<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: https on pix and asa - cert expired in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/https-on-pix-and-asa-cert-expired/m-p/1531678#M603527</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7.0.5 is ancient &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the exact check that is done is if certificate exists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;care to share your "show run crypto ca trust" "show cry ca cert" outputs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Sep 2010 16:26:00 GMT</pubDate>
    <dc:creator>Marcin Latosiewicz</dc:creator>
    <dc:date>2010-09-14T16:26:00Z</dc:date>
    <item>
      <title>https on pix and asa - cert expired</title>
      <link>https://community.cisco.com/t5/network-security/https-on-pix-and-asa-cert-expired/m-p/1531677#M603524</link>
      <description>&lt;P&gt;The https certificate of one of our pix firewalls has expired, so I wondered how to refresh it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried everything from generating new key pairs to zeroizing every key I could grab and generate new ones, disabling and enabling the http server in between, so in theory it should start with a new cert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however, deleting installed certs and clearing the cache of the browser didn´t help much, all the client sees is the expired cert, which I suspect to be the cert the pix is still delivering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can someone share some light on how the https demon is actually related to the key pairs and what you need to do in order to refresh an expired cert on a pix 7.05 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tia,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;oliver&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-on-pix-and-asa-cert-expired/m-p/1531677#M603524</guid>
      <dc:creator>keller.oliver</dc:creator>
      <dc:date>2019-03-11T18:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: https on pix and asa - cert expired</title>
      <link>https://community.cisco.com/t5/network-security/https-on-pix-and-asa-cert-expired/m-p/1531678#M603527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7.0.5 is ancient &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the exact check that is done is if certificate exists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;care to share your "show run crypto ca trust" "show cry ca cert" outputs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 16:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-on-pix-and-asa-cert-expired/m-p/1531678#M603527</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-09-14T16:26:00Z</dc:date>
    </item>
  </channel>
</rss>

