01-25-2023 11:17 AM - edited 01-25-2023 11:26 AM
We couldn't get SNORT updates, the error was Peer certificate cannot be authenticated with known CA certificates
I connected via ssh, opened an expert shell and started checking log files and I found a lot of this
curl: (60) SSL certificate problem: unable to get local issuer certificate
in
/var/log/schedule_tasks.log
This lead me to add the Identrust root CA and HydrantID intermediate CA certificate PEM files to
/etc/sf/keys/fireamp/thawte_roots
then run
sudo c_rehash /etc/sf/keys/fireamp/thawte_roots
to process them in correctly. This resolved the curl error above allowing the FMC to download SNORT updates.
Edit: You need these specific certs
HydrantID Server CA O1
IdenTrust Commercial Root CA 1
Solved! Go to Solution.
01-25-2023 11:17 AM
Initial post IS the solution
01-25-2023 11:17 AM
Initial post IS the solution
05-29-2023 03:33 AM
How do I find these certificates?
11-16-2023 09:11 PM
Is there impact or need any maintenance window to do these changes ?.
11-28-2023 07:21 PM
This may not be solved for some. Here's the bug https://quickview.cloudapps.cisco.com/quickview/bug/CSCvm03931. Even though your version may not be listed, the fix is updating to the latest recommended version.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide