import the certificate from that public IP. Though&amp;nbsp;I tried deleting the TLS for that IP and re-create it. I know we have webroot for the workstations but I dont think it acts like a transparent proxy for the IPS but I might be wrong.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 13:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601905#M45289</guid>
      <dc:creator>NED PH</dc:creator>
      <dc:date>2014-11-27T13:52:57Z</dc:date>
    </item>
    <item>
      <title>If you delete and re-add the</title>
      <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601906#M45290</link>
      <description>&lt;P&gt;If you delete and re-add the host, the associated certificate should be renewed. In the IDM link above you will see how to view the trusted host certificate. I would check that against what you see if you simply browse to the download host using https. contrast those two values to one another to see if you are getting the certificate from an intermediate proxy server. You could also check from a public PC (say connecting via a hotspot or from home) to get another point of comparison.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 17:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601906#M45290</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-11-27T17:50:47Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin, I would like to</title>
      <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601907#M45291</link>
      <description>&lt;P&gt;Hi Marvin, I would like to thank you for the support. This is now resolved when I upgraded the IPS to version 7.1(9)E4, it looks like this is a bug on 7.1(7)E4.&amp;nbsp;&lt;/P&gt;&lt;P&gt;https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCui05041&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Fred&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2014 11:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601907#M45291</guid>
      <dc:creator>NED PH</dc:creator>
      <dc:date>2014-11-28T11:24:16Z</dc:date>
    </item>
    <item>
      <title>Interesting. That BugID</title>
      <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601908#M45292</link>
      <description>&lt;P&gt;Interesting. That BugID indicates a proxy problem and does not say your version is affected.&lt;/P&gt;&lt;P&gt;In any case, I'm glad it's resolved for you. Best regards.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2014 14:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601908#M45292</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-11-28T14:20:22Z</dc:date>
    </item>
    <item>
      <title>Fred, I had the same exact</title>
      <link>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601909#M45293</link>
      <description>&lt;P&gt;Fred,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had the same exact problem with our IPS. I did all the steps you did and it did not fix the problem. I opened a support case and the fix was to update the IPS software.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I updated to 7.1(9)E4 and this fixed the problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think Cisco needs to alert it's customer base of this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2014 21:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-do-you-mean-by-quot-trusted-tls-certificates-quot-on-the/m-p/2601909#M45293</guid>
      <dc:creator>mhanson2004</dc:creator>
      <dc:date>2014-12-01T21:26:16Z</dc:date>
    </item>
  </channel>
</rss>

