12-29-2022 01:35 PM
I'm tasked with cleaning-up ASA configs. There exist a few certificates that have expired 2 years ago with no adverse effects.
I already understand I should make new valid certificates, but honestly there seems no reason for this to be a priority.
Am I safe with just deleting these old certificates from the configuration?
Thank you!
Solved! Go to Solution.
12-29-2022 02:34 PM
@jmaxwellUSAF ok if that's their only usage get rid of them. No cert for RAVPN though?
You'll need a certificate in future if you need to connect to ASDM, at which point I suggest issuing a cert from your internal CA.
12-29-2022 01:44 PM - edited 12-29-2022 01:45 PM
@jmaxwellUSAF what is or was the certificate used for? Is it referenced in the configuration somewhere?...which would indicate whether its still in use.
Is it just a root CA certificate or identity certificate?
12-29-2022 02:29 PM
I did research the use of these certificates. They are for the ASDM. For security reasons my company does not allow use of the ADSM GUI. We must use only CLI. Anyway the certs expired over a year ago.
If I need to create a new certificate, will these old certificates somehow prove useful? Or should I just delete them because they lack relevance?
12-29-2022 02:34 PM
@jmaxwellUSAF ok if that's their only usage get rid of them. No cert for RAVPN though?
You'll need a certificate in future if you need to connect to ASDM, at which point I suggest issuing a cert from your internal CA.
12-29-2022 01:47 PM
if they are old and redundant, there is no reason to keep it , I do not see any reason - you can delete them.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide