← Integrations

Automated SSL certificate renewal for Cisco Firepower

Firepower won't update a renewed certificate on its own. CertKit will.

A Firepower (FTD) device managed through Firepower Device Manager stores certificates as internal certificate objects, and the Remote Access VPN's server certificate and a SAML server's service provider certificate each reference one. When a certificate renews, those references keep pointing at the old object until someone uploads the new certificate, re-selects it, and runs a deployment. Every 47 days. On every firewall you manage.

CertKit centralizes certificate issuance and renewal, then pushes the renewed certificate to your Firepower devices automatically via the CertKit Agent and the FDM REST API, applies it to the service you choose, and runs the deployment for you.

Start free trial Watch demo

Built for Cisco Firepower

Pre-built templates for the Remote Access VPN and SAML server ship in your CertKit account. No scripting required.

CertKit renews your Firepower certificate for you. On every renewal it uploads the new certificate and its CA chain over the FDM REST API, applies it to the Remote Access VPN or SAML server you picked, removes the old certificate, and runs the FDM deployment. No console clicks, no manual upload, no forgotten Deploy button.

Schedule CertKit's deployments in a maintenance window so a half-finished change from earlier in the day doesn't go live at renewal time.

How to install an SSL certificate on Cisco Firepower

The manual process, if you want to do it yourself:

  1. Generate a private key and certificate request. Create the key and CSR with OpenSSL — Firepower Device Manager expects you to bring the certificate and key with you rather than enrolling on the box.
  2. Submit the CSR to a certificate authority. Purchase a certificate or use a free ACME CA, then wait for the signed certificate file to come back. A wildcard certificate covers the VPN headend and everything else on the domain.
  3. Upload the certificate. In FDM, under Objects → Certificates, add an Internal Certificate and paste the PEM certificate and private key. Upload each intermediate CA in the chain separately as a Trusted CA certificate.
  4. Re-select the certificate on every service that uses it. The Remote Access VPN's server certificate under Device → Remote Access VPN — the certificate AnyConnect and Secure Client users see — and the service provider certificate on each SAML server object. Neither refreshes on its own.
  5. Deploy the pending changes. Click Deploy and wait for the job to finish. Until you do, the device keeps serving the old certificate — and when you do, every other pending change on the device deploys with it.

Every one of these steps is manual, and Firepower won't repeat any of them for you when the certificate renews. With lifetimes shrinking to 47 days, installation stops being an annual chore and becomes a recurring task: eight times a year, on every firewall you manage. Miss one and remote workers get a certificate warning from Secure Client — or stop connecting entirely.

At 47 days, automation is the only sustainable way to run Firepower certificates. Here's how CertKit does it.

How it works

 Your network            CertKit                 ACME CA
┌───────────────────┐     ┌──────────────────┐    ┌─────────────┐
│  ┌─────────────┐  │     │                  │    │             │
│  │Deploy Agent │◄─┼─────┤  Issue & Renew   │◄──►│             │
│  └──┬────┬─────┘  │     │   Certificates   │    │             │
│     │    │ FDM    │     │                ┌───┐  └─────────────┘
│     │    │ REST   │     └───────────┬────│DNS│
│     ▼    ▼        │                 │    └───┘
│ ┌──────────────┐  │                 │
│ │ Firepower    │  │                 │
│ │ [x] Uploaded │  │ ◄───────────────┘
│ │ [x] Deployed │  │       Verify
│ └──────────────┘  │
└───────────────────┘

CertKit issues and renews certificates centrally in the cloud using delegated DNS validation. You create a one-time CNAME record; CertKit handles every ACME challenge after that.

The deploy agent is a small service you run on a server inside your network. It makes an outbound HTTPS connection to CertKit to pull each renewed certificate, then connects to the Firepower management address over the FDM REST API on your LAN to upload the certificate, apply it, and run the deployment. The firewall never talks to CertKit or the public internet directly, never runs ACME, needs no port 80 open, and never stores DNS credentials. One deploy agent can reach every Firepower and other appliance on that network, so there's nothing to install on the firewalls themselves.

CertKit has transformed how Belden manages SSL certificate issuance, delivering a streamlined process that dramatically reduced both cost and complexity. Their solution has been a clear win for our organization.

Ryan Buckner, IT Infrastructure Analyst, Belden

Two places an FDM-managed Firepower uses your certificate

An FTD device presents your certificate in two different roles, each configured through a different part of the FDM API. CertKit ships a pre-built template for each. Pick the ones you use; the rest stay untouched.

Remote Access VPN Server certificate for AnyConnect / Secure Client SAML server Service provider certificate in the SAML exchange

What CertKit handles

Setup takes about ten minutes

  1. Connect your domain. Add a one-time CNAME record to delegate DNS validation to CertKit. Every renewal challenge after that is automatic.
  2. Create an FDM administrator for CertKit. The agent needs an FDM account allowed to manage certificate objects, the Remote Access VPN or SAML servers, and deployments. A dedicated account keeps the audit trail clean.
  3. Install the CertKit Agent. One command on any Windows host with HTTPS reachability to the Firepower management address. The agent runs as a background service and needs no inbound firewall rules.
  4. Add the Firepower deployment script. Choose the RA VPN or SAML template, set the management address, the FDM credentials, and the connection profile or SAML server name. CertKit runs it on every renewal.

See the full architecture →

Why not run ACME on the firewall?

FTD has no ACME client, and giving a perimeter security device what ACME needs is a bad trade anyway: DNS provider credentials on the firewall are a privilege escalation waiting to happen, and opening port 80 to the public on the device that terminates your VPN is worse.

Scripting the FDM API yourself has its own sharp edges: token authentication, separate object types for internal certificates and trusted CAs, walking the RA VPN configuration to find the one that owns your connection profile, and a deployment job you have to start and babysit or nothing actually changes. We built and tested the deployment so you don't have to. CertKit issues the certificate via delegated DNS validation, then the agent handles the upload, the binding, the cleanup, and the deployment as one verified step, with no ACME client on the firewall.

Firepower is just one part of your network edge

Most networks have more than one place where TLS certificates live: load balancers like F5 BIG-IP and Citrix NetScaler, web servers, and other firewall vendors like Fortinet, Palo Alto, SonicWall, and Juniper SRX, plus the Aruba ClearPass cluster handling network access control. CertKit automates all of it from one account.

See all integrations

Start automating Firepower certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing