Jump to content

Cisco devices need certificates updating before 2020-01-01


Recommended Posts

Posted (edited)
my head office is full of their gear, oh joy, at least im dell where I work, but a painful January incoming for me, cheers for this.

This FN won't impact the vast majority of users. This is only if you used an IOS device to create a cert which is typically done on ISR routers for voice configuration. As a general best practice you shouldn't be self signing certs with your network hardware. Just because you have the capability to it doesn't mean you should.

 

Use a private or open source cert provider or your own CA. If you do issue a cert it is your responsibility to keep track of its expiration, not your hardware vendor. If for some reason you don't want to do this you could also just recreate a new cert, but it would be continuing bad practices.

Edited by SuperfluousAdjective
Posted (edited)
Give us all plenty of notice I see.....

 

If your organization deployed a self signed cert inside IOS they put themselves on notice when the cert was created. It is not a secret or mystery to see when it expires in IOS. The person who created the certificate is the one who is responsible for making sure it does not expire and create and unplanned outage. It is not the responsibility of your hardware vendors to proactively reach out to you when your self-signed certificates expire. Maintaining good documentation is a best practice... as is not self-signing certificates on routers in the first place. Use a real CA or at the very least an open-source certificate.

Edited by SuperfluousAdjective
Posted

I dont think we are using self certs on our site there for switching/routers, but I am of the opinion though, update its firmware now with this, as it could cause potential problems later on if it expires past that date that we don't know about, it actually ties in for us. My colleagues and I are doing a huge reimaging piece on our switching there as it was setup by someone who did all kinds of weird and wonderful stuff when they installed it (Believe he was a CCIE studying guy in the service company we used to employ, so our head office has all manner of bonkers stuff like route-maps in place, when it should be fairly simple yet secure stuff - everytime someone has done work there somethings gone awry)

 

Might as well bite the bullet and get them updated from 12.2 in all this :)

Posted
If your organization deployed a self signed cert inside IOS they put themselves on notice when the cert was created. It is not a secret or mystery to see when it expires in IOS. The person who created the certificate is the one who is responsible for making sure it does not expire and create and unplanned outage. It is not the responsibility of your hardware vendors to proactively reach out to you when your self-signed certificates expire. Maintaining good documentation is a best practice... as is not self-signing certificates on routers in the first place. Use a real CA or at the very least an open-source certificate.
I agree. I have inherited a mess of a network with no documentation spread over Australia. Nightmare with things like this.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...