<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wrong domain for self signed ID Cert. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470486#M651946</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Trent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try removing then reapplying the keypair "CA" in the trustpoint configuration then try enrolling it again?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Loren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Aug 2010 02:34:23 GMT</pubDate>
    <dc:creator>Loren Kolnes</dc:creator>
    <dc:date>2010-08-25T02:34:23Z</dc:date>
    <item>
      <title>Wrong domain for self signed ID Cert.</title>
      <link>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470483#M651943</link>
      <description>&lt;P&gt;I am tryin to generate a self signed certificate for Indentity Certificates, and keep coming up with the wrong domain name. The "Issued To" and "Issued by" both refer to the incorrect domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the config, the correct domain name can be found in:&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;domain-name &lt;/STRONG&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;STRONG&gt;dns server-group DefaultDNS&lt;BR /&gt;group-policy DefaultRAGroup attributes&lt;BR /&gt;group-policy DefaultRAGroup_1 attributes&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;However, the incorrect domain name can not be found anywhere in the config. I have removed any and all &lt;BR /&gt;certificates already issued. I see no configuration what so ever refering to any certificates, CA, Local-CA, &lt;BR /&gt;trustpoints, etc..&lt;BR /&gt;&lt;BR /&gt;But when I go back again to create a new self signed Identity cert, I still get the OLD domain. If I go to advanced&lt;BR /&gt;options I can fill out the FQDN and IP. The FQDN will be ASA5510.CorrectDomain.com. But of course what will be issued&lt;BR /&gt;is ASA5510.NOTTHECORRECTONE.com&lt;BR /&gt;&lt;BR /&gt;The domain name that is showing up is one that was first used when the device arrived and I created an initial&lt;BR /&gt;configuration just to get the device on a network to access. Since that time the original config has long since&lt;BR /&gt;been erased with a brand new config added line by line. Yet still this ghost from the original keeps showing up.&lt;BR /&gt;Where is it finding this?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470483#M651943</guid>
      <dc:creator>TRENT WAITE</dc:creator>
      <dc:date>2019-03-11T18:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong domain for self signed ID Cert.</title>
      <link>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470484#M651944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Trent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell me what version the ASA is running.&lt;/P&gt;&lt;P&gt;Can you also capture the following information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run all | inc [olddomainname]&lt;/P&gt;&lt;P&gt;sh run all cry ca trustpoint&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Loren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 00:35:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470484#M651944</guid>
      <dc:creator>Loren Kolnes</dc:creator>
      <dc:date>2010-08-25T00:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong domain for self signed ID Cert.</title>
      <link>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470485#M651945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA Version 8.2(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I run "&lt;STRONG&gt;show run all | inc icontrol.com&lt;/STRONG&gt;" I get no output. If I run "&lt;STRONG&gt;show run all&lt;/STRONG&gt;" and then copy over to Wordpad and run a search I get nothing in reference to old domain, but do get references for the new domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the attached txt file is the results of the "&lt;STRONG&gt;show run all&lt;/STRONG&gt;". The old domain name is "icontrol.com". I replaced in the text file the new domain name with "icshxxx.com", however that is the only thing that was replaced. There is no reference what so ever to icontrol.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yet after running this command, seeing no reference what so ever, I decided to say what the heck and tried it again. Sure enough the self created Identity Cert created had the domain name "&lt;STRONG&gt;icontrol.com&lt;/STRONG&gt;", and not "icshxxx.com". However, if you look at the ADSM it clearly shows that the Issue to and Issue by as "&lt;STRONG&gt;ASA5510.icontrol.com&lt;/STRONG&gt;". But running the "&lt;STRONG&gt;sh run all cry ca trustpoin&lt;/STRONG&gt;t" shows nothing for Trustpoint0 in regards to the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# show run all | inc icontrol.com&lt;BR /&gt;ASA5510# sh run all cry ca trustpoint&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt; revocation-check none&lt;BR /&gt; enrollment retry period 1&lt;BR /&gt; enrollment retry count 0&lt;BR /&gt; enrollment self&lt;BR /&gt; &lt;STRONG&gt;no fqdn&lt;BR /&gt; no email&lt;/STRONG&gt;&lt;BR /&gt; subject-name CN=ASA5510&lt;BR /&gt; no serial-number&lt;BR /&gt; &lt;STRONG&gt;no ip-address&lt;/STRONG&gt;&lt;BR /&gt; no password&lt;BR /&gt; keypair CA&lt;BR /&gt; client-types ipsec ssl&lt;BR /&gt; accept-subordinates&lt;BR /&gt; id-cert-issuer&lt;BR /&gt; id-usage ssl-ipsec&lt;BR /&gt; no ignore-ipsec-keyusage&lt;BR /&gt; no ignore-ssl-keyusage&lt;BR /&gt; proxy-ldc-issuer&lt;BR /&gt; crl configure&lt;BR /&gt;&amp;nbsp; policy cdp&lt;BR /&gt;&amp;nbsp; cache-time 60&lt;BR /&gt;&amp;nbsp; enforcenextupdate&lt;BR /&gt;&amp;nbsp; protocol http&lt;BR /&gt;&amp;nbsp; protocol ldap&lt;BR /&gt;&amp;nbsp; protocol scep&lt;BR /&gt;ASA5510#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did clear the ASDM cache, and restarted ASDM. It still shows "&lt;STRONG&gt;ASA5510.icontrol.com&lt;/STRONG&gt;" and not "&lt;STRONG&gt;ASA5510.icshrff.com&lt;/STRONG&gt;". Also, if I go to the Advanced tab and enter in the FQDN, e-mail address, and IP address, it will not be applied.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 01:14:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470485#M651945</guid>
      <dc:creator>TRENT WAITE</dc:creator>
      <dc:date>2010-08-25T01:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong domain for self signed ID Cert.</title>
      <link>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470486#M651946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Trent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try removing then reapplying the keypair "CA" in the trustpoint configuration then try enrolling it again?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Loren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 02:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470486#M651946</guid>
      <dc:creator>Loren Kolnes</dc:creator>
      <dc:date>2010-08-25T02:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong domain for self signed ID Cert.</title>
      <link>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470487#M651947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help Loren. I have the problem solved now, the solution was to reload the OS. I shut down the ASA last night, and had the CA's removed. Loaded up the ASA today, looked at the config and there was nothing relating to certs between isakmp crypto to SSH. I then used the ASDM to add a new Identity cert and it shows up with the correct domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a 5505 that had the same problem, and I did the same steps I used with this 5510. The 5505's issue was resolved when removing the CA's, certs,&amp;nbsp; and Trustpoints, but I never had to reload or restart that unit. So it did not occur to me that doing this would solve the 5510's issue. Well one less issue to worrry about &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 18:17:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470487#M651947</guid>
      <dc:creator>TRENT WAITE</dc:creator>
      <dc:date>2010-08-25T18:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong domain for self signed ID Cert.</title>
      <link>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470488#M651948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Trent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to hear you got this working.&lt;/P&gt;&lt;P&gt;Just FYI in my recreate removing and reapplying the keypair resolved this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Loren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 23:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wrong-domain-for-self-signed-id-cert/m-p/1470488#M651948</guid>
      <dc:creator>Loren Kolnes</dc:creator>
      <dc:date>2010-08-25T23:50:45Z</dc:date>
    </item>
  </channel>
</rss>

