02-28-2022 09:20 AM
Hi All,
Customer need to configure an SSL policy on Cisco FTd 2130 model but they are not going to use/generate Self signed or CSR Certificate for this requirement. It is possible that customer can use its own wild card certificate for ssl policy ?
Pls help
02-28-2022 09:37 AM - edited 02-28-2022 09:44 AM
@sv7 You need a CA certificate for TLS decryption, as the FTD will perform a MiTM and spoof the certificate.
You would need a private CA, such as Microsoft for this purpose. You will need a CA signing authority certificate, no a typical identity certificate.
More information
https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKSEC-3063.pdf
02-28-2022 09:47 AM
Like Rob said - you need to issue a certificate-issuing certificate to FTD from your private CA if you want to decrypt outgoing traffic.
If you only want to decrypt and inspect incoming traffic to servers that use the wildcard (or other certificate) you can use that as long as you have the private key(s).
02-28-2022 09:34 PM
Hi,
As my understanding it clears that i have to generate CSR from Fmc and after it gets signed from CA Authority can use for SSL decryption.
Please correct if im wrong somwhere
02-28-2022 11:37 PM - edited 02-28-2022 11:44 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide