THIS FIELD NOTICE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTY OF MERCHANTABILITY. YOUR USE OF THE INFORMATION ON THE FIELD NOTICE OR MATERIALS LINKED FROM THE FIELD NOTICE IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS FIELD NOTICE AT ANY TIME.
Revision | Publish Date | Comments |
---|---|---|
1.0 |
04-Apr-23 |
Initial Release |
Affected OS Type | Affected Software Product | Affected Release | Affected Release Number | Comments |
---|---|---|---|---|
NON-IOS |
AsyncOS for Secure Email |
11 |
11.0.0, 11.0.3, 11.1.0 |
|
NON-IOS |
AsyncOS for Secure Email |
12 |
12.0.0, 12.1.0, 12.5.0, 12.5.3 |
|
NON-IOS |
AsyncOS for Secure Email |
13 |
13.0.5, 13.5.1, 13.5.3 |
|
NON-IOS |
AsyncOS for Secure Email |
14 |
14.0.0, 14.2.0 |
Defect ID | Headline |
---|---|
CSCwc95269 | ESA : Unable to connect to the Cisco Aggregator Server |
The internal Certificate Authority (CA) trust store used by the Cisco Aggregator (Click Tracking) service does not include the root CA IdenTrust Commercial Root CA 1. Due to this, any Secure Email Gateway (ESA) that runs an impacted version of AsyncOS will lose Click Tracking functionality once the existing https://aggregator.cisco.com/ certificate has expired and is renewed using the IdenTrust Commercial Root CA 1 root CA.
For enhanced security, the certificate supplied to https://aggregator.cisco.com/ will be renewed using a CA of HydrantID Server CA O1, which is then further issued by the root CA IdenTrust Commercial Root CA 1. The current DigiCert certificate will expire in February 2024, and customers who utilize Click Tracking will be required to upgrade to a fixed AsyncOS release before this time in order to avoid disruption to their service.
This alert will be seen:
Unable to connect to the Cisco Aggregator Server.
Details: (60, 'SSL certificate problem: unable to get local issuer certificate'
In addition to the alert, the same message can be observed within the cloud_connector logs:
An error occurred when fetching the URL click track record data from the Cisco Aggregator Server: (60, 'SSL certificate problem: unable to get local issuer certificate')
In order to resolve this issue, upgrade to one of these fixed AsyncOS versions:
Customers who currently use or plan to use a FIPS-compliant AsyncOS version should upgrade to 14.2.2. Customers who require FIPS certification should upgrade to 15.0, which is tentatively scheduled to be released in April of 2023.
If you require further assistance, or if you have any further questions regarding this field notice, please contact the Cisco Systems Technical Assistance Center (TAC) by one of the following methods:
My Notifications—Set up a profile to receive email updates about reliability, safety, network security, and end-of-sale issues for the Cisco products you specify.
Unleash the Power of TAC's Virtual Assistance