10-06-2021 07:33 AM
Hello,
We have 3 certificates on ESA along with the default.
We noticed that soon it's going to expire.
From certconfig, there is no option to update the default certificate.
What should we do?
Thanks,
MEB
10-06-2021 07:39 AM
10-08-2021 09:12 AM
You may be right, it may auto-renew itself.
However, as best practise, i read that if you use somewhere the demonstrate certificate (usually it says where is used once you go to network > certificafes) you should use self-signed cert instead of it, if your public ones are not related with the hostname that you have specify for each course of action.
Regularly, you can see where the certificate is used on interfaces, listeners, destination controls etc.
So, we will use a self-signed to be on the safe side, but will also let the demo to see what will happen.
Hope it helps the next guy/gal who will have the same issue.
Meb
10-11-2021 08:40 AM
Hello,
The demo certificate is a dummy self-signed certificate and is not really intended to be used outside of initial deployment. You can create your own self-signed certificate to use in place of the demo. Of course, the ideal scenario would be to get your certificate signed by a trusted third party so that it can be verified. There's no reason not to have a trusted and signed certificate nowadays as they're quite cheap and easy to obtain.
As far as demo renewal, it has been done for specific versions in the past, and if expired, then during an upgrade; however, from what I've heard, that is no longer the case, and it will no longer auto-renew moving forward.
Thanks!
-Dennis M.
10-11-2021 08:44 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide