11-04-2013 02:14 PM
Can someone help me with the current process for installing a new certificate on an M670 running 8.1.0-476? Do I still use OPENSSL to generate the private key, and then get the certificate signed and import the certificate via CLI, pem format?
Can I install a SAN certificate? I have one DNS name spam.domain.com for the two (internal and external) SPAM quarantine interfaces and another name mspam.domain.com for the management interface.
Appreciate the input, I only do this every three years and the process has changed the last two times and I find nothing in the documentation.
Jason
Solved! Go to Solution.
11-08-2013 07:21 AM
Jason -
You can use a SAN certificate - as long as the machine names are specified and signed off in the cert by your signer.
Had previous saved notes for similar questions in the past --- see if this helps:
For full create and install:
http://tools.cisco.com/squish/39054
Starting with AsyncOS version 7.1 it is possible to generate a self-signing request on the ESA appliance. This can be used as a workaround to create certificates for SMAs.
Let me know!
-Robert
11-08-2013 07:21 AM
Jason -
You can use a SAN certificate - as long as the machine names are specified and signed off in the cert by your signer.
Had previous saved notes for similar questions in the past --- see if this helps:
For full create and install:
http://tools.cisco.com/squish/39054
Starting with AsyncOS version 7.1 it is possible to generate a self-signing request on the ESA appliance. This can be used as a workaround to create certificates for SMAs.
Let me know!
-Robert
12-11-2013 11:57 AM
Thanks Robert, Got r done.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide