{"id":111,"date":"2023-03-19T08:35:44","date_gmt":"2023-03-19T07:35:44","guid":{"rendered":"http:\/\/10.4.44.99:10084\/?p=111"},"modified":"2023-03-19T08:35:44","modified_gmt":"2023-03-19T07:35:44","slug":"cisco-asa-asdm-certificate-selfsigned","status":"publish","type":"post","link":"https:\/\/www.winni.at\/wordpress\/?p=111","title":{"rendered":"Cisco ASA | ASDM Certificate SelfSigned"},"content":{"rendered":"\n<p>Install an Identity Certificate for ASDM<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<h3 class=\"wp-block-heading\">Run the ASDM Identity Certificate Wizard (ASDM 7.3 and Later)<\/h3>\n\n\n\n<p>ASDM 7.3 and later provides the ASDM Identity Certificate Wizard. The wizard makes configuring self-signed identity certificates easy.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>When you first launch ASDM and do not have a trusted certificate, you are prompted to launch ASDM with Java Web Start; the certificate wizard then starts automatically.<\/li>\n\n\n\n<li>If you start ASDM yourself using Java Web Start, then you can launch the wizard from the Wizards menu.<\/li>\n\n\n\n<li>To generate the separate ASA FirePOWER module certificate, you must re-run the wizard to generate the additional certificate.<\/li>\n<\/ul>\n\n\n\n<p>Procedure<\/p>\n\n\n\n<p><strong>1.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Launch ASDM. Use an already installed ASDM Launcher, or connect to the ASA IP address with a browser (<strong>https:\/\/<\/strong>&nbsp;<em>asa_ip_address<\/em>&nbsp;<strong>\/admin<\/strong>) to install a new Launcher. The Launcher prompts you to automatically start ASDM with Java Web Start for the purpose of running the certificate wizard.<\/p>\n\n\n\n<p><strong>2.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;(If the wizard did not launch automatically) Choose&nbsp;<strong>Wizards &gt; ASDM Identity Certificate Wizard<\/strong>.<\/p>\n\n\n\n<p><strong>3.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Complete the wizard. We recommend choosing the&nbsp;<strong>Simple Mode<\/strong>&nbsp;option.<\/p>\n\n\n\n<p><strong>4.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;(ASA FirePOWER module) Re-run the wizard, and choose the&nbsp;<strong>SFR Module&nbsp;<\/strong>option.<\/p>\n\n\n\n<p><strong>5.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Quit ASDM.<\/p>\n\n\n\n<p><strong>6.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;See&nbsp;<a href=\"http:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/asdm\/identity-cert\/cert-install.html#93109\">Register the New Identity Certificate(s) with Java<\/a>&nbsp;to register both certificates.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Register the New Identity Certificate(s) with Java<\/h3>\n\n\n\n<p>This procedure shows Java in Windows 7; your operating system may differ.<\/p>\n\n\n\n<p>Procedure<\/p>\n\n\n\n<p><strong>1.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;On your computer, launch the Java Control Panel. On the&nbsp;<strong>Security<\/strong>&nbsp;tab, click&nbsp;<strong>Manage<\/strong>&nbsp;<strong>Certificates<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371534.tif\/_jcr_content\/renditions\/371534.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371534.tif\/_jcr_content\/renditions\/371534.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p><strong>2.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;From the&nbsp;<strong>Certificate type<\/strong>&nbsp;drop-down list, choose&nbsp;<strong>Secure Site<\/strong>, and click&nbsp;<strong>Import<\/strong>.<\/p>\n\n\n\n<p><strong>Note:&nbsp;<\/strong>You&nbsp;<em>must<\/em>&nbsp;choose the&nbsp;<strong>Secure Site&nbsp;<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>option; other categories do not work.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371535.tif\/_jcr_content\/renditions\/371535.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371535.tif\/_jcr_content\/renditions\/371535.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p><strong>3.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Choose the ASA certificate you earlier exported from ASDM.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371536.tif\/_jcr_content\/renditions\/371536.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371536.tif\/_jcr_content\/renditions\/371536.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371537.tif\/_jcr_content\/renditions\/371537.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371537.tif\/_jcr_content\/renditions\/371537.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p><strong>4.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;(ASA FirePOWER module) Click&nbsp;<strong>Import<\/strong>&nbsp;again, and choose the module certificate that you earlier exported from ASDM.<\/p>\n\n\n\n<p><strong>5.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Click&nbsp;<strong>Close<\/strong>.<\/p>\n\n\n\n<p><strong>6.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;You can now use the ASDM Launcher.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">(ASDM 7.2 and Earlier) Manually Configure the ASA for an Identity Certificate<\/h4>\n\n\n\n<p>Complete all of the following procedures.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Create the Identity Certificate<\/h5>\n\n\n\n<p>Procedure<\/p>\n\n\n\n<p><strong>1.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;In a browser, connect to the ASA (<strong>https:\/\/<\/strong>&nbsp;<em>asa_ip_address<\/em>&nbsp;<strong>\/admin<\/strong>) and launch ASDM by clicking&nbsp;<strong>Run ASDM<\/strong>.<\/p>\n\n\n\n<p><strong>2.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Choose&nbsp;<strong>Configuration &gt; Device Management &gt; Certificate Management &gt; Identity Certificates<\/strong>, and click&nbsp;<strong>Add<\/strong>.<\/p>\n\n\n\n<p><strong>3.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Click the&nbsp;<strong>Add a new identity certificate<\/strong>&nbsp;radio button, and click&nbsp;<strong>Select<\/strong>&nbsp;for the&nbsp;<strong>Certificate Subject DN<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371527.tif\/_jcr_content\/renditions\/371527.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371527.tif\/_jcr_content\/renditions\/371527.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p><strong>4.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;From the&nbsp;<strong>Attribute<\/strong>&nbsp;drop-down list, choose&nbsp;<strong>Common Name (CN)<\/strong>, enter the ASA IP address for the<strong>Value<\/strong>, click&nbsp;<strong>Add<\/strong>, and then click&nbsp;<strong>OK<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371528.tif\/_jcr_content\/renditions\/371528.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371528.tif\/_jcr_content\/renditions\/371528.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p><strong>5.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Check the&nbsp;<strong>Generate self-signed certificate<\/strong>&nbsp;check box and click&nbsp;<strong>Add Certificate<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371529.tif\/_jcr_content\/renditions\/371529.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371529.tif\/_jcr_content\/renditions\/371529.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p><strong>6.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Click&nbsp;<strong>Apply<\/strong>.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Export the New Certificate<\/h5>\n\n\n\n<p>Procedure<\/p>\n\n\n\n<p><strong>1.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Select the certificate, and click&nbsp;<strong>Export<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371530.tif\/_jcr_content\/renditions\/371530.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371530.tif\/_jcr_content\/renditions\/371530.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p><strong>2.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Click&nbsp;<strong>Browse<\/strong>&nbsp;to choose a save location and name the certificate with the.csr extension (the Java Control Panel expects a.csr extension, so you can save yourself a step by using.csr even though this certificate is a CER file).<\/p>\n\n\n\n<p><strong>3.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Click the&nbsp;<strong>PEM Format (Certificate Only)<\/strong>&nbsp;radio button, and then click&nbsp;<strong>Export Certificate<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371531.tif\/_jcr_content\/renditions\/371531.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371531.tif\/_jcr_content\/renditions\/371531.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\">Set the Certificate to Be Used with SSL<\/h5>\n\n\n\n<p>Procedure<\/p>\n\n\n\n<p><strong>1.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Choose&nbsp;<strong>Device Management &gt; Advanced &gt; SSL Settings<\/strong>. In the&nbsp;<strong>Certificates<\/strong>&nbsp;area, select the management interface entry, and click&nbsp;<strong>Edit<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371532.tif\/_jcr_content\/renditions\/371532.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371532.tif\/_jcr_content\/renditions\/371532.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p><strong>2.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;From the&nbsp;<strong>Primary Enrolled Certificate<\/strong>&nbsp;drop-down list, choose the newly-created certificate with the CN value of the ASA IP address, and click&nbsp;<strong>OK<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371533.tif\/_jcr_content\/renditions\/371533.jpg\"><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/300001-400000\/370001-380000\/371001-372000\/371533.tif\/_jcr_content\/renditions\/371533.jpg\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p><strong>3.<\/strong><a href=\"http:\/\/www.cisco.com\/c\/dam\/en\/us\/td\/i\/templates\/blank.gif\"><\/a>&nbsp;Click&nbsp;<strong>Apply<\/strong>.<\/p>\n\n\n\n<p>Source:&nbsp;<a href=\"http:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/asdm\/identity-cert\/cert-install.html\">http:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/asdm\/identity-cert\/cert-install.html<\/a><\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Install an Identity Certificate for ASDM<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[3],"tags":[19,20,21,22,25,34],"class_list":["post-111","post","type-post","status-publish","format-standard","hentry","category-kb","tag-cisco","tag-cisco-asa","tag-cisco-asa-add-certificate","tag-cisco-asa-certificate","tag-cisco-asa-self-singned","tag-cisco-firewall-certificate"],"_links":{"self":[{"href":"https:\/\/www.winni.at\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.winni.at\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.winni.at\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.winni.at\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.winni.at\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=111"}],"version-history":[{"count":0,"href":"https:\/\/www.winni.at\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/111\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.winni.at\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.winni.at\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.winni.at\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}