39-5
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 39 Configuring Certificates
Certificate Configuration
The OCSP server (responder) certificate typically signs the OCSP response. After receiving the
response, the security appliance tries to verify the responder certificate. The CA normally sets the
lifetime of its OCSP responder certificate to a relatively short period to minimize the chance of it being
compromised.The CA typically also includes an ocsp-no-check extension in the responder certificate
indicating that this certificate does not need revocation status checking. But if this extension is not
present, the security appliance tries to check its revocation status using the same method specified in the
trustpoint. If the responder certificate is not verifiable, revocation checks fails. To avoid this possibility,
configure
revocation-check
none
in the responder certificate validating trustpoint, while configuring
r
evocation-check ocsp
for the client certificate.
Supported CA Servers
The security appliance supports the following CA servers:
•
Cisco IOS CS
•
Baltimore Technologies
•
Entrust
•
Microsoft Certificate Services
•
Netscape CMS
•
RSA Keon
•
VeriSign
Certificate Configuration
This section describes how to configure the security appliance with certificates and other procedures
related to certificate use and management.
This section includes the following topics:
•
Preparing for Certificates, page 39-5
•
Configuring Key Pairs, page 39-6
•
Configuring Trustpoints, page 39-7
•
Obtaining Certificates, page 39-9
•
Configuring CRLs for a Trustpoint, page 39-13
•
Exporting and Importing Trustpoints, page 39-14
•
Configuring CA Certificate Map Rules, page 39-15
Preparing for Certificates
Before you configure a security appliance with certificates, ensure that the security appliance is
configured properly to support certificates. An improperly configured security appliance can cause
enrollment to fail or for enrollment to request a certificate containing inaccurate information.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......