ETExamTower
Q21Management and Operations

Refer to the exhibit. A small company was acquired by a large organization. Consequently, the new organization decided to update the information on its Enterprise RootCA and generated a new certificate using OpenSSL. Which configuration updates the new certificate and generates an alert in the vManage **Monitor | Events** dashboard?

Question exhibitQuestion exhibitQuestion exhibitQuestion exhibitQuestion exhibit
← → navigate · a answer
Discussion · 25
4
How can B be correct when the validity of the cert it generates is 2000 days and it uses O=XYZ, although the exhibit shows a cert with a validity of 365 day and O=ABC? In my opinion, A is the right answer.
3
B looks correct.
3
A is correct: Eliminate C/D because they use Symantec in step 2 - as per the question, it should be local enterprise CA as used in A/B Step 1 should say 365 days, not 2000, so that eliminates B and leaves us with A.
2
The right answer should be A
2
The correct answer is B, not A. The OpenSSL syntax is correct and has the right navigation to the enterprise root certificate directory rather than D.
2
A looks correct
2
3650 days is incorrect, and it will not be generated on a vmanage. B option specified 2000 days, which is incorrect
2
B looks correct
2
Correct Answer is B According to Cisco's published guides!
2
in doc this is an example: OpenSSL> x509 -req -days 730 -in vmanage.csr -CA subca.crt -CAkey subca.key -set_serial 02 -out vmanage.crt which options matches this one?
2
I've tested this in a lab environment, B looks right #RootCA openssl req -x509 -new -nodes -key ROOTCA.key -sha256 -days 2000 -subj "/C=UK/ST=Hampshire/L=Southampton/O=LAB-1/CN=roger.local" -out ROOTCA.pem This is from this lab: https://www.youtube.com/watch?v=X0yfM45sTyk&list=PLplGU0K93TA4oi8wcWGUUtdyJP9VNZ5Ce&index=6
1
I lean toward A https://stackoverflow.com/questions/10175812/how-to-generate-a-self-signed-ssl-certificate-using-openssl
1
I still stand by B. The syntax is correct, A isn’t. Also, why would you want a RootCA only valid for 1 year?
1
In Releases 17.1 and later, Cisco vManage can act as a Certificate Authority (CA) and can automatically generate and install signed certificates on vEdge Cloud router. Notice the top left corner. VManage Module RootCa
1
B is the correct answer. the syntax of the command is: openssl req (without the "-") and then go to vManage > Administration > §Controller Certificate Authorization > Enterprise Root Certificate
1
B ONLY - see for syntax below: student@student-vm:~/lolcalCA$ openssl req -x509 -newkey rsa:2048 -keyout myca.key- -out myca.crt - days 3650 -nodes
1
One thing that bodered me was the O value. The question says the organization is changed, so the O value must change too, from the old ABC to XYZ (new organization name)
1
B is not right
1
the number of days does not match the cert in question
1
Because the cert in question is valid for 365 days, therefore B can't be valid no matter how you look at it
1
A looks like the correct answer
1
Reference: https://www.cisco.com/c/en/us/support/docs/routers/sd-wan/215103-how-to-generate-self-signed-web-certific.html#:~:text=vmanage%3A~%2Fweb%24%20openssl%20genrsa%20-out%20rootca.key%202048%20Generating%20RSA,is%2065537%20%280x10001%29%20vmanage%3A~%2Fweb%24%20ls%20rootca.key%20web_cert.csr%20vmanage%3A~%2Fweb%24
1
There's no requirement for the cert to be valid for 365 days. It may be valid for 2000 days. Also there's a change in ORG name in option B. Plus according to the reference Roger95 provided, the syntax in option B is correct. I'll go with B.
1
There's no issue with 2000 days and it's not incorrect.
1
B is correct. Step1 says - " generate RootCA Certificate" which matches with command syntax/attributes. In option A - the comand generates a "vmanage.crt" which is something else. (It will be needed later on)