<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower 2100-series FXOS certificate regeneration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3396394#M921892</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm getting an error about expired certificate from FXOS:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;#show fault&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Major F0853 2018-06-02T13:06:08.798 126445 default Keyring's certificate is invalid, reason: expired.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If checking further:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;#scope security&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;#show keyring default&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Signature Algorithm: sha256WithRSAEncryption&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Issuer: C=US, ST=California, L=San Jose, O=Cisco Systems, Inc., OU=Test, CN=localhost&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Validity&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Not Before: Jun 2 12:59:10 2017 GMT&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Not After : Jun 2 12:59:10 2018 GMT&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Subject: C=US, ST=California, L=San Jose, O=Cisco Systems, Inc., OU=Test, CN=localhost&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, yep, it is expired.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Classic FXOS way to extend the validity (&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos221/cli-guide/b_CLI_ConfigGuide_FXOS_221/platform_settings.html#concept_emd_w3t_cy" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos221/cli-guide/b_CLI_ConfigGuide_FXOS_221/platform_settings.html#concept_emd_w3t_cy&lt;/A&gt;) does not help:&lt;/P&gt;
&lt;PRE class="pre codeblock"&gt;&lt;CODE&gt;Firepower-chassis# &lt;KBD class="userinput"&gt;&lt;STRONG class="ph userinput"&gt;scope security&lt;/STRONG&gt;&lt;/KBD&gt;
Firepower-chassis /security # &lt;KBD class="userinput"&gt;&lt;STRONG class="ph userinput"&gt;scope keyring default&lt;/STRONG&gt;&lt;/KBD&gt;
Firepower-chassis /security/keyring* # &lt;KBD class="userinput"&gt;&lt;STRONG class="ph userinput"&gt;set regenerate yes&lt;/STRONG&gt;&lt;/KBD&gt;
Firepower-chassis /security/keyring* # &lt;KBD class="userinput"&gt;&lt;STRONG class="ph userinput"&gt;commit-buffer&lt;/STRONG&gt;&lt;/KBD&gt;
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is rejected on FP2100 series due to:&lt;BR /&gt;&lt;EM&gt;FTD* # commit-buffer&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Error: Changes not allowed. use: 'connect ftd' to make changes.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Version FMC/FTD 6.2.3.1 &amp;amp; FXOS 2.3(1.84) - but is all bundled, so I don't have any options anyway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the moment cannot seem to find procedure for 2100-series where everything is bundled together and separate changes to FXOS are not done. How to regenerate certificate for this platform?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:51:39 GMT</pubDate>
    <dc:creator>niko</dc:creator>
    <dc:date>2020-02-21T15:51:39Z</dc:date>
    <item>
      <title>Firepower 2100-series FXOS certificate regeneration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3396394#M921892</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm getting an error about expired certificate from FXOS:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;#show fault&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Major F0853 2018-06-02T13:06:08.798 126445 default Keyring's certificate is invalid, reason: expired.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If checking further:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;#scope security&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;#show keyring default&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Signature Algorithm: sha256WithRSAEncryption&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Issuer: C=US, ST=California, L=San Jose, O=Cisco Systems, Inc., OU=Test, CN=localhost&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Validity&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Not Before: Jun 2 12:59:10 2017 GMT&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Not After : Jun 2 12:59:10 2018 GMT&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Subject: C=US, ST=California, L=San Jose, O=Cisco Systems, Inc., OU=Test, CN=localhost&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, yep, it is expired.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Classic FXOS way to extend the validity (&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos221/cli-guide/b_CLI_ConfigGuide_FXOS_221/platform_settings.html#concept_emd_w3t_cy" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos221/cli-guide/b_CLI_ConfigGuide_FXOS_221/platform_settings.html#concept_emd_w3t_cy&lt;/A&gt;) does not help:&lt;/P&gt;
&lt;PRE class="pre codeblock"&gt;&lt;CODE&gt;Firepower-chassis# &lt;KBD class="userinput"&gt;&lt;STRONG class="ph userinput"&gt;scope security&lt;/STRONG&gt;&lt;/KBD&gt;
Firepower-chassis /security # &lt;KBD class="userinput"&gt;&lt;STRONG class="ph userinput"&gt;scope keyring default&lt;/STRONG&gt;&lt;/KBD&gt;
Firepower-chassis /security/keyring* # &lt;KBD class="userinput"&gt;&lt;STRONG class="ph userinput"&gt;set regenerate yes&lt;/STRONG&gt;&lt;/KBD&gt;
Firepower-chassis /security/keyring* # &lt;KBD class="userinput"&gt;&lt;STRONG class="ph userinput"&gt;commit-buffer&lt;/STRONG&gt;&lt;/KBD&gt;
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is rejected on FP2100 series due to:&lt;BR /&gt;&lt;EM&gt;FTD* # commit-buffer&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Error: Changes not allowed. use: 'connect ftd' to make changes.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Version FMC/FTD 6.2.3.1 &amp;amp; FXOS 2.3(1.84) - but is all bundled, so I don't have any options anyway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the moment cannot seem to find procedure for 2100-series where everything is bundled together and separate changes to FXOS are not done. How to regenerate certificate for this platform?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:51:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3396394#M921892</guid>
      <dc:creator>niko</dc:creator>
      <dc:date>2020-02-21T15:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2100-series FXOS certificate regeneration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3409723#M921893</link>
      <description>&lt;P&gt;Hi - we have the same issue with no fix at moment on 6.2.3.2 - has been escalated within Cisco.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 14:32:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3409723#M921893</guid>
      <dc:creator>Warbs</dc:creator>
      <dc:date>2018-07-03T14:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2100-series FXOS certificate regeneration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3411113#M921894</link>
      <description>&lt;P&gt;I have the same error. I tried to regenerate the certficate but the error is the same.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 20:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3411113#M921894</guid>
      <dc:creator>paulo viteri</dc:creator>
      <dc:date>2018-07-05T20:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2100-series FXOS certificate regeneration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3914509#M921895</link>
      <description>&lt;P&gt;see bug note&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvk26612/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvk26612/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 09:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3914509#M921895</guid>
      <dc:creator>alfred.thyri</dc:creator>
      <dc:date>2019-08-27T09:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2100-series FXOS certificate regeneration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3999282#M921896</link>
      <description>Just executed your commands on my Firepower 2110 running latest ASA 9.12.3 code and it worked:&lt;BR /&gt;&lt;BR /&gt;firepower-2110# scope security &lt;BR /&gt;firepower-2110 /security # scope keyring default&lt;BR /&gt;firepower-2110 /security/keyring # set regenerate yes&lt;BR /&gt;firepower-2110 /security/keyring* # commit-buffer &lt;BR /&gt;firepower-2110 /security/keyring # top&lt;BR /&gt;&lt;BR /&gt;firepower-2110# show fault &lt;BR /&gt;Severity  Code     Last Transition Time     ID       Description&lt;BR /&gt;--------- -------- ------------------------ -------- -----------&lt;BR /&gt;Cleared   F0853    2019-12-16T09:59:13.246    583116 default Keyring's certificate is invalid, reason: expired.&lt;BR /&gt;firepower-2110# show vers&lt;BR /&gt;Boot Loader version: 1.0.09&lt;BR /&gt;System version: 2.6(1.156)&lt;BR /&gt;Service Manager version: 2.6(1.156)&lt;BR /&gt;fpga version: 2.0.00&lt;BR /&gt;fpga golden version: 2.0.00&lt;BR /&gt;power sequencer version: 2.13&lt;BR /&gt;lanspi version: unknown</description>
      <pubDate>Mon, 16 Dec 2019 09:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/3999282#M921896</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-12-16T09:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2100-series FXOS certificate regeneration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/5018461#M1109167</link>
      <description>&lt;P&gt;for newer versions, see&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe60267" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe60267&lt;/A&gt;&amp;nbsp; .&lt;/P&gt;
&lt;P&gt;you have to do all three steps.&amp;nbsp; "&lt;SPAN&gt;sysopt sam 1001 on" override is done in FXOS mode.&amp;nbsp; Commit will give an error unless you first exit a couple times to the top menu (still in fxos)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 20:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2100-series-fxos-certificate-regeneration/m-p/5018461#M1109167</guid>
      <dc:creator>hoylea</dc:creator>
      <dc:date>2024-02-14T20:27:05Z</dc:date>
    </item>
  </channel>
</rss>

