10-27-2020 04:46 PM
Hello,
I have a working remote access SSL VPN solution using a pair of FTDs on 6.4. The current SSL certificate is RSA based but we've been asked to upgrade to ECDSA for suite B. The documentation states 'Only RSA based certificates are supported in SSL and IPSec'. Has anyone got an elliptic curve certificate working for SSL VPNs on the FTD?
Thank you,
Martin
10-27-2020 04:54 PM
it can use dh instead of rsa,
I will share example later.
10-28-2020 12:27 AM
@MHM Cisco World wrote:
it can use dh instead of rsa,
He is talking about the certificate that is used for authentication. Authentication and Key-Exchange are different functions.
10-28-2020 12:26 AM
At least it is documented to be supported on version 6.6. But I am not aware of the first release that supports it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide