cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2087
Views
0
Helpful
5
Replies

How to install SSL certificate on the second ACE in the HA pair

grichardson661
Level 1
Level 1

Hi,

I'm struggling to figure out how to install a certificate (.p7b and .crf) on my second ACE in a HA pair.

On ACE01 i generated a CSR and gave the details to our SSL provider, they provided the certificates and i imported them. All good there.

How can i install the same SSL on ACE02 if i haven't generated a CSR on my backup devicde, or do i generate a CSR and import the same certificate?

Since bringing the ACE's into HA all contexts have sync'd and the backup ACE is in 'hot standby' state. But one context fails the sync and i think this is because the SSL certificate is not installed correctly on the second ACE02.

Anybody got any ideas, suggestions?

Cheers

1 Accepted Solution

Accepted Solutions

Yes try using the same cert on ACE02 with the key you just exported. Verify using "crypto verify .." to see if they match.

-

Siva

View solution in original post

5 Replies 5

sivaksiv
Cisco Employee
Cisco Employee

Hi,

If you already have the cert and key on the Active ACE, then you just need to export them using "crypto export ..." command from Active ACE and then import to the standby ACE using "crypto import ..."

Regards,

Siva

Sweet as easy as that. I'll give it ago, cheers!

grichardson661
Level 1
Level 1

I've managed to export the key but the CERT is none exportable. Can i use the crt file on ACE02?

Cheers

Yes try using the same cert on ACE02 with the key you just exported. Verify using "crypto verify .." to see if they match.

-

Siva

Thanks Sivaksiv, very helpful! Will give it ago and feedback.

Review Cisco Networking for a $25 gift card