10-09-2024 02:04 AM
Good day -
I can no longer download and run the ASDM from our dual FPR2110 (primary / secondary) system ,
after intalling OpenSSL 3.2.2-3.fc40 on a Red Hat Fedora Core 40 x86_64 system -
it used to work under OpenSSL 3.2.1-2.fc40 , with the following file installed in
/usr/share/pki/ca-trust-source/anchors/asdm.pem :
# openssl x509 -inform pem -text -in /usr/share/pki/ca-trust-source/anchors/asdm.pem
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
20:75:83:3e:b3:84:45:e8:ad:50:6f:72:25:25:21:40
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=Symantec Corporation, OU=Symantec Trust Network, CN=Symantec Class 3 SHA256 Code Signing CA
Validity
Not Before: Nov 9 00:00:00 2016 GMT
Not After : Nov 26 23:59:59 2019 GMT
Subject: C=US, ST=California, L=San Jose, O=Cisco Systems, Inc., CN=Cisco Systems, Inc.
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b2:e5:54:8e:1b:e6:51:99:8b:46:47:6d:78:c8:
32:53:c3:2e:f1:7a:0b:bc:63:1c:95:ed:a5:1e:73:
4e:f6:b1:9d:03:6f:8e:cf:b9:ef:88:c0:13:9e:f2:
46:31:71:c2:62:aa:5a:aa:32:1c:aa:12:34:ed:d8:
9e:5c:63:52:4f:db:b8:39:38:de:6f:d0:23:5a:ad:
ae:cf:b5:e2:2e:0a:8a:9d:e5:98:cd:88:38:97:85:
b1:d2:f1:a6:c3:d6:48:37:5a:92:f1:6a:cb:3f:87:
d5:6d:76:eb:a5:f8:d8:4e:4b:b5:49:3d:28:ba:ad:
fc:23:f5:f6:d6:c0:e2:46:f2:12:c4:91:8c:97:d0:
f9:9b:ee:81:4c:a4:d8:d6:13:67:c1:9a:8a:b2:4f:
af:79:5d:f7:19:6c:ec:63:88:e0:9b:42:31:fa:af:
d9:e9:61:51:1e:74:bc:cf:58:79:ce:ba:8a:5e:06:
36:04:b8:01:fd:f7:4b:3d:8e:d9:70:37:39:cc:f4:
da:49:bb:5d:d4:b9:b1:32:2b:1d:94:a3:a4:0a:50:
12:6b:ae:80:90:66:db:06:10:d2:5c:0e:95:d3:5b:
31:6e:b5:54:0f:ef:32:c3:91:f1:8d:29:01:76:f6:
86:8a:fd:7a:dd:9e:74:3b:d8:db:51:98:40:2a:37:
93:05
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints:
CA:FALSE
X509v3 Key Usage: critical
Digital Signature
X509v3 CRL Distribution Points:
Full Name:
URI:http://sv.symcb.com/sv.crl
X509v3 Certificate Policies:
Policy: 2.23.140.1.4.1
CPS: https://d.symcb.com/cps
User Notice:
Explicit Text: https://d.symcb.com/rpa
X509v3 Extended Key Usage:
Code Signing
Authority Information Access:
OCSP - URI:http://sv.symcd.com
CA Issuers - URI:http://sv.symcb.com/sv.crt
X509v3 Authority Key Identifier:
96:3B:53:F0:79:33:97:AF:7D:83:EF:2E:2B:CC:CA:B7:86:1E:72:66
X509v3 Subject Key Identifier:
C2:68:7E:CE:20:AF:02:89:9D:41:66:F3:F8:C2:86:14:94:C9:5A:80
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
28:02:84:de:83:a7:62:ce:cb:11:24:9f:76:b7:4e:98:14:47:
48:f8:ec:e3:bf:5d:91:c3:c6:35:43:f4:89:ed:e9:b0:88:5a:
85:ca:94:3d:63:f9:4f:4b:d2:e4:81:7c:73:20:55:81:5e:60:
b1:16:c3:cf:a4:64:21:d1:21:be:e7:aa:26:fb:6a:19:92:3d:
ba:13:6a:68:bb:6d:fc:da:60:52:45:6f:c6:6d:b4:4f:a0:61:
83:3d:0e:07:da:e7:f9:1e:4e:2b:bb:80:2a:fd:11:9a:90:96:
24:dc:1d:74:bb:4b:cc:64:06:0a:a2:8e:6a:1c:f0:c8:0d:d4:
cf:4d:a6:0e:94:fc:f2:87:ee:d3:1d:22:56:08:ea:a5:0a:f4:
90:b1:de:1b:00:0c:1a:ac:93:bf:75:be:d0:bc:80:d5:12:dd:
ed:02:c9:65:ff:33:80:59:34:15:16:ef:2b:36:3a:1a:5d:61:
c5:a3:c2:76:26:e1:6b:bd:c0:20:ce:80:33:f4:db:25:f1:ff:
d7:fd:9a:27:63:83:b5:15:57:80:f9:36:08:75:fa:48:3c:99:
64:47:5b:6c:26:2d:6d:24:9e:f8:ba:c2:93:e5:5e:19:d1:d5:
fc:25:58:09:e2:09:d3:b6:30:a7:f1:80:bd:c5:68:a1:50:f0:
da:a5:c8:d0
-----BEGIN CERTIFICATE-----
MIIE2TCCA8GgAwIBAgIQIHWDPrOEReitUG9yJSUhQDANBgkqhkiG9w0BAQsFADB/
MQswCQYDVQQGEwJVUzEdMBsGA1UEChMUU3ltYW50ZWMgQ29ycG9yYXRpb24xHzAd
BgNVBAsTFlN5bWFudGVjIFRydXN0IE5ldHdvcmsxMDAuBgNVBAMTJ1N5bWFudGVj
IENsYXNzIDMgU0hBMjU2IENvZGUgU2lnbmluZyBDQTAeFw0xNjExMDkwMDAwMDBa
Fw0xOTExMjYyMzU5NTlaMHExCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9y
bmlhMREwDwYDVQQHDAhTYW4gSm9zZTEcMBoGA1UECgwTQ2lzY28gU3lzdGVtcywg
SW5jLjEcMBoGA1UEAwwTQ2lzY28gU3lzdGVtcywgSW5jLjCCASIwDQYJKoZIhvcN
AQEBBQADggEPADCCAQoCggEBALLlVI4b5lGZi0ZHbXjIMlPDLvF6C7xjHJXtpR5z
TvaxnQNvjs+574jAE57yRjFxwmKqWqoyHKoSNO3YnlxjUk/buDk43m/QI1qtrs+1
4i4Kip3lmM2IOJeFsdLxpsPWSDdakvFqyz+H1W1266X42E5LtUk9KLqt/CP19tbA
4kbyEsSRjJfQ+ZvugUyk2NYTZ8GairJPr3ld9xls7GOI4JtCMfqv2elhUR50vM9Y
ec66il4GNgS4Af33Sz2O2XA3Ocz02km7XdS5sTIrHZSjpApQEmuugJBm2wYQ0lwO
ldNbMW61VA/vMsOR8Y0pAXb2hor9et2edDvY21GYQCo3kwUCAwEAAaOCAV0wggFZ
MAkGA1UdEwQCMAAwDgYDVR0PAQH/BAQDAgeAMCsGA1UdHwQkMCIwIKAeoByGGmh0
dHA6Ly9zdi5zeW1jYi5jb20vc3YuY3JsMGEGA1UdIARaMFgwVgYGZ4EMAQQBMEww
IwYIKwYBBQUHAgEWF2h0dHBzOi8vZC5zeW1jYi5jb20vY3BzMCUGCCsGAQUFBwIC
MBkMF2h0dHBzOi8vZC5zeW1jYi5jb20vcnBhMBMGA1UdJQQMMAoGCCsGAQUFBwMD
MFcGCCsGAQUFBwEBBEswSTAfBggrBgEFBQcwAYYTaHR0cDovL3N2LnN5bWNkLmNv
bTAmBggrBgEFBQcwAoYaaHR0cDovL3N2LnN5bWNiLmNvbS9zdi5jcnQwHwYDVR0j
BBgwFoAUljtT8Hkzl699g+8uK8zKt4YecmYwHQYDVR0OBBYEFMJofs4grwKJnUFm
8/jChhSUyVqAMA0GCSqGSIb3DQEBCwUAA4IBAQAoAoTeg6dizssRJJ92t06YFEdI
+Ozjv12Rw8Y1Q/SJ7emwiFqFypQ9Y/lPS9LkgXxzIFWBXmCxFsPPpGQh0SG+56om
+2oZkj26E2pou2382mBSRW/GbbRPoGGDPQ4H2uf5Hk4ru4Aq/RGakJYk3B10u0vM
ZAYKoo5qHPDIDdTPTaYOlPzyh+7THSJWCOqlCvSQsd4bAAwarJO/db7QvIDVEt3t
Asll/zOAWTQVFu8rNjoaXWHFo8J2JuFrvcAgzoAz9Nsl8f/X/ZonY4O1FVeA+TYI
dfpIPJlkR1tsJi1tJJ74usKT5V4Z0dX8JVgJ4gnTtjCn8YC9xWihUPDapcjQ
-----END CERTIFICATE-----
and then running 'update-ca-trust' .
Note that the certicate Expired on Not After : Nov 26 23:59:59 2019 GMT.
How can I update the certicficate used by ASDM ?
Solved! Go to Solution.
10-09-2024 02:08 AM
10-09-2024 02:08 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide