05-24-2020 06:43 PM
I'm on 6.6.0 and I am getting this bug.
04-23-2021 12:59 PM
How is this fixed. If I am having this issue running 6.6.1
09-17-2023 10:41 PM
I was trying to update my FTD from 7.0.4 to 7.2.5 and the upgrade was always failing with a Java error at about 38% and then reverting back.
Eventually I discovered that the webserver certificate was expired. Trying to replace the certificate with a CA signed certificate is failing with "SSP server unavailable" error.
Here is what I have done to fix this. These steps worked for me in both in 7.0.4 and 7.2.4. You can't replace the webserver certificate with a CA signed certificate but you can replace it with a self signed certificate on the firepower itself.
1. ssh to your firepower (with FDM)
2. go to expert mode
3. sudo su
4. cd /etc/ssl
5. Generate - CSR request
openssl req -new -newkey rsa:2048 -nodes -keyout private.key -out firepower.csr
6. Sign the "self signed" certificate
openssl x509 -req -days 825 -in firepower.csr -signkey private.key -out server.pem
7. Replace the certificate and private key in DefaultWebserverCertificate (firepower/Objects/Certificate in FDM) with the private.key and server.pem generated above. Run these on your firepower and copy the output: cat /etc/ssl/private.key respectively, cat /etc/ssl/server.pem
8. restart the device. After this the upgrade will work.
06-10-2024 10:54 AM
This worked for me. You saved me a lot of time and headache! Thank you!
07-06-2025 02:22 PM
How do I do step 7?
Step 8 is easy.
07-06-2025 02:33 PM
07-06-2025 08:01 PM
SSP Server Unavailable.
Attempted to edit DefaultWebserverCertificate per your instructions. Attempted to upload CER and Keys to DefaultWebserverCertificate. Attempted to change DefaultWebserverCertificate.
Attempts were made after multiple reboots. Attempts were made after attempting to just restart http.
I have deregistered and reregistered the firewall with my account. I was able to update the DefaultInternalCertificate. Current version is 7.4.2.1-30. Default web certificate expired over 115 days ago.
06-30-2021 07:57 PM
I am importing several objects to FTD 1120 - 6.6.1-91 via API Call and I am getting this error:
"statusMessage": "Configuration import failed at step of 'import objects'. Configuration import failed - SSP Server Unavailable\nSSP Server Unavailable",
"scheduleUuid": "d270b736-da16-11eb-9061-d98ad80b9753",
"diskFileName": "ftd1.txt",
07-24-2021 11:27 AM
I'm running 6.7.0-65 and receiving it as well.
08-26-2021 05:45 AM
Cisco Firepower 1120 Threat Defense (78) Version 6.6.4 (Build 64)
I have the same "SSP Server Unavailable" when replace default cert
11-17-2021 01:43 PM
Me Too!!! Anyone found a solution?
11-30-2022 05:31 AM
same for me on Cisco Firepower 2120 Threat Defense (77) Version 7.0.4 (Build 55)
08-14-2023 09:03 AM
I am having this issue on 7.0.1-84.
08-21-2023 10:05 AM
Same with 7.2.4.1-43 managed by FDM, SSP Server Unavailable when updating "DefaultWebserverCertificate"
Has anyone found a solution?
09-17-2023 11:01 PM
See my solution above. works on 7.2.4.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide