cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3304
Views
5
Helpful
12
Replies

Using FMC GUI to replace RA VPN Certificate

LVS-Derek
Level 1
Level 1

Hi everyone.

 

I'm replacing the SSL cert for our RA VPN.  I've used the GUI because I'm not much of a Linux guy and I'm fairly new to Cisco stuff.  I have a pair of 5525s with the FMC virtual appliance.  I used the FMC GUI to generate a CSR but the interface timed out before I got the response back.  If I click the option to Enroll the identity certificate, it wants to start from scratch with a new CSR.  How do I get it to accept the certificate I got from GoDaddy?

 

Thanks for any help you can offer.

 

Derek

12 Replies 12

Hi,
When you generate the CSR you should be able to safely close the screen and then return later to import the signed certificate. If you closed the screen and re-entered it later, it might say that it's going to regenerate a CSR but I've tested, it doesn't, it's the same CSR. You should be able to successfully import the signed identity certificate from godaddy.

HTH

Thanks. I'll try that right now and report back!

No luck. What format should this certificate be in? Maybe I need to convert it first?

I've never had a problem importing an identity certicate in PEM format....these are prefixed with a “—–--- BEGIN …” line and end with "------ END CERTIFICATE---".

What format is your cerificate in? If not PEM then yes perhaps convert to PEM.

HTH

I'm trying the PEM again right now. It's possible I may have misselected the first time because it's taking a lot longer this time. I'll let it spin for a bit before I refresh.

No dice. It was still spinning when I got back to it so I hit Refresh. It's back to "Identity certificate import required." So I tried the PEM file once more and this time it quickly returned to the same message.

Is the file just the identity certificate certificate or the entire chain?
I assume the FTD you are applying the certificate to is actually online? If it's turned off then you cannot import the certificate.

Just the identity certificate. I was able to successfully upload the CA chain but it won't take the identity cert. I can't create a PKCS12 file because the interface doesn't give me access to the key used.

What enrollment type did you use? Manual?

You might have to just start again and re-submit to the CA.

Really hoping to avoid that as I've already reissued once, and I think GoDaddy only allows two! Man I hate these things.

Which version of FMC are you using?

What enrolment type did you use?

 

Just so we are on the right wave length, these are the steps that work:-

 

If using manual, you import the root certificate

 

vpn 1.PNG

Define the certificate parameters.

vpn 2.PNG

Click Save

Navigate to Devices > Certificates

Click Add

From the Device drop-down list select your device

From the Cert Enrollment drop-down list selectthe certificate enrolment

 

vpn 3.PNG

Click the ID button

Generate the CSR

vpn 44.png

Copy the contents of the CSR and send to GoDaddy to sign the certificate

vpn 5.PNG

Browse identity certificate to import the signed identity certifcate

 

Is that the steps you followed?

 

HTH

Yes, that's exactly what I did. I'm using FMC 6.5 on a pair of 5525s.
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card