<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSM 4.4 device credentials in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197225#M920833</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found a workaround + cisco fix is there. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had IPS software updated to 7.2.1. It is not supported by CSM 4.4 (SP1 should be installed) As a workaround I've:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- deleted the device&lt;/P&gt;&lt;P&gt;- added it back . During addition you have "test connectivity". It fails, but it shows you the device certificate. Copy fingerprint from the output.&lt;/P&gt;&lt;P&gt;- go to newly added device, then credentials, insert fingerprint, save.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Working fine but still CSM update is scheduled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Volodymyr Morskyy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Jun 2013 08:59:21 GMT</pubDate>
    <dc:creator>Volodymyr Morskyy</dc:creator>
    <dc:date>2013-06-05T08:59:21Z</dc:date>
    <item>
      <title>CSM 4.4 device credentials</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197223#M920831</link>
      <description>&lt;P&gt;I have just upgraded to CSM 4.4 (from 4.3 sp 1) almost everything works as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However - one of my firewalls has had its ssl certificate expire.&lt;/P&gt;&lt;P&gt;So I go to device properties -&amp;gt; device credentials &lt;/P&gt;&lt;P&gt;Go down to the Authentication Certificate Thumbprint and click retrieve from device.&lt;/P&gt;&lt;P&gt;As expected I get a window with the Certificate details (and the expiry date is now 2023 so it is valid)&lt;/P&gt;&lt;P&gt;Click on accept&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then go to click on save - at this point I get a window with no description text, but a title which states "Error Validating Data" and a Yes or No Option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clicking either yes or no has the same result - it doesn't accept the cert and I can't then use test connectivty to get my firewall back to being managed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very confused here.... any suggestions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Giles Cooper&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197223#M920831</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2020-02-21T12:52:32Z</dc:date>
    </item>
    <item>
      <title>CSM 4.4 device credentials</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197224#M920832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hitting the same issue. Did you found solution for this as I am about to go to cisco. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 06:14:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197224#M920832</guid>
      <dc:creator>Volodymyr Morskyy</dc:creator>
      <dc:date>2013-06-05T06:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: CSM 4.4 device credentials</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197225#M920833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found a workaround + cisco fix is there. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had IPS software updated to 7.2.1. It is not supported by CSM 4.4 (SP1 should be installed) As a workaround I've:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- deleted the device&lt;/P&gt;&lt;P&gt;- added it back . During addition you have "test connectivity". It fails, but it shows you the device certificate. Copy fingerprint from the output.&lt;/P&gt;&lt;P&gt;- go to newly added device, then credentials, insert fingerprint, save.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Working fine but still CSM update is scheduled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Volodymyr Morskyy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 08:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197225#M920833</guid>
      <dc:creator>Volodymyr Morskyy</dc:creator>
      <dc:date>2013-06-05T08:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: CSM 4.4 device credentials</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197226#M920834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sorry I found a workaround but forgot about this question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right click on the device and select Device Properties&lt;/P&gt;&lt;P&gt;Go to credentials&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And click retrieve from device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Copy the thumbprint to the clipboard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cancel the device properites screen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to Security manager administation&lt;/P&gt;&lt;P&gt;Select Device communication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click Add Certificate&lt;/P&gt;&lt;P&gt;Paste in the thumbprint and supply the IP address of the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click Save&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And it should work properly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 10:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197226#M920834</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2013-06-05T10:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: CSM 4.4 device credentials</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197227#M920835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Giles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the same thing I've done but from different menus))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you anyway&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 12:55:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197227#M920835</guid>
      <dc:creator>Volodymyr Morskyy</dc:creator>
      <dc:date>2013-06-05T12:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: CSM 4.4 device credentials</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197228#M920836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0pt; padding: 0pt; color: #333333; font-family: arial,helvetica,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;This is definitely a bug in CSM 4.x and still exists in the latest version 4.4 SP2.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: #333333; font-family: arial,helvetica,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;A href="https://tools.cisco.com/bugsearch/bug/CSCue25304"&gt;https://tools.cisco.com/bugsearch/bug/CSCue25304&lt;/A&gt;&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: #333333; font-family: arial,helvetica,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;A href="https://tools.cisco.com/bugsearch/bug/CSCuf94050"&gt;https://tools.cisco.com/bugsearch/bug/CSCuf94050&lt;/A&gt;&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: #333333; font-family: arial,helvetica,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;SURE there="" are="" more=""&gt;&lt;/SURE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: #333333; font-family: arial,helvetica,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;I ran the script suggested in the workaround (script.pl) and it did provide a resolution on this issue in our installation.&amp;nbsp; Here is the information taken directly from the bug links above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A script is included with CSM 4.4 SP1 to automate these changes for all affected devices:&lt;/P&gt;&lt;P&gt;1.) Ensure that there are no pending changes present in CSM that have not been committed to the database. This can be done via the Configuration Manager (client app)'s File menu &amp;gt; Submit . Then, exit/close any/all open instances of CSM client app's.&lt;/P&gt;&lt;P&gt;2.) On the CSM server itself, right-click on the Command Prompt start menu item and choose the "Run as administrator" option to open a privileged command prompt window, then:&lt;/P&gt;&lt;P&gt;cd \"Program Files (x86)"\CSCOpx\bin&lt;/P&gt;&lt;P&gt;perl.exe script.pl&lt;/P&gt;&lt;P&gt;3.) Once the script completes, restart the 'Cisco Security Manager Daemon Manager' (CRMDmgtd) MS Windows service and allow it a few minutes for it to restart all dependent services&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: #333333; font-family: arial,helvetica,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;In case anyone has an issue after the script, then I have another workaround on this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: #333333; font-family: arial,helvetica,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;What we have done to update the certificates is to select the device under "Devices" and then run the "IPS Certificates Utility"&amp;nbsp; (Manage-&amp;gt;IPS-&amp;gt;IPS Certificates).&amp;nbsp; Select the device and choose "Regenerate Certificate" and it will update the certificate push the date out. The "Sync Certificate" works as well, but it is just a matter of preference on how you want to accomplish the update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: #333333; font-family: arial,helvetica,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;Thanks for the workaround suggestions provided and I hope this information is useful to someone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR class="Apple-interchange-newline" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Nov 2013 06:19:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197228#M920836</guid>
      <dc:creator>kevinknaul</dc:creator>
      <dc:date>2013-11-19T06:19:38Z</dc:date>
    </item>
    <item>
      <title>CSM 4.4 device credentials</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197229#M920837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had this problems too. &lt;/P&gt;&lt;P&gt;We are checked Firewall events and it was blocked ssl(tcp/443) port between CSM and Firewalls. We opened these ports and it was solved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2014 02:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4-device-credentials/m-p/2197229#M920837</guid>
      <dc:creator>Enkhbayar Bold</dc:creator>
      <dc:date>2014-03-06T02:22:08Z</dc:date>
    </item>
  </channel>
</rss>

