Loading...
centrexIT
Knowledge Center

Ryan Young Interiors Ryan Young AnyConnect SSL Renewal

KB00001084
Ernesto Cano Work Instruction Archived 1 min
ArchivedErnesto Canov0.5
Published Jul 29, 2024Expires Jul 29, 2025 (expired)

PROCEDURE

This procedure details how to renew the SSL certificate for Ryan Young Interiors’s AnyConnect client.

REQUIREMENTS

Credentials for ASDM found in PWstate.

STEPS

1.      Sign onto RYI-DC2 and launch ASDM. The IP is 192.168.3.254. The credentials are in PWstate.

2.      Select Configuration – Certificate Management – Identity Certificates – Select the currently active certificate – Select Add – Select “Add a new identity certificate” – Select the Key Pair drop-down and choose AnyConnect.

3.      Next, choose Select…

4.      In the following box, enter the following attributes, then select OK.

5.      Now select Add Certificate.

6.      Select Browse, and save it to C:\Certificates, provide it a name with .txt on the end, and then Save As. Select OK and then Add Certificate as shown in this guide.

7.      Browse to the location of where you saved your CSR and open the .txt file and copy the entire contents to your clipboard. Next, sign into OneLogin and choose GoDaddy. From there, select the icon with the nine squares next to My Account and choose SSL Certificates. In the Search Domains box, type in vpn.ryan-young.com and select the SSL in the darker grey box. Scroll down to the middle of the page and beneath Manage Certificate, choose Re-Key your certificate. In the box that says Paste your CSR here, paste in the contents of your clipboard from earlier and select Add Change. After this, select Submit All Changes.

8.      Your newly re-keyed certificate will take a couple of minutes before it is available. Keep refreshing the page until you see Ready! to the right of Re-Key your certificate.

9.      Once it is ready, look to the right and find the Download Certificate box. Under the Server Type drop-down, pick Other and download the .zip file to your local computer. Copy the .zip file to the C:\Certificates folder on RYI-DC2 and extract it within the same directory.

10.      Back in ASDM, select the new certificate and select Install.

11.      Select the certificate that has a numbered name. In this year’s example, it is dc72e526f252d87.crt. Next, select Install ID certificate file.

12.      You will now see the specified file listed in the Install from a file bar. Select Install Certificate. A moment later, you will then see Certificate Import Succeeded.

13.      Back in ASDM, go to Configuration – Device Management – Advanced – SSL Settings. From here, under Certificates, scroll down to the outside interface and select Edit.

14.      Select the Primary Enrolled Certificate drop-down, choose the newly created one, and select OK. After this, select Apply. At the top, select Save to save the new configuration. Do not update the Load Balancing Enrolled Certificate.

15.      Wait a moment and then browse to https://vpn.ryan-young.com/ and check your new SSL verify the valid from day. If the date matches what you believe it should be, the renewal should be completed. Test with AnyConnect. If all works fine, then you have successfully updated the SSL for vpn.ryan-young.com

REFERENCES