aethercert
Firewalls

Automated certificates for Cisco Secure Firewall Management Center

On Firepower, certificates live as internal certificate objects in the Management Center. The package creates or updates that object over the FMC REST API and can deploy the change to a managed device.

The deployment steps defined in this package's manifest.

At a glance

Package
cisco-firepower-target 2.0.0
Compatibility
Secure Firewall Management Center / Firepower Management Center >=6.6 <8.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
Session login
Capabilities
Read inventoryImport certificate and keyActivate configuration
Deployment steps
findCertObject → createCertObject* → updateCertObject* → deployToDevice*
Rollback
None
Key usage
No requirement

* conditional step

What it does

An agent on your network signs in to the Management Center, looks up the internal certificate object by name, creates it on first issue or updates it on renewal, and optionally starts a deployment to the device you specify.

Multi-domain FMCs are supported by setting the domain UUID.

How it runs

  1. 01

    findCertObject

    The internal certificate object is looked up by name.

  2. 02

    createCertObject / updateCertObject

    It is created or updated with the new certificate and key.

  3. 03

    deployToDevice

    The change is deployed to the managed device, if configured.

What you configure

  • Management Center host and port
  • API username and password (stored encrypted)
  • Domain UUID (Global by default)
  • Internal certificate object name
  • Optional managed device UUID

Prerequisites

  • An agent with network access to the Management Center
  • An FMC API user with rights to edit objects and deploy

Limitations

  • A deployment pushes all pending changes for that device.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate Cisco Secure Firewall Management Center

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.