{"id":8233,"date":"2025-03-07T17:48:11","date_gmt":"2025-03-07T10:48:11","guid":{"rendered":"https:\/\/www.ablenet.co.th\/?p=8233"},"modified":"2025-03-07T17:50:15","modified_gmt":"2025-03-07T10:50:15","slug":"%e0%b8%81%e0%b8%b2%e0%b8%a3%e0%b9%81%e0%b8%81%e0%b9%89%e0%b9%84%e0%b8%82%e0%b8%9b%e0%b8%b1%e0%b8%8d%e0%b8%ab%e0%b8%b2%e0%b9%83%e0%b8%9a-certificate-%e0%b8%82%e0%b8%ad%e0%b8%87-fmc-%e0%b8%ab%e0%b8%a1","status":"publish","type":"post","link":"https:\/\/www.ablenet.co.th\/en\/2025\/03\/07\/%e0%b8%81%e0%b8%b2%e0%b8%a3%e0%b9%81%e0%b8%81%e0%b9%89%e0%b9%84%e0%b8%82%e0%b8%9b%e0%b8%b1%e0%b8%8d%e0%b8%ab%e0%b8%b2%e0%b9%83%e0%b8%9a-certificate-%e0%b8%82%e0%b8%ad%e0%b8%87-fmc-%e0%b8%ab%e0%b8%a1\/","title":{"rendered":"\u0e01\u0e32\u0e23\u0e41\u0e01\u0e49\u0e44\u0e02\u0e1b\u0e31\u0e0d\u0e2b\u0e32\u0e43\u0e1a Certificate \u0e02\u0e2d\u0e07 FMC \u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38"},"content":{"rendered":"<p><strong>cacert.pem<\/strong> Certificate \u0e1a\u0e19 <strong>FMC<\/strong> \u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38 \u0e2a\u0e48\u0e07\u0e1c\u0e25\u0e43\u0e2b\u0e49\u0e17\u0e38\u0e01\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c\u0e41\u0e2a\u0e14\u0e07\u0e2a\u0e16\u0e32\u0e19\u0e30\u0e40\u0e1b\u0e47\u0e19 &#8220;disabled&#8221;<\/p>\n<p><strong>\u0e2d\u0e32\u0e01\u0e32\u0e23\u0e02\u0e2d\u0e07\u0e1b\u0e31\u0e0d\u0e2b\u0e32: \u0e15\u0e31\u0e27\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c Firepower<\/strong> \u0e44\u0e21\u0e48\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21\u0e15\u0e48\u0e2d\u0e01\u0e31\u0e1a <strong>Firepower Management Center (FMC)<\/strong> \u0e44\u0e14\u0e49 \u0e40\u0e19\u0e37\u0e48\u0e2d\u0e07\u0e08\u0e32\u0e01\u0e43\u0e1a\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07\u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e40\u0e0b\u0e47\u0e19\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07 <strong>sftunnel certificates<\/strong> \u0e1a\u0e19 <strong>FMC<\/strong> \u0e44\u0e14\u0e49\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38\u0e41\u0e25\u0e49\u0e27\u0e19\u0e31\u0e48\u0e19\u0e40\u0e2d\u0e07\u0e04\u0e23\u0e31\u0e1a<\/p>\n<p><strong>\u0e44\u0e1f\u0e25\u0e4c\u0e1a\u0e31\u0e19\u0e17\u0e36\u0e01\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25 (Logs):<\/strong><\/p>\n<p><em>\u0e02\u0e49\u0e2d\u0e1c\u0e34\u0e14\u0e1e\u0e25\u0e32\u0e14\u0e1a\u0e19\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c:<\/em><\/p>\n<pre><code>Sep 20 04:10:47 DEVICE SF-IMS[50792]: [51982] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to FMC-IP:8305\/tcp\r\nSep 20 04:10:47 DEVICE SF-IMS[50792]: [51982] sftunneld:sf_ssl [INFO] Wait to connect to 8305 (IPv4): FMC-IP\r\nSep 20 04:10:47 DEVICE SF-IMS[50792]: [51982] sftunneld:sf_ssl [ERROR] -Error with certificate at depth: 1\r\nSep 20 04:10:47 DEVICE SF-IMS[50792]: [51982] sftunneld:sf_ssl [ERROR] err 10:certificate has expired\r\nSep 20 04:10:47 DEVICE SF-IMS[50792]: [51982] sftunneld:sf_ssl [ERROR] SSL_renegotiate error: 1: error:00000001:lib(0):func(0):reason(1)\r\n<\/code><\/pre>\n<p><em>\u0e02\u0e49\u0e2d\u0e1c\u0e34\u0e14\u0e1e\u0e25\u0e32\u0e14\u0e1a\u0e19 FMC:<\/em><\/p>\n<pre><code>Sep 20 03:14:23 FMC SF-IMS[1504]: [4171] sftunneld:sf_ssl [ERROR] SSL_renegotiate error: 1: error:00000001:lib(0):func(0):reason(1)\r\nSep 20 03:14:23 FMC SF-IMS[1504]: [4171] sftunneld:sf_ssl [WARN] establishConnectionUtil: SSL handshake failed\r\nSep 20 03:14:23 FMC SF-IMS[1504]: [4171] sftunneld:sf_ssl [ERROR] establishSSLConnection: Unable to connect with both threads:\r\n<\/code><\/pre>\n<p><strong>\u0e40\u0e07\u0e37\u0e48\u0e2d\u0e19\u0e44\u0e02\u0e02\u0e2d\u0e07\u0e1b\u0e31\u0e0d\u0e2b\u0e32:<\/strong> \u0e44\u0e1f\u0e25\u0e4c <strong>cacert.pem<\/strong> \u0e41\u0e2a\u0e14\u0e07\u0e2a\u0e16\u0e32\u0e19\u0e30\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38\u0e1a\u0e19 <strong>FMC<\/strong><\/p>\n<p>\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e15\u0e23\u0e27\u0e08\u0e2a\u0e2d\u0e1a\u0e43\u0e1a\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07\u0e44\u0e14\u0e49\u0e42\u0e14\u0e22\u0e43\u0e0a\u0e49\u0e04\u0e33\u0e2a\u0e31\u0e48\u0e07\u0e15\u0e48\u0e2d\u0e44\u0e1b\u0e19\u0e35\u0e49:<\/p>\n<pre><code class=\"language-bash\">cd \/etc\/sf\/ca_root\/\r\nroot@firepower:\/etc\/sf\/ca_root# openssl x509 -text -in cacert.pem\r\n<\/code><\/pre>\n<p>\u0e15\u0e31\u0e27\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e1c\u0e25\u0e25\u0e31\u0e1e\u0e18\u0e4c\u0e17\u0e35\u0e48\u0e41\u0e2a\u0e14\u0e07\u0e27\u0e48\u0e32\u0e43\u0e1a\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38\u0e41\u0e25\u0e49\u0e27:<\/p>\n<pre><code class=\"language-plaintext\"> Validity\r\n    Not Before: Jul 18 18:31:32 2012 GMT\r\n    Not After : Jul 16 18:31:32 2022 GMT &lt;&lt;&lt;\r\n<\/code><\/pre>\n<p><strong>\u0e41\u0e19\u0e27\u0e17\u0e32\u0e07\u0e41\u0e01\u0e49\u0e44\u0e02\u0e0a\u0e31\u0e48\u0e27\u0e04\u0e23\u0e32\u0e27 (Workaround):<\/strong> \u0e41\u0e19\u0e27\u0e17\u0e32\u0e07\u0e41\u0e01\u0e49\u0e44\u0e02\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e1b\u0e31\u0e0d\u0e2b\u0e32\u0e19\u0e35\u0e49\u0e2d\u0e18\u0e34\u0e1a\u0e32\u0e22\u0e44\u0e27\u0e49\u0e17\u0e35\u0e48 <a href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/security\/firepower-management-center-4600\/222464-renewal-of-fmc-sftunnel-ca-certificate-f.html\">Cisco Support<\/a> \u0e42\u0e14\u0e22\u0e02\u0e36\u0e49\u0e19\u0e2d\u0e22\u0e39\u0e48\u0e01\u0e31\u0e1a\u0e27\u0e48\u0e32\u0e43\u0e1a\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38\u0e41\u0e25\u0e49\u0e27\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/p>\n<p><strong>\u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14\u0e40\u0e1e\u0e34\u0e48\u0e21\u0e40\u0e15\u0e34\u0e21\u0e40\u0e01\u0e35\u0e48\u0e22\u0e27\u0e01\u0e31\u0e1a\u0e1b\u0e31\u0e0d\u0e2b\u0e32:<\/strong> \u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e14\u0e39\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e40\u0e1e\u0e34\u0e48\u0e21\u0e40\u0e15\u0e34\u0e21\u0e44\u0e14\u0e49\u0e17\u0e35\u0e48 <a href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/field-notices\/742\/fn74214.html\">Cisco Field Notice<\/a><\/p>\n<p><strong>\u0e01\u0e32\u0e23\u0e15\u0e23\u0e27\u0e08\u0e2a\u0e2d\u0e1a\u0e27\u0e31\u0e19\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38\u0e02\u0e2d\u0e07\u0e43\u0e1a\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07:<\/strong> \u0e43\u0e0a\u0e49\u0e04\u0e33\u0e2a\u0e31\u0e48\u0e07\u0e15\u0e48\u0e2d\u0e44\u0e1b\u0e19\u0e35\u0e49\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e15\u0e23\u0e27\u0e08\u0e2a\u0e2d\u0e1a:<\/p>\n<pre><code class=\"language-bash\">root@firepower:\/etc\/sf\/ca_root# openssl x509 -text -in cacert.pem\r\n<\/code><\/pre>\n<p>\u0e2b\u0e32\u0e01\u0e27\u0e31\u0e19\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38\u0e02\u0e2d\u0e07\u0e43\u0e1a\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07 (Not After) \u0e40\u0e1b\u0e47\u0e19\u0e27\u0e31\u0e19\u0e17\u0e35\u0e48\u0e1c\u0e48\u0e32\u0e19\u0e21\u0e32\u0e41\u0e25\u0e49\u0e27 \u0e41\u0e2a\u0e14\u0e07\u0e27\u0e48\u0e32\u0e43\u0e1a\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38\u0e41\u0e25\u0e30\u0e15\u0e49\u0e2d\u0e07\u0e14\u0e33\u0e40\u0e19\u0e34\u0e19\u0e01\u0e32\u0e23\u0e15\u0e48\u0e2d\u0e2d\u0e32\u0e22\u0e38\u0e04\u0e23\u0e31\u0e1a<\/p>\n<p>#FMC #Firepower #Cisco #Cybersecurity<\/p>\n","protected":false},"excerpt":{"rendered":"<p>cacert.pem Certificate \u0e1a\u0e19 FMC \u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38 \u0e2a\u0e48\u0e07\u0e1c\u0e25\u0e43\u0e2b\u0e49\u0e17\u0e38\u0e01\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c\u0e41\u0e2a\u0e14\u0e07\u0e2a\u0e16\u0e32\u0e19\u0e30\u0e40\u0e1b\u0e47\u0e19 &#8220;disabled&#8221; \u0e2d\u0e32\u0e01\u0e32\u0e23\u0e02\u0e2d\u0e07\u0e1b\u0e31\u0e0d\u0e2b\u0e32: \u0e15\u0e31\u0e27\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c Firepower \u0e44\u0e21\u0e48\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21\u0e15\u0e48\u0e2d\u0e01\u0e31\u0e1a Firepower Management Center (FMC) \u0e44\u0e14\u0e49 \u0e40\u0e19\u0e37\u0e48\u0e2d\u0e07\u0e08\u0e32\u0e01\u0e43\u0e1a\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07\u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e40\u0e0b\u0e47\u0e19\u0e23\u0e31\u0e1a\u0e23\u0e2d\u0e07 sftunnel certificates \u0e1a\u0e19 FMC \u0e44\u0e14\u0e49\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38\u0e41\u0e25\u0e49\u0e27\u0e19\u0e31\u0e48\u0e19\u0e40\u0e2d\u0e07\u0e04\u0e23\u0e31\u0e1a \u0e44\u0e1f\u0e25\u0e4c\u0e1a\u0e31\u0e19\u0e17\u0e36\u0e01\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25 (Logs): \u0e02\u0e49\u0e2d\u0e1c\u0e34\u0e14\u0e1e\u0e25\u0e32\u0e14\u0e1a\u0e19\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c: Sep 20 04:10:47 DEVICE SF-IMS[50792]: [51982] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to FMC-IP:8305\/tcp Sep 20 04:10:47 DEVICE SF-IMS[50792]: [51982] sftunneld:sf_ssl [INFO] Wait to connect to 8305 (IPv4): FMC-IP Sep 20 [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":8235,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[51],"tags":[63,582,93,94],"class_list":["post-8233","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-article","tag-cisco","tag-cybersecurity","tag-firepower","tag-fmc"],"_links":{"self":[{"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/posts\/8233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/comments?post=8233"}],"version-history":[{"count":2,"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/posts\/8233\/revisions"}],"predecessor-version":[{"id":8236,"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/posts\/8233\/revisions\/8236"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/media\/8235"}],"wp:attachment":[{"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/media?parent=8233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/categories?post=8233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ablenet.co.th\/en\/wp-json\/wp\/v2\/tags?post=8233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}