03-14-2025 10:57 AM
I have an expired cert that I'm trying to remove via FMC (7.2.9) but I can't find it.
In the CLI I see this...
webvpn
trustpoint sp VPN_x2025-02
...but in FMC I can't find anything that's using that certificate. I don't see it under any of the VPN profiles, the group policies, the access interfaces or the advanced tab.
Does anyone have suggestions for where in the FMC GUI the webvpn > trustpoint sp cert is configured?
Thanks
(If there are no suggestions I'll try flex config to remove it.)
03-14-2025 11:03 AM
@DaveNoonan26775 you install the certificates in the FMC under Devices > Certificates. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/objects-certs.html
03-14-2025 11:54 AM
That's true, and when I try to delete it from there it says it used and won't remove it.
The error message when I try to delete it is...
Unable to delete certifcate enrollment. It is used in the following policies:
Remote Acess VPN: VF-SVPN
There are six tunnel-group's under policy and I don't see VPN_x2025-02 under any of them, so I went to the CLI and found it under webvpn, but I still don't know what means in FMC terms. (This is the bit I don't like about GUIs.)
03-14-2025 11:58 AM
@DaveNoonan26775 configured as the Access Interface certificate?
Devices > VPN > Remote Access.
Click the Access Interface tab
Select the Configure Interface Specific Identity Certificate check box and select Interface Identity Certificate from the drop-down list.
03-14-2025 01:14 PM - edited 03-14-2025 01:16 PM
Been there, done that.
Thank you. At least I feel like I'm not alone now.
03-16-2025 01:47 AM
@DaveNoonan26775 if you are using SAML, you might also find it under AAA servers which are indirectly referenced by a VPN Connection profile / tunnel-group.
Removal via flexconfig will be blacklisted since the feature is configured via the GUI.
03-17-2025 07:42 AM
We recently started using SAML but the cert in question was on the interface at one time, but replaced when it expired.
At least now I feel more confident that I haven't missed anything obvious. I'll open a TAC case and see if they can find it.
Thanks, @Marvin Rhoads , Thanks @Rob Ingram.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide